SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer

Turquoise Health - Remote - Remote - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Turquoise Health is a Series C healthcare price transparency platform backed by a16z and other leading VCs. They're seeking a Senior Application Security Engineer to own application-layer security across their platform and drive security practices across engineering teams. In this role, you'll build and operate Turquoise's application security scanning program, including SAST, DAST, dependency/SCA, container, and IaC scanning. You'll triage findings from automated scans, penetration tests, and bug bounty reports, prioritizing by risk and tracking remediation to closure. You'll partner directly with engineering teams on vulnerability fixes, providing hands-on debugging and code-level guidance. A key part of the role is building trust with engineering, product, and design teams to embed security early in the development process rather than as an afterthought. You'll perform threat modeling, maintain secure-coding standards, support incident response for application-layer issues, coordinate third-party penetration tests, and track security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) for reporting to engineering and leadership. Turquoise is remote-first and US-based, operating on US business hours. The team values transparency, empathy, inclusivity, creativity, and ownership. REQUIREMENTS: - 5+ years of experience in application security, security engineering, or software engineering with a security focus - Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, with judgment to distinguish real risk from noise - Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including ability to review code and architecture to spot issues and propose fixes - Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines - Strong communication skills to explain risk and remediation clearly to engineers and non-security stakeholders - Collaborative, pragmatic approach to security that balances risk reduction with shipping velocity NICE TO HAVE: - Experience in healthcare, fintech, or other regulated industries - Experience with compliance frameworks (HIPAA, SOC 2, GDPR) - Security certifications (OSCP, GWAPT, CSSLP) - Experience building or maturing an AppSec program from early stage - Scripting/automation experience (Python, Go, Terraform, or infrastructure-as-code tools) - Red team experience with internal campaigns and remediation reporting

Similar roles