Senior Application Security Engineer
This is a fully remote role in the United States.
Turquoise is hiring a Senior Application Security Engineer to drive security for the applications and data our customers rely on. This role owns application-layer security across Turquoise's platform and is the software counterpart to our infrastructure security. You'll build and tune our code scanning program, driving vulnerabilities from discovery to remediation. Day to day, you'll work closely with engineering teams on the design, architecture, and services our product teams build.
What You'll Do
Build and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.
Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.
Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.
Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).