Turnkey, founded in 2022 and headquartered in New York, New York, provides secure and scalable crypto infrastructure focused on embedded wallets and on-chain transaction automation
Senior Security Engineer – Application Security
Location
United States
Posted
128 days ago
Salary
0
Seniority
Senior
Job Description
Senior Security Engineer – Application Security
Turnkey
• You will partner with Product and Engineering at both the design and development stage to ensure that we implement new features securely, including (but not limited to): - Participating in the implementation efforts - Doing security reviews - Helping with product design decisions - Auditing and surfacing vulnerabilities in our current products - Conducting threat modeling and security assessments for new features and systems, identifying risks early and shaping secure architectural decisions. - Developing and improving our Automated Tooling: further enhancing our automated tooling to scale our product security capabilities and find potential code problems both before and after we deploy - Making the safe way, the easy way: work on defining and building application guardrails so that developers can build securely by default - Investigating and remediating security issues, including vulnerabilities and incidents, and drive long-term improvements to prevent recurrence - Embedding a culture of secure development across engineering, defining practices that influence how Turnkey builds, deploys, and maintains systems at scale.
Job Requirements
- Bachelors degree in Computer Science, Engineering, or a related field
- 5+ years of experience in application or product security, ideally in fast-moving, high-impact or crypto-native environments
- Strong understanding of web, mobile, and cryptographic security fundamentals (e.g. OWASP Top Ten, SANS/CWE Top 25)
- Proficiency in programming and scripting languages (Typescript/Javascript, Go, Rust) and experience building secure systems from the code up
- Hands-on experience with security testing tools and methodologies (static/dynamic analysis, pen testing, etc.)
- Strong understanding of cloud, containerized, and runtime environments (AWS, GCP, Docker, Kubernetes), with the ability to embed security early in the SDLC
- Excellent analytical, problem-solving, and communication skills, with a collaborative mindset for partnering across product and infrastructure teams
- Curious, proactive, and passionate about building secure, reliable systems in a fast moving startup environment
- A builder mentality; comfortable operating with ambiguity, tackling incomplete systems, and applying hands-on engineering experience to security challenges.
- Familiarity with crypto or DeFi systems and their unique security challenges
- Familiarity with threat modeling frameworks and cloud-native security tooling
Benefits
- Full benefits, including medical, dental, vision, life, disability, HSA/FSA, 401(k) - detailed benefits overview available as we get further in the process
- Paid parental leave
- Unlimited PTO (and we will force you to take time off!)
- $3,000/yr learning and development budget to attend industry conferences
- Multiple team offsites per year
- Macbook Pro laptop
- Lunch stipend (for those physically in the New York City office)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer
Docker, IncDocker helps developers bring their ideas to life by conquering the complexity of app development.
• Work with leadership to align security initiatives with business goals, ensuring that security is a core component of product and infrastructure • Take ownership and drive implementation for key programs such as vulnerability management, cloud governance, and product security • Serve as a security subject matter expert for software security and architecture • Partner with engineering to design and implement security architecture and controls across Docker products and platforms • Perform security design reviews and threat modeling of emerging AI products • Integrate security into SDLC through security requirements, design assessments, and automated security testing • Manage Docker’s Vulnerability Disclosure Program (VDP) by validating submissions, and working with engineering to resolve confirmed issues • Design and enforce security configurations in cloud environments (e.g. AWS, GCP, Azure) according to industry best practices • Establish automated monitoring and alerting to detect security anomalies across our environments • Serve on rotating on-call schedule to respond to security incidents, investigate threats, and coordinate remediation efforts • Educate and collaborate with cross-functional teams (e.g., engineering, product) to promote security practices
Senior Security Analyst
Control RisksThe global specialist risk consultancy - Helping organisations succeed in a volatile world
• As a Minor Safety Senior Analyst supporting our client, you will play a critical role in helping a major global technology company maintain a secure and resilient online environment. • Review abuse and safety incident reports, specifically targeting minors on the client’s platform, take appropriate action per operations policies and follow through clearly and consistently on every report • Investigate behavioral abuse and threat actors on the Client’s platform in order to understand techniques, impact and attribution • Participate in high velocity analytic workflow ensuring tight deadlines are consistently met, a high bar of analytic excellence is consistently applied and reporting deliverables reflect best practice intelligence assessments. • Prepare written analytic products, presentations and strategic insights for senior leadership and to the broader organization. • Drive improvement initiatives by providing guidance on policy development and executing projects that will enhance existing workflows • Review team members’ work, provide feedback, create and deliver training • Identify and escalate new issues and trends • Assist in improving our support resources and content • Serve as a consultative partner with our vendor team and provide expertise for processing all types of requests with a high degree of quality and efficiency • You set an example and are an active mentor of others, showing flexibility and impeccable teamwork in order to effectively prioritize competing demands.
Master Network Engineer – Security Infrastructure
GovCIOGovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.
• Design, implement, and operate next-generation firewall and web security proxy solutions, ensuring secure, high-availability network operations across data centers and nationwide field locations • Design, implement, and maintain Palo Alto Networks next-generation firewall solutions, including security policies, NAT, VPNs, threat prevention, URL filtering, and decryption • Engineer and support Cisco routing and switching infrastructure across LAN/WAN environments • Design and maintain secure network architectures incorporating firewalls, web proxies, VPNs, and access control technologies • Deploy, configure, and support McAfee Web Security Proxy (Web Gateway) to enforce web filtering, malware protection, and acceptable use policies • Integrate firewall and proxy solutions with authentication systems (Active Directory, LDAP, RADIUS, TACACS+) • Monitor security platforms for threats, performance issues, and policy violations • Analyze logs and alerts to identify security incidents and implement mitigation strategies • Perform configuration reviews, rulebase optimization, and security hardening
Cybersecurity Specialist
GFT TechnologiesAs a pioneer for digital transformation GFT develops sustainable solutions across new technologies.
• Supports the creation of architecture standards, patterns and reference models. • Conducts technical security assessments for systems, clouds, applications or networks. • Conduct threat analysis and identify common security gaps. • Provides recommend security architecture and improvements aligned with GFT standards and hardening guidelines. • Work with cross-functional teams to clarify design requirements. • Improves and optimizes processes and security standards and hardenings.



