Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Turquoise Health

Senior Application Security Engineer

Turquoise Health

. Own application-layer security across Turquoise's platform .

Posted 10/2/2026full-timeRemote • United StatesSenior💰 $172,000 - $200,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in application-layer security, including SAST, DAST, and vulnerability management, while effectively collaborating with engineering teams to integrate security into the software development lifecycle. Proficient in threat modeling, secure coding standards, and compliance frameworks relevant to regulated industries.

Highest-signal resume keywords
Application SecuritySAST/DAST Scanning ToolsOWASP Top 10Cloud Environments (AWS)Security Certifications (OSCP, GWAPT, CSSLP)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Application SecuritySASTDASTDependency/SCA ScanningThreat ModelingSecure Coding StandardsVulnerability ManagementScripting (Python, Go, Terraform)Red Team ExperienceCI/CD Pipeline Security
Soft Skills
Strong Communication SkillsCollaborative ApproachPragmatic Security Mindset
Tools & Technologies
CI/CD ToolsSecurity Scanning ToolsCloud Platforms (AWS)Infrastructure-as-Code Tools
Certifications & Qualifications
OSCPGWAPTCSSLP
Industry Keywords
HealthcareFintechRegulated IndustryCompliance Frameworks (HIPAA, SOC 2, GDPR)

Tech Stack

Tools & technologies
AWSCloudPythonSDLCTerraformGo

About the role

Key responsibilities & impact
  • Own application-layer security across Turquoise's platform
  • Build and run the application security scanning program, including SAST, DAST, dependency/SCA, container, and IaC scanning
  • Tune scanning tools to reduce noise and surface real risk
  • Triage findings from scans, penetration tests, and bug bounty reports
  • Prioritize findings by risk and track remediation through closure
  • Partner with engineering teams on vulnerability remediation, debugging, and code-level guidance
  • Help integrate security early into engineering, product, and design processes, SDLC, and CI/CD pipelines
  • Perform threat modeling and maintain secure-coding standards
  • Support incident response for application-layer security issues
  • Coordinate and help manage third-party penetration tests
  • Track and report security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage, to engineering and leadership

Requirements

What you’ll need
  • 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus
  • Hands-on experience with SAST, DAST, and dependency/SCA scanning tools
  • Deep understanding of OWASP Top 10, authentication/authorization flaws, injection, SSRF, and other common vulnerability classes
  • Ability to review code and architecture to identify vulnerabilities and propose effective fixes
  • Experience with cloud environments; AWS preferred
  • Experience securing modern CI/CD pipelines
  • Strong communication skills to explain risk and remediation steps clearly
  • Collaborative, pragmatic approach to security
  • Experience in healthcare, fintech, or another regulated industry
  • Experience with compliance frameworks such as HIPAA, SOC 2, or GDPR
  • Security certifications such as OSCP, GWAPT, or CSSLP
  • Experience building or maturing an AppSec program from an early stage
  • Scripting or automation experience with Python, Go, Terraform, or other infrastructure-as-code tools
  • Red team experience performing internal campaigns and providing remediation reports
  • Current authorization to work in the United States
  • Turquoise does not sponsor employment visas or assume sponsorship of existing visas

Benefits

Comp & perks
  • Equity options
  • Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options
  • Company-sponsored disability & life insurance
  • Unlimited PTO
  • 401(k) + 4% Matching
  • Fully remote work + flexible working hours
  • $750 work-from-home setup budget
  • Paid biannual in-person company summits
  • Quarterly $150 co-hanging stipend to meet up with coworkers
  • Monthly $100 health and wellness benefit
  • Generous paid family leave
  • Annual $1,200 learning & development stipend