Senior Application Security Engineer
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.
What You'll Do
Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.
Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.
Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.
Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).
Perform threat modeling and maintain secure-coding standards.
Support incident response for application-layer security issues.
Coordinate and help manage third-party penetration tests.
Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.
What You'll Bring
5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.
Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.
Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.
Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.
Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.
A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.
Nice to Have
Experience in healthcare, fintech, or another regulated industry.
Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.
Security certifications such as OSCP, GWAPT, or CSSLP.
Experience building or maturing an AppSec program from an early stage.
Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform).
Red team experience performing internal campaigns and providing remediation reports.
Benefits
Competitive pay with equity options
Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options.
Company-sponsored disability & life insurance.
Unlimited PTO
401(k) + 4% Matching
Fully remote work + flexible working hours
$750 work-from-home setup budget
Paid biannual in-person company summits
Quarterly $150 co-hanging stipend to meet up with coworkers.
Monthly $100 health and wellness benefit
Generous paid family leave
Annual $1,200 learning & development stipend
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Train and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesTrain and Evaluate AI Agents in CAD Environments (Freelance)
Mindrift
United StatesSenior Engineer – DoD/U.S. Navy Energetics Facility Design and Construction
Eastern Research Group
United StatesSecurity Operations Specialist
HiddenLayer
United StatesMore Openings at Turquoise Health
Explore Top Companies in this Space
Wellth
Healthcare / HealthTech / Behavioral Economics / Enterprise Software
InterSystems
Database Platforms / Healthtech / Enterprise Software
Verse Medical
HealthTech / Enterprise Software / Digital Health
EnableComp
HealthTech / Revenue Cycle Management / Enterprise Software
Turquoise Health
View Company ProfileTurquoise Health is a trailblazing HealthTech company on a mission to eliminate the administrative waste and financial opacity that plagues the US healthcare system. Founded in 2020 by industry veterans Chris Severn and Adam Geitgey, the company provides a comprehensive, AI-driven platform for healthcare pricing, contracts, and transactions. Under the hood, Turquoise Health ingests and structures massive amounts of complex, unstructured data—turning opaque machine-readable files (MRFs) and dense managed care contracts into clear, actionable intelligence. Their platform allows users to leverage real-time rate transparency, automate compliance, and utilize AI to extract language and rates directly from contracts to model negotiation scenarios. Their primary target audience spans the entire healthcare ecosystem, including major providers like UNC Health and Johns Hopkins, massive payer networks, life sciences companies, and self-insured employers who are desperately seeking predictable pricing. What sets Turquoise Health apart in the crowded healthcare SaaS landscape—fueled by a recent $40M Series C led by top-tier investors like a16z and Oak HC/FT—is its relentless drive to replace the industry's default "it depends" pricing model with a modern, transparent marketplace where patients and providers know the exact cost of care upfront.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.