Senior Application Security Engineer

Posted 2 days ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of application-layer security across Turquoise's platform.

• Develop and manage the application security scanning program, which includes SAST, DAST, dependency/SCA, container, and IaC scanning.

• Optimize scanning tools to minimize noise and highlight genuine risks.

• Assess findings from scans, penetration tests, and bug bounty reports.

• Prioritize issues based on risk and oversee remediation until resolved.

• Collaborate with engineering teams on vulnerability remediation, debugging, and providing code-level guidance.

• Assist in integrating security into the engineering, product, and design processes, as well as the SDLC and CI/CD pipelines.

• Conduct threat modeling and uphold secure coding standards.

• Support incident response efforts for application-layer security incidents.

• Organize and manage third-party penetration tests.

• Monitor and report on security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage to engineering and leadership.


⛳️ Requirements

• Over 5 years of experience in application security, security engineering, or a related software engineering role with a focus on security.

• Practical experience with SAST, DAST, and dependency/SCA scanning tools.

• Comprehensive knowledge of the OWASP Top 10, authentication/authorization vulnerabilities, injection issues, SSRF, and other common vulnerability types.

• Capability to review code and architecture to identify vulnerabilities and suggest effective solutions.

• Familiarity with cloud environments, preferably AWS.

• Experience in securing modern CI/CD pipelines.

• Excellent communication skills to clearly articulate risks and remediation steps.

• A collaborative and pragmatic approach to security.

• Background in healthcare, fintech, or another regulated industry.

• Knowledge of compliance frameworks such as HIPAA, SOC 2, or GDPR.

• Possession of security certifications like OSCP, GWAPT, or CSSLP.

• Experience in establishing or enhancing an AppSec program from an early stage.

• Proficiency in scripting or automation using Python, Go, Terraform, or other infrastructure-as-code tools.

• Experience with red teaming, including conducting internal campaigns and producing remediation reports.

• Current authorization to work in the United States.

• Note: Turquoise does not sponsor employment visas or take responsibility for existing visa sponsorships.


🏝️ Benefits

• Equity options.

• Excellent healthcare plan options (Medical, Dental & Vision), including FSA, DCFSA, & HSA choices.

• Company-sponsored disability and life insurance.

• Unlimited Paid Time Off (PTO).

• 401(k) with 4% matching.

• Fully remote work with flexible working hours.

• $750 budget for work-from-home setup.

• Paid biannual in-person company summits.

• Quarterly $150 stipend for coworker meet-ups.

• Monthly $100 health and wellness benefit.

• Generous paid family leave.

• Annual $1,200 learning and development stipend.

People also viewed

Bolder Apps1 day ago

LLM Application Engineer

AR flagArgentina, +4 more countriesFull-timeApplication Engineer
ApplyView job
Planar1 day ago

Applications Engineer

US flagNew York, +2 more statesFull-timeApplication Engineer
ApplyView job
AcuityMD2 days ago

Senior Software Engineer, Applications

US flagUnited States OnlyFull-timeApplication Engineer$155k – $250k/year
ApplyView job
CloudPSO2 days ago

Senior AI/ML Engineer, Mobile Application Engineer – iOS/Android

PK flagPakistan OnlyFull-timeApplication Engineer
ApplyView job
Fenner Dunlop EMEA2 days ago

Application Engineering Specialist

US flagArizona OnlyFull-timeApplication Engineer
ApplyView job
Fenner Dunlop Americas2 days ago

Application Engineering Specialist

US flagArizona OnlyFull-timeApplication Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers