Senior Application Security Engineer

Turquoise

United States

Remote

USD 150,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive pay with equity options
Fully remote work + flexible working
Stellar health care plan options (Med,
401(k) + 4% Matching
Unlimited PTO
Biannual in-person summits

Job summary

Turquoise Health is a remote-first, US-based company seeking a Senior Application Security Engineer to own application-layer security across our platform and drive our code scanning program. You will work closely with engineering on design, architecture, and secure development practices.

The role emphasizes threat modeling, incident response support, and collaboration to embed security early in SDLC and CI/CD pipelines.

Qualifications

  • 5+ years of experience in application security, security engineering, or a related software role.
  • Hands-on with SAST, DAST, and dependency/SCA scanning tools; able to distinguish real risk from noise.
  • Deep understanding of OWASP Top 10 and common vulnerability classes; able to review code and architecture.
  • Experience securing cloud environments (AWS preferred) and modern CI/CD pipelines.
  • Strong communication skills to explain risk to engineers and non-security stakeholders.
  • Collaborative, pragmatic security approach that balances risk reduction with speed.

Responsibilities

  • Build and run our application security scanning program (SAST, DAST, SCA, container and IaC scanning) and tune tools.
  • Triage findings from scans, pen tests, and bug bounty; prioritize by risk and track remediation.
  • Partner with engineering teams to fix vulnerabilities with hands-on debugging and code guidance.
  • Promote security in early design through mature SDLC and CI/CD pipelines.
  • Perform threat modeling and maintain secure-coding standards.
  • Support incident response for application-layer security issues.
  • Coordinate and help manage third-party penetration tests.
  • Track and report security posture metrics to engineering and leadership.

Skills

5+ yrs exp
SAST
DAST
SCA
AWS
CI/CD
Communication
Collaboration

Tools

Python
Go
Terraform
Code scanning tools

Job description

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

What You'll Do
  • Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.

  • Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.

  • Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.

  • Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).

  • Perform threat modeling and maintain secure-coding standards.

  • Support incident response for application-layer security issues.

  • Coordinate and help manage third-party penetration tests.

  • Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.

What You'll Bring
  • 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.

  • Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.

  • Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.

  • Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.

  • Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.

  • A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.

Nice to Have
  • Experience in healthcare, fintech, or another regulated industry.

  • Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.

  • Security certifications such as OSCP, GWAPT, or CSSLP.

  • Experience building or maturing an AppSec program from an early stage.

  • Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.

  • Red team experience performing internal campaigns and providing remediation reports

Benefits
  • Competitive pay with equity options

  • Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options

  • Company-sponsored disability & life insurance

  • Unlimited PTO

  • 401(k) + 4% Matching

  • Fully remote work + flexible working hours

  • $750 work-from-home setup budget

  • Paid biannual in-person company summits

  • Quarterly $150 co-hanging stipend to meet up with coworkers

  • Monthly $100 health and wellness benefit

  • Generous paid family leave

  • Annual $1,200 learning & development stipend

About Turquoise Health

Turquoise Health is a Series C price transparency platform for finance leaders across healthcare. Backed by a16z, Oak HC/FT, Adams Street, Yosemite, Bessemer Venture Partners, and others, we power price transparency for 300+ enterprise organizations and are building the infrastructure for a more open, efficient healthcare marketplace. We're a remote-first, US-based team that values transparency, empathy, inclusivity, creativity, and ownership.

We operate on US business hours and work with clients entirely based in the US. For this role, we are seeking US-based candidates.

We strongly encourage BIPOC, people with disabilities, and LGBTQIA+ folks to apply for any open roles of interest. Healthcare affects all people differently, but it significantly affects those in underserved communities. With a robust, diverse team, we are stronger and better equipped to change the future of healthcare for all.

Work Authorization

This role requires current authorization to work in the United States. Turquoise does not sponsor employment visas (H-1B, PERM, etc.) or assume sponsorship of existing visas for this position.

Disability Accommodation Email

Turquoise is committed to providing reasonable accommodations to applicants and employees with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require assistance or an accommodation with the hiring process, please contact recruiting@turquoise.health

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Engineering Manager, AI Team
Senior Engineering Manager, AI Team

turquoise-health • United States

Remote
USD 190,000 - 250,000
Competitive pay
Equity options
Remote-friendly
+5
Senior Design Engineer
Senior Design Engineer

Turquoise • United States

Remote
USD 120,000 - 180,000
Competitive pay with equity options
Fully remote work and flexible hours
401(k) with 4% matching
+1
Software Engineer II, Frontend-leaning
Software Engineer II, Frontend-leaning

Turquoise • United States

Remote
USD 110,000 - 140,000
Equity options
Health care plan (Medical, Dental &amp
Senior Enterprise Account Executive, Payer
Senior Enterprise Account Executive, Payer

Turquoise • United States

On-site
USD 80,000 - 110,000
Competitive pay with equity options
Stellar health care plan options
Unlimited PTO
+4
Senior Product Manager, Data Asset Strategy
Senior Product Manager, Data Asset Strategy

Turquoise • San Diego (CA)

On-site
USD 159,000 - 180,000
Competitive pay with equity options
Stellar health care plan options
Company-sponsored disability & life 보험
+6
Senior Enterprise Account Executive, Payer
Senior Enterprise Account Executive, Payer

Turquoise • San Diego (CA)

On-site
USD 220,000 - 245,000
Competitive pay with equity options
Stellar health care plan options
Unlimited PTO
+2
Cyber Security Engineer (Application Security)
Cyber Security Engineer (Application Security)

TherapyNotes.com • Philadelphia

On-site
USD 110,000 - 150,000
Salary up to $150k
Insurance
Retirement plan
+5
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer [Remote-US]
Senior Application Security Engineer [Remote-US]

Quanata • United States

On-site
USD 220,000 - 350,000
Monthly wellness allowance
401(k) plan with company match
Professional development budget of $5,000
Product Security Engineer New Remote - US
Product Security Engineer New Remote - US

Modern Health • Northern (KY)

Hybrid
USD 101,000 - 140,000
Annual wellness stipend
New hire stipend
ModSquad community events
+2