Application Security Engineer

Segment (Twilio)

Toronto

On-site

CAD 100,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Opendoor is looking for an Application Security Engineer to enhance security across their engineering processes by implementing automated solutions and protecting both consumer and internal applications. With responsibilities spanning from vulnerability management to mentoring engineers in secure practices, this role is critical for maintaining high security standards within Opendoor's innovative environment.

Applicants should have over 5 years of experience in application security or software engineering, proficient in languages like Python, Go, and TypeScript, and possess a strong understanding of security issues related to today's tech landscape.

Qualifications

  • 5+ years of application security or software engineering experience with a security focus.
  • Experience with hands-on expertise across the SAST/DAST/SCA toolchain.
  • Strong grasp of application vulnerability classes including OWASP Top 10.

Responsibilities

  • Own the security of everything we ship at Opendoor.
  • Fix application vulnerabilities across our consumer products and APIs.
  • Mentor engineers on secure design and code review.

Skills

Application security experience
Software engineering skills in Python, Go, TypeScript, or Ruby
Hands-on experience with SAST/DAST/SCA tools
Knowledge of common application vulnerabilities
Threat modeling skills
Cloud and container security experience
Offensive security experience (desirable)
Mobile application security review experience (desirable)

Education

Experience in security-focused roles

Tools

GitHub Advanced Security
AWS
Kubernetes
Semgrep
Burp Suite

Job description

Requirements
  • Deep conviction that AI and automation should eliminate manual work humans shouldn't be doing anyway. You're excited to replace developer toil and reactive vuln triage with automated systems, guardrails, and agents
  • Business enablement security mindset — you measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed
  • 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby — and the ability to read and write code across the others
  • Hands‑on expertise across the SAST/DAST/SCA toolchain, with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent
  • Strong grasp of common application vulnerability classes (OWASP Top 10, OWASP API Security Top 10), with particular fluency in GraphQL, REST, and gRPC security pitfalls — broken authorization, mass assignment, introspection exposure, IDORs
  • Practical threat modeling skills — you can take an architecture diagram and a 30‑minute conversation and walk out with the three things that actually matter
  • Experience with cloud and container security on AWS and Kubernetes, including IAM, secrets management, and CI/CD pipeline security
  • Humility and genuine curiosity — you're as excited to learn from product engineers and enable their work as you are to break things
  • (Desirable) Offensive security experience — pentesting web apps, APIs, or mobile, and/or red team operations
  • (Desirable) Experience running a bug bounty or coordinated disclosure program at scale
  • (Desirable) Mobile application security review experience (iOS and Android)
  • (Desirable) Experience securing AI/ML pipelines, agent frameworks, or MCP‑style integrations
  • (Desirable) OSCP, OSWE, or similar offensive certifications
What the job involves
  • Our Security Engineering team is building intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity
  • We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't
  • As our Application Security Engineer, you'll own the security of everything we ship — from the consumer flows that put cash offers in homeowners' hands, to the GraphQL APIs that power our products, to the AI agents and vibe‑coded tools our engineers and operators build every week
  • You'll be the technical owner of how we find, fix, and prevent application‑layer risk at Opendoor scale
  • Find and fix application vulnerabilities across our consumer products, internal admin tools, and the GraphQL APIs powering home acquisition, resale, mortgage, title, and escrow
  • Own and evolve our AppSec tooling stack — SAST/DAST, SCA and secrets scanning — and integrate findings into developer workflows where engineers already live (pull requests, Linear, Slack)
  • Run our HackerOne program: triage incoming reports, validate exploits, route fixes to product engineering teams, and determine root causes so we can stamp them out at the source
  • Lead threat modeling and security design reviews for new services, APIs, and mobile features — and turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake
  • Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation PRs — replacing manual security review with high‑signal automation
  • Partner with engineering teams to harden authentication, authorization, and input validation across our Ruby monolith and Go/Python/TypeScript services, including the GraphQL gateway (Apollo) and our EKS workloads - while driving a shift‑left strategy to identify vulnerabilities earlier in the development lifecycle
  • Stand up a credible offensive security capability — internal pentesting, red team exercises, and adversarial analysis of high‑risk flows (wire fraud, agent unlocks, identity verification) -- leveraging purple team exercises to ensure offensive findings are directly translated into hardened detection and response capabilities
  • Set the bar for what "secure by default" looks like for AI‑maximalist engineering, including vibe‑coded apps, MCP servers, and agent‑driven workflows that touch production data
  • Mentor engineers across the company in secure design, code review, and how to think like an attacker
  • Tech Stack:
  • Languages: Go, Python, TypeScript, Ruby, Terraform
  • Cloud: AWS, GCP, Azure, Kubernetes / EKS
  • AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning)
  • Semgrep, HackerOne, Burp Suite, Cloudflare WAF
  • AI Tooling: Claude, OpenAI, various agent frameworks, MCP — used heavily for vuln triage, exploit verification, and remediation drafting
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Enterprise Security Engineer
Enterprise Security Engineer

Opendoor • Toronto

On-site
CAD 100,000 - 130,000
Infrastructure Security Engineer
Infrastructure Security Engineer

Opendoor • Toronto

On-site
CAD 110,000 - 150,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Application Security Researcher
Application Security Researcher

OX Security • Toronto

On-site
CAD 120,000 - 180,000
Health Coverage
Unlimited PTO
Birthday/anniversary gifts
Security Architect
Security Architect

Ateko, backed by Bell Canada • Montreal (administrative region)

On-site
CAD 120,000 - 160,000
Senior Product Security Engineer
Senior Product Security Engineer

BeyondTrust, Inc. • Ottawa

On-site
CAD 120,000 - 180,000
Senior Offensive Security Engineer -SAST, DAST, SCA, IAST
Senior Offensive Security Engineer -SAST, DAST, SCA, IAST

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

On-site
CAD 120,000 - 160,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Oakville

On-site
CAD 120,000 - 180,000
Chief Software Engineering Architect
Chief Software Engineering Architect

DataStealth Inc. • Mississauga

On-site
CAD 180,000 - 240,000
Hybrid schedule
Staff Security Engineer (Enterprise AI)
Staff Security Engineer (Enterprise AI)

Affirm • Ottawa

Remote
CAD 120,000 - 180,000
Remote-first pay
Spending wallets
Supportive communities
+7