--- title: 'Application Security Engineer at Opal Security' canonical: 'https://feeny.ai/job/application-security-engineer-opal-security-san-francisco-rcy76s1xh1ff' type: 'job' last_seen: '2026-09-06' --- # Application Security Engineer at Opal Security - **Company:** Opal Security - **Location:** San Francisco, CA - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-05-20 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/opal/d2beff94-0445-4a4b-af58-30ef33eea2c8 ## Job description About Opal Security: At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation. The Role: Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job. We're hiring an Application Security Engineer to own security across Opal's product and platform — and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software. Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center — it's core to what we do. This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security — enterprise IT, compliance, and vendor risk management are handled separately. What You’ll Do: Secure Development Lifecycle - - Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews — you set the bar - Run and coordinate app pentests (internal and external) and drive findings to closure - Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code - Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works Software Security Engineering - - Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows - Own the Auth0 ↔ Opal integration — tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0) - Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good - Create shared libraries that make the secure path the easy path for every product engineer Incident Response & Cloud Security - - Be first on the scene for security incidents: investigate, contain, find the root cause, fix it - Partner with Infra on cloud hardening — AWS IAM, EKS, KMS, network segmentation - Level up detection and response by writing detection rules and improving logging and alerting Security Culture - - Mentor engineers on secure coding, common vuln patterns, and security architecture — you make the org smarter - Help set the security roadmap by grounding it in real product risk - Be the security teammate engineers want to work with — a collaborator, not a bottleneck You Might Be a Fit If You: - Have 4+ years in application security or software security engineering - Actually write production code — findings reports are the floor, not the ceiling - Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle - Are comfortable in AWS and containerized environments (Kubernetes, Docker) - Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL - Have led complex, cross-functional security initiatives from kickoff to completion - Have run or participated in external pentests and seen findings through remediation - Thrive on ownership and ambiguity — you'd rather write the playbook than wait for one ## About Opal Security ## Core Business - **Primary industry**: Cybersecurity – Identity Security / Access Governance - **Target customers**: B2B Enterprise (e.g., Databricks, Notion, Cloudflare, Scale AI, CoreWeave, SpaceXAI, Superhuman) - **Mission or purpose**: “To secure every identity and access path” [opal.dev/about](https://www.opal.dev/about) ## Products & Services - **Paladin**: AI agent that evaluates every access request, approves safe requests automatically, escalates only what needs a human, and revokes access when no longer needed. - **OpalScript**: Version-controlled, code-based approval workflows that scale across teams and environments; AI can generate the logic from natural language. - **OpalQuery**: Query the entire stack in plain English to surface risk, over-provisioned access, separation-of-duties conflicts, and hidden privilege escalation paths. - **Just-In-Time Access**: Grant privileged access only when needed, auto-revoke when work is done. - **AI-Guided Access Reviews**: Explainable recommendations that surface the riskiest access, replacing rubber-stamp reviews. - **Access Intelligence**: Ask who has access to what, and why, in plain English. - **Security for AI Agents**: Define what AI agents can see, access, and execute before they touch your systems. - **Programmable Governance**: Build access logic into workflows and approvals as version-controlled, testable code. - **Platform integrations**: Connects to 250+ systems across cloud, identity, SaaS, databases, and AI platforms (e.g., Okta, AWS, GCP, Snowflake, GitHub, OpenAI, Anthropic, Databricks, ServiceNow, Salesforce). ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total funding of $59M (latest $23M round announced June 2026); annual revenue not publicly available - **Notable Investors/Partners**: Greylock Partners, Battery Ventures, Box Group, SVCI, Cambium Capital. Advisors include former CTO of JPMorgan Chase, former CSO of Robinhood, CISO of Datadog, CEO of Abnormal Security, CTO of 1Password, CSO of Coinbase, and founder of LDAP. - **Growth Signals**: - Named to Notable Capital’s “Rising in Cyber 2026” list (30 most promising private cybersecurity startups). - More than 60% of the team has joined since the start of 2026, with hiring accelerating across engineering, product, and go-to-market. - Major customers: Databricks runs 86,000 just-in-time access requests through Opal; Mercari governs over 5,000 Okta entitlements via automated reviews. - Launched the industry’s first platform to see, encode, and enforce access governance for AI agents (Paladin) in March 2026. ## Competitive Advantages - **AI-native architecture** that understands CISO context with security engineer precision. - **Policy-as-code** (OpalScript) enables version-controlled, testable, and scalable access logic. - **Unified governance** across humans, non-human identities (service accounts, CI/CD pipelines), and AI agents—all in one access graph. - **Just-in-time by default** reduces standing access and attack surface. - **Self-hosted or on-prem deployment** option for tightly controlled environments. - **SOC 2 Type 2 certified**, independent penetration testing annually, TLS 1.2+ in transit, AWS KMS at rest, daily encrypted backups. - **250+ integrations** with major cloud, identity, SaaS, database, and AI platforms. ## Strategic Focus - Unify identity governance across all identity types, with a strong emphasis on securing AI agents as they proliferate in enterprise environments. - Scale the engineering and go-to-market teams (60%+ team growth in 2026). - Expand leadership: new Chief Product Officer (Sameer Mehta, ex-Veza), Chief Technology Officer (Alex Pien, ex-Meta), VP of Field Engineering (ex-Cisco), VP of Marketing (ex-Clumio), Head of Product & Solutions Marketing (ex-Salesforce). - Continue to build a self-improving system that ensures resilience and enables faster movement without increasing risk. ## Why Work Here - **Hybrid work model**: Offices in San Francisco (HQ) and New York; employees engage in a combination of remote and on-site work. - **Fast-growing startup** backed by top-tier VCs (Greylock, Battery Ventures) with significant momentum and market recognition. - **Mission-driven security work**: Opportunity to solve hard problems in identity security, especially at the intersection of AI and access control. - **Cutting-edge technology**: Work on AI-native policy engines, large-scale access graphs, and integrations with hundreds of platforms. - **Strong engineering culture** with leadership from experienced executives (ex-Meta, ex-Veza, ex-Cisco, ex-Palo Alto Networks). - **Open roles** (as of mid-2026): Software Engineer, Engineering Manager, Product Manager, Forward Deployed Engineer, Solutions Engineer, Enterprise Account Executive, Technical Customer Success Manager, Application Security Engineer, and more. ## Sources 1. [opal.dev](https://www.opal.dev/) 2. [opal.dev/about](https://www.opal.dev/about) 3. [builtin.com/company/opal-security](https://builtin.com/company/opal-security) 4. [linkedin.com/company/opalsecurity](https://www.linkedin.com/company/opalsecurity) 5. [opal.dev/media-press/opal-security-raises-23m-new-leadership](https://www.opal.dev/media-press/opal-security-raises-23m-new-leadership) ## Other roles at Opal Security - [GTM Engineer](https://feeny.ai/job/gtm-engineer-opal-security-san-francisco-39ywrh6eh725) — San Francisco, CA - [Business Development Representative](https://feeny.ai/job/business-development-representative-opal-security-san-francisco-9ps3v5c9j6c2) — San Francisco, CA - [Senior Field Marketing Manager](https://feeny.ai/job/senior-field-marketing-manager-opal-security-san-francisco-v228sq12atz3) — San Francisco, CA - [Enterprise Account Executive - Southeast](https://feeny.ai/job/enterprise-account-executive-southeast-opal-security-atlanta-fhzns023gzw1) — Atlanta, GA - [Enterprise Account Executive - Southern California](https://feeny.ai/job/enterprise-account-executive-southern-california-opal-security-los-angeles-8rke94henpjv) — Los Angeles, CA - [Enterprise Account Executive - Mid West](https://feeny.ai/job/enterprise-account-executive-mid-west-opal-security-austin-vycxprpkp42d) — Austin, TX - [Security & Compliance Lead](https://feeny.ai/job/security-compliance-lead-opal-security-san-francisco-b414fmaeemcp) — San Francisco, CA - [Product Marketing & Content Associate](https://feeny.ai/job/product-marketing-content-associate-opal-security-san-francisco-4vbht8k73qg1) — San Francisco, CA - [Senior Manager Demand Generation](https://feeny.ai/job/senior-manager-demand-generation-opal-security-san-francisco-3a47zepv1b9c) — San Francisco, CA - [Software Engineer, Infrastructure](https://feeny.ai/job/software-engineer-infrastructure-opal-security-san-francisco-6mtmwh30b8t6) — San Francisco, CA