hirly

Turquoise Health

Senior Application Security Engineer

Remote

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Turquoise Health first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Senior
Stated salary
$172,000 – $200,000 per year
Country
US
Work mode
Remote-friendly
First seen by hirly
3 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

What You'll Do

Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.

Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.

Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.

Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).

Perform threat modeling and maintain secure-coding standards.

Support incident response for application-layer security issues.

Coordinate and help manage third-party penetration tests.

Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.

What You'll Bring

5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.

Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.

Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.

Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.

Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.

A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.

Nice to Have

Experience in healthcare, fintech, or another regulated industry.

Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.

Security certifications such as OSCP, GWAPT, or CSSLP.

Experience building or maturing an AppSec program from an early stage.

Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.

Red team experience performing internal campaigns and providing remediation reports

Benefits

Competitive pay with equity options

Stellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA options

Company-sponsored disability & life insurance

Unlimited PTO

401(k) + 4% Matching

Fully remote work + flexible working hours

$750 work-from-home setup budget

Paid biannual in-person company summits

Quarterly $150 co-hanging stipend to meet up with coworkers

Monthly $100 health and wellness benefit

Generous paid family leave

Annual $1,200 learning & development stipend

About Turquoise Health

Turquoise Health is a Series C price transparency platform for finance leaders across healthcare. Backed by a16z, Oak HC/FT, Adams Street, Yosemite, Bessemer Venture Partners, and others, we power price transparency for 300+ enterprise organizations and are building the infrastructure for a more open, efficient healthcare marketplace. We're a remote-first, US-based team that values transparency, empathy, inclusivity, creativity, and ownership.

We operate on US business hours and work with clients entirely based in the US. For this role, we are seeking US-based candidates.

We strongly encourage BIPOC, people with disabilities, and LGBTQIA+ folks to apply for any open roles of interest. Healthcare affects all people differently, but it significantly affects those in underserved communities. With a robust, diverse team, we are stronger and better equipped to change the future of healthcare for all.

Work Authorization

This role requires current authorization to work in the United States. Turquoise does not sponsor employment visas (H-1B, PERM, etc.) or assume sponsorship of existing visas for this position.

Disability Accommodation Email

Turquoise is committed to providing reasonable accommodations to applicants and employees with disabilities. Please tell us if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require assistance or an accommodation with the hiring process, please contact [email protected]

Original posting on Turquoise Health's site ↗

Listed on hirly, a job board. hirly is not the employer: Turquoise Health is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job