Turquoise

Senior Application Security Engineer

Remote·$172K–200K

code scanning

This is a fully remote role in the United States.

Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.

WHAT YOU'LL DO

  • Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.
  • Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.
  • Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.
  • Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).
  • Perform threat modeling and maintain secure-coding standards.
  • Support incident response for application-layer security issues.
  • Coordinate and help manage third-party penetration tests.
  • Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.

WHAT YOU'LL BRING

  • 5+ years of experience in application security, security engineering, o
Read the rest on jobs.ashbyhq.com