
Senior Application Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Take ownership of application-layer security across Turquoise's platform.
• Develop and manage the application security scanning program, which includes SAST, DAST, dependency/SCA, container, and IaC scanning.
• Optimize scanning tools to minimize noise and highlight genuine risks.
• Assess findings from scans, penetration tests, and bug bounty reports.
• Prioritize issues based on risk and oversee remediation until resolved.
• Collaborate with engineering teams on vulnerability remediation, debugging, and providing code-level guidance.
• Assist in integrating security into the engineering, product, and design processes, as well as the SDLC and CI/CD pipelines.
• Conduct threat modeling and uphold secure coding standards.
• Support incident response efforts for application-layer security incidents.
• Organize and manage third-party penetration tests.
• Monitor and report on security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage to engineering and leadership.
• Over 5 years of experience in application security, security engineering, or a related software engineering role with a focus on security.
• Practical experience with SAST, DAST, and dependency/SCA scanning tools.
• Comprehensive knowledge of the OWASP Top 10, authentication/authorization vulnerabilities, injection issues, SSRF, and other common vulnerability types.
• Capability to review code and architecture to identify vulnerabilities and suggest effective solutions.
• Familiarity with cloud environments, preferably AWS.
• Experience in securing modern CI/CD pipelines.
• Excellent communication skills to clearly articulate risks and remediation steps.
• A collaborative and pragmatic approach to security.
• Background in healthcare, fintech, or another regulated industry.
• Knowledge of compliance frameworks such as HIPAA, SOC 2, or GDPR.
• Possession of security certifications like OSCP, GWAPT, or CSSLP.
• Experience in establishing or enhancing an AppSec program from an early stage.
• Proficiency in scripting or automation using Python, Go, Terraform, or other infrastructure-as-code tools.
• Experience with red teaming, including conducting internal campaigns and producing remediation reports.
• Current authorization to work in the United States.
• Note: Turquoise does not sponsor employment visas or take responsibility for existing visa sponsorships.
• Equity options.
• Excellent healthcare plan options (Medical, Dental & Vision), including FSA, DCFSA, & HSA choices.
• Company-sponsored disability and life insurance.
• Unlimited Paid Time Off (PTO).
• 401(k) with 4% matching.
• Fully remote work with flexible working hours.
• $750 budget for work-from-home setup.
• Paid biannual in-person company summits.
• Quarterly $150 stipend for coworker meet-ups.
• Monthly $100 health and wellness benefit.
• Generous paid family leave.
• Annual $1,200 learning and development stipend.
Bolder Apps
Planar
AcuityMD
CloudPSO
Get handpicked remote jobs straight to your inbox weekly.