What You'll DoBuild and run our application security scanning program (SAST, DAST, dependency/SCA, container and IaC scanning), tuning tools to reduce noise and surface real risk.Triage findings from scans, penetration tests, and bug bounty reports; prioritize by risk and track remediation through to closure.Partner with engineering teams to fix vulnerabilities, including hands-on debugging and code-level guidance when needed.Build trust and cooperation with engineering, product, and design teams so security is considered early in the process, not bolted on at the end (mature SDLC, CI/CD pipelines).Perform threat modeling and maintain secure-coding standards.Support incident response for application-layer security issues.Coordinate and help manage third-party penetration tests.Track and report on security posture metrics (open vulnerabilities, remediation SLAs, scan coverage) to engineering and leadership.What You'll Bring5+ years of experience in application security, security engineering, or a related software engineering role with a security focus.Hands-on experience with SAST, DAST, and dependency/SCA scanning tools, and the judgment to distinguish real risk from noise.Deep understanding of common vulnerability classes (OWASP Top 10, authentication/authorization flaws, injection, SSRF, etc.), including the ability to review code and architecture to spot these issues and propose effective fixes.Experience with cloud environments (AWS preferred) and securing modern CI/CD pipelines.Strong communication skills, able to explain risk and remediation steps clearly to engineers and non-security stakeholders alike.A collaborative, pragmatic approach to security that balances risk reduction with shipping velocity.Nice to HaveExperience in healthcare, fintech, or another regulated industry.Experience working within compliance frameworks such as HIPAA, SOC 2, or GDPR.Security certifications such as OSCP, GWAPT, or CSSLP.Experience building or maturing an AppSec program from an early stage.Scripting or automation experience (Python, Go, Terraform, or infrastructure-as-code tool like Terraform.Red team experience performing internal campaigns and providing remediation reportsBenefitsCompetitive pay with equity optionsStellar health care plan options (Medical, Dental & Vision), with FSA, DCFSA, & HSA optionsCompany-sponsored disability & life insuranceUnlimited PTO401(k) + 4% MatchingFully remote work + flexible working hours$750 work-from-home setup budgetPaid biannual in-person company summitsQuarterly $150 co-hanging stipend to meet up with coworkersMonthly $100 health and wellness benefitGenerous paid family leaveAnnual $1,200 learning & development stipendAbout Turquoise HealthTurquoise Health is a Series C price transparency platform for finance leaders across healthcare. Backed by a16z, Oak HC/FT, Adams Street, Yosemite, Bessemer Venture Partners, and others, we power price transparency for 300+ enterprise organizations and are building the infrastructure for a more open, efficient healthcare marketplace. We're a remote-first, US-based team that values transparency, empathy, inclusivity, creativity, and ownership.We operate on US business hours and work with clients entirely based in the US. For this role, we are seeking US-based candidates.We strongly encourage BIPOC, people with disabilities, and LGBTQIA+ folks to apply for any open roles of interest. Healthcare affects all people differently, but it significantly affects those in underserved communities. With a robust, diverse team, we are stronger and better equipped to change the future of healthcare for all.