← Back to results

Senior Application Security Engineer

Drive application security for Turquoise Health's platform as a Senior Application Security Engineer in a fully remote role.

Location
United States
Compensation
Not disclosed
Level
senior
Type
full time · Remote

Posted by employer 12 hours ago

First seen on Joblaze 5 hours ago

Last verified on the company career page 5 hours ago

Apply at Turquoise Health → Save job Scanned from turquoise.health

Skills & Technologies

What you'll build

  • Build and run application security scanning program
  • Triage findings from scans and penetration tests
  • Partner with engineering teams to fix vulnerabilities
  • Perform threat modeling and maintain secure-coding standards
  • Track and report on security posture metrics

Must have

  • 5+ years of experience in application security
  • Hands-on experience with SAST, DAST, and dependency/SCA scanning tools
  • Deep understanding of common vulnerability classes
  • Experience with cloud environments (AWS preferred)
  • Strong communication skills

Nice to have

  • Experience in healthcare, fintech, or another regulated industry
  • Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR
  • Security certifications such as OSCP, GWAPT, or CSSLP
  • Experience building or maturing an AppSec program
  • Red team experience performing internal campaigns

Practical constraints

  • This role requires current authorization to work in the United States

Requirements

Experience
5+ years
Visa
No sponsorship (stated in posting)

Not disclosed in this posting: compensation.

Benefits

401k Match Education Budget Unlimited PTO Equity/Stock Options Remote Work Health Insurance Parental Leave

Joblaze summary

In the role of Senior Application Security Engineer at Turquoise Health, the individual will focus on enhancing application-layer security by managing and refining the company's code scanning program while collaborating closely with engineering teams. Key skills include hands-on experience with various security scanning tools and a solid understanding of common vulnerabilities, particularly in cloud environments. This position is ideal for someone with over five years of experience in application security or related fields, who can effectively communicate risks and remediation strategies. Turquoise Health, a Series C company, emphasizes a collaborative approach to security within a remote-fi

Joblaze insights

  • Listed today — first seen on Joblaze October 3, 2026. Last confirmed on Turquoise Health's careers page October 3, 2026.
  • Python appears in 39.5% of 329 comparable senior security roles in United States; DAST appears in 3% of 329 comparable senior security roles in United States.

Quick facts

Is the Senior Application Security Engineer role remote?
Yes — Turquoise Health lists this as a fully remote position.
How much experience is required?
At least 5 years of relevant experience for this Senior Application Security Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, DAST, Go, Python, SAST, Terraform.
What seniority level is this role?
Turquoise Health targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Application Security Engineer role at Turquoise Health.

From the original posting

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

What You'll Do

  • Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.

  • Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.

  • Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.

  • Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).

  • Perform threat modeling and maintain secure-coding standards.

  • Support incident response for application-layer security issues.

  • Coordinate and help manage third-party penetration tests.

  • Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.

What You'll Bring

  • 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.

  • Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.

  • Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.

  • Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.

  • Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.

  • A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.

Nice to Have

  • Experience in healthcare, fintech, or another regulated industry.

  • Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.

  • Security certifications such as OSCP, GWAPT, or CSSLP.

  • Experience building or maturing an AppSec program from an early stage.

  • Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.

  • Red team experience performing internal campaigns and providing remediation reports

Benefits

  • Competitive pay with equity options

  • Company-sponsored disability & life insurance

  • Unlimited PTO

  • 401(k) + 4% Matching

  • Fully remote work + flexible working hours

  • $750 work-from-home setup budget

  • Paid biannual in-person company summits

  • Monthly $100 health and wellness benefit

  • Generous paid family leave

  • Annual $1,200 learning & development stipend

Standard company text repeated across Turquoise Health's postings is omitted here.

Similar positions

Tanium
Suno
Turquoise Health
Software Engineer II, Frontend-leaning
Turquoise Health · Remote
Starburst
Security Engineer
Starburst · Warsaw, Poland
Starburst