Senior Application Security Engineer
New
T
Turquoise HealthHealthcare technology
This is a fully remote role in the United States. For this role, we are seeking US-based candidates., US business hoursFull-TimeSenior
Salary$172K - $200K; $172K – $200K • Offers Equity; Starting Salary Range $172K – $200K • Offers Equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.
- Required Skills
- AWSCI/CD
Requirements
- Have 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.
- Have hands-on experience with SAST, DAST, and dependency/SCA scanning tools.
- Understand common vulnerability classes, including OWASP Top 10, authentication and authorization flaws, injection, and SSRF.
- Be able to review code and architecture to identify security issues and propose effective fixes.
- Have experience with cloud environments; AWS is preferred.
- Have experience securing modern CI/CD pipelines.
- Experience in healthcare, fintech, or another regulated industry is a nice-to-have.
- Experience with HIPAA, SOC 2, or GDPR compliance frameworks is a nice-to-have.
- Security certifications such as OSCP, GWAPT, or CSSLP are a nice-to-have.
- AppSec program development, scripting or automation, or red team experience is a nice-to-have.
Responsibilities
- Build and run the application security scanning program, including SAST, DAST, dependency/SCA, container, and IaC scanning.
- Tune scanning tools to reduce noise and surface real risk.
- Triage findings from scans, penetration tests, and bug bounty reports; prioritize risk and track remediation through closure.
- Partner with engineering teams to fix vulnerabilities through hands-on debugging and code-level guidance.
- Work with engineering, product, and design teams to integrate security early in the SDLC and CI/CD pipelines.
- Perform threat modeling and maintain secure-coding standards.
- Support incident response for application-layer security issues and coordinate third-party penetration tests.
- Track and report security posture metrics, including open vulnerabilities, remediation SLAs, and scan coverage.
View Full Description & ApplyYou'll be redirected to the employer's site