T

Senior Application Security Engineer

turquoise • United State
Remote
Apply Now

Turquoise is seeking a Senior Application Security Engineer to lead application-layer security and drive vulnerability management across their platform. This role involves building and tuning security scanning programs, partnering with engineering teams on secure design and remediation, and performing threat modeling. The ideal candidate has 5+ years of experience in application security and a strong understanding of common vulnerability classes.

Key Highlights
Owns application-layer security and drives security for applications and data.
Builds and tunes application security scanning programs (SAST, DAST, SCA, container, IaC).
Partners closely with engineering teams on secure design, architecture, and vulnerability remediation.
Key Responsibilities
Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.
Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.
Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.
Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).
Perform threat modeling and maintain secure-coding standards.
Support incident response for application-layer security issues.
Coordinate and help manage third-party penetration tests.
Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.
Technical Skills Required
Application Security SAST DAST
Benefits & Perks
Competitive pay with equity options
Stellar health care plan options
Unlimited PTO
Nice to Have
Experience in healthcare, fintech, or another regulated industry.
Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.
Security certifications such as OSCP, GWAPT, or CSSLP.
Experience building or maturing an AppSec program from an early stage.
Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.
Red team experience performing internal campaigns and providing remediation reports

Job Description

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.
Want the full job description? Read the complete details on LinkedIn, the original posting.
Continue on LinkedIn

This is a short excerpt. All rights to the full description belong to its original publisher.

See Jaabz jobs first on Google 1 tap · free · in AI Overviews Jaabz is on your Google Manage Preferred Sources

Similar Jobs

Explore other opportunities that match your interests

Principal Cyber Threat Intelligence Analyst

Cyber Security
•
1d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

whatjobs.com

United State

Senior DevSecOps Security Engineer (Hybrid) - L-CAP Platform

Cyber Security
•
1d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Leidos

United State

Security Engineer, Detection & Response

Cyber Security
•
1d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Vercel

United State

Subscribe our newsletter

New Things Will Always Update Regularly