Skip to content

Open nowPosted 7 hours ago

Senior Application Security Engineer

Turquoise Health16 open roles

Pay
$172,000 – $200,000 a year
Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Application Security EngineerTurquoise Health · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Turquoise Health's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Turquoise Health postings stay open a median of 10 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 7 hours ago

Turquoise Health median: 10 days open

The posting

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

WHAT YOU'LL DO

- Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.

- Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.

- Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.

- Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).

- Perform threat modeling and maintain secure-coding standards.

- Support incident response for application-layer security issues.

- Coordinate and help manage third-party penetration tests.

- Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.

WHAT YOU'LL BRING

- 5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.

- Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.

- Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.

- Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.

- Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.

- A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.

NICE TO HAVE

- Experience in healthcare, fintech, or another regulated industry.

- Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.

- Security certifications such as OSCP, GWAPT, or CSSLP.

- Experience building or maturing an AppSec program from an early stage.

- Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.

- Red team experience performing internal campaigns and providing remediation reports

BENEFITS

- Competitive pay with equity options

- Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options

- Company-sponsored disability & life insurance

- Unlimited PTO

- 401(k) + 4% Matching

- Fully remote work + flexible working hours

- $750 work-from-home setup budget

- Paid biannual in-person company summits

- Quarterly $150 co-hanging stipend to meet up with coworkers

- Monthly $100 health and wellness benefit

- Generous paid family leave

- Annual $1,200 learning & development stipend

ABOUT TURQUOISE HEALTH

Turquoise Health is a Series C price transparency platform for finance leaders across healthcare. Backed by a16z, Oak HC/FT, Adams Street, Yosemite, Bessemer Venture Partners, and others, we power price transparency for 300+ enterprise organizations and are building the infrastructure for a more open, efficient healthcare marketplace. We're a remote-first, US-based team that values transparency, empathy, inclusivity, creativity, and ownership.

We operate on US business hours and work with clients entirely based in the US. For this role, we are seeking US-based candidates.

We strongly encourage BIPOC, people with disabilities, and LGBTQIA+ folks to apply for any open roles of interest. Healthcare affects all people differently, but it significantly affects those in underserved communities. With a robust, diverse team, we are stronger and better equipped to change the future of healthcare for all.

WORK AUTHORIZATION

This role requires current authorization to work in the United States. Turquoise does not sponsor employment visas (H-1B, PERM, etc.) or assume sponsorship of existing visas for this position.

DISABILITY ACCOMMODATION EMAIL

Turquoise is committed to providing reasonable accommodations to applicants and employees with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require assistance or an accommodation with the hiring process, please contact [email protected]

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Turquoise Health's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Turquoise Health's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Turquoise Health's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.