Job Description Help for Job Description. Opens a new window. About The Role Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't. As our Infrastructure Security Engineer, you'll own the security of everything Opendoor runs on including multi-account AWS, Kubernetes clusters, the identity plane connecting every system, and the cloud workloads behind home acquisition, resale, mortgage, title, and escrow. There's meaningful work already in motion and real room to define where it goes next. What You'll Do ? Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together. ? Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks. ? Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure. ? Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation. ? Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation. ? Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time. ? Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP. ?
Run our cloud detection engineering:
GuardDuty, Security Hub, CloudTrail, VPC flow logs — tuned for signal, integrated with Datadog and our incident response playbooks. ? Set the bar for what "secure by default" looks like for AI-maximalist engineering — vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure. ? Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails. Tech Stack ?
Cloud Platforms:
AWS (primary), Azure, GCP ?
Containers and Orchestration:
EKS, Bottlerocket, Karpenter, Helm, Argo CD ?
Identity and Access:
Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault ?