You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Turquoise Health

Senior Application Security Engineer

  • Remote
  • 6+ years

Salary

$172,000 - 200,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

Responsibilities

  • Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.
  • Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.
  • Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.
  • Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).
  • Perform threat modeling and maintain secure-coding standards.
  • Support incident response for application-layer security issues.
  • Coordinate and help manage third-party penetration tests.
  • Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.
  • What You'll Bring
  • 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.
  • Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.
  • Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.
  • Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.
  • Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.
  • A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.

Requirements

  • Experience in healthcare, fintech, or another regulated industry.
  • Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.
  • Security certifications such as OSCP, GWAPT, or CSSLP.
  • Experience building or maturing an AppSec program from an early stage.
  • Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.
  • Red team experience performing internal campaigns and providing remediation reports

Benefits

  • Competitive pay with equity options
  • Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options
  • Company-sponsored disability & life insurance
  • Unlimited PTO
  • 401(k) + 4% Matching
  • Fully remote work + flexible working hours
  • $750 work-from-home setup budget
  • Paid biannual in-person company summits
  • Quarterly $150 co-hanging stipend to meet up with coworkers
  • Monthly $100 health and wellness benefit
  • Generous paid family leave
  • Annual $1,200 learning & development stipend
  • About Turquoise Health
  • Turquoise Health is a Series C price transparency platform for finance leaders across healthcare. Backed by a16z, Oak HC/FT, Adams Street, Yosemite, Bessemer Venture Partners, and others, we power price transparency for 300+ enterprise organizations and are building the infrastructure for a more open, efficient healthcare marketplace. We're a remote-first, US-based team that values transparency, empathy, inclusivity, creativity, and ownership.
  • We operate on US business hours and work with clients entirely based in the US. For this role, we are seeking US-based candidates.
  • We strongly encourage BIPOC, people with disabilities, and LGBTQIA+ folks to apply for any open roles of interest. Healthcare affects all people differently, but it significantly affects those in underserved communities. With a robust, diverse team, we are stronger and better equipped to change the future of healthcare for all.
  • Work Authorization
  • This role requires current authorization to work in the United States. Turquoise does not sponsor employment visas (H-1B, PERM, etc.) or assume sponsorship of existing visas for this position.
  • Disability Accommodation Email

Where you’d work

Fully remote

You can work from

  • United States

No visa sponsorship

About the company

Turquoise Health

  • Industry: HealthTech

6 of their 6 open roles are remote

Your chances

We've checked whether it's still hiring and how crowded it is.

  • 21 checks run
  • 0 red flags

Still hiring?

14 checks

No red flags

How crowded?

7 checks

No red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details14 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • Python
  • Go
  • AWS
  • Terraform
  • CI/CD
Seniority
Senior
Type
Full-time
Equity
Equity offered
Industry
HealthTech
Specialty
Security
Show 8 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
5+ years
Tech stack
  • Python
  • Go
  • AWS
  • Terraform
  • CI/CD

Location

Work model
Remote
Region
United States
Remote from
  • United States
Visa sponsorship
Not sponsored

Compensation

Salary
$172,000 - 200,000 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
HealthTech

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason