Secure, flexible, and scalable wallet infrastructure
Senior Security Engineer, Application Security
Location
United States
Posted
5 days ago
Salary
$175K - $275K / year
Job Description
About Us
Turnkey is developer-first infrastructure for private key management, making it simple to create wallets, sign transactions, and automate on-chain actions through one elegant API, without ever exposing sensitive key material. Founded by the team who scaled Coinbase Custody from zero to a $100M+ ARR business and helped protect over $100B in crypto assets, Turnkey is tackling crypto security at its foundational level. Our mission is to make strong cryptography the default across the open internet the same way AWS made scalable computing the default for software.
Our team is low-ego, high-agency, and high-autonomy, with a significant amount of combined experience in cryptography, security, and low-level systems. We're building the trustless, programmable infrastructure that will power the next wave of mass-market crypto applications and we're looking for people who want to shape what that future looks like.
Role Overview
We are hiring a Senior Application Security Engineer to join Turnkey's team and help ensure our systems, pipelines, and runtime environments are secure by design and resilient at scale.
You'll embed directly with product and infrastructure engineering teams, shaping how security is integrated into every aspect of our architecture. This is a hands-on, builder role ideal for someone who enjoys building secure systems from the ground up.
What You’ll Do
You will partner with Product and Engineering at both the design and development stage to ensure that we implement new features securely, including (but not limited to):
- Participating in the implementation efforts
- Doing security reviews
- Helping with product design decisions
- Auditing and surfacing vulnerabilities in our current products
- Conducting threat modeling and security assessments for new features and systems, identifying risks early and shaping secure architectural decisions.
- Developing and improving our Automated Tooling: further enhancing our automated tooling to scale our product security capabilities and find potential code problems both before and after we deploy
- Making the safe way, the easy way: work on defining and building application guardrails so that developers can build securely by default
- Investigating and remediating security issues, including vulnerabilities and incidents, and drive long-term improvements to prevent recurrence
- Embedding a culture of secure development across engineering, defining practices that influence how Turnkey builds, deploys, and maintains systems at scale.
What We're Looking For
- Bachelors degree in Computer Science, Engineering, or a related field
- 5+ years of experience in application or product security, ideally in fast-moving, high-impact or crypto-native environments
- Strong understanding of web, mobile, and cryptographic security fundamentals (e.g. OWASP Top Ten, SANS/CWE Top 25)
- Proficiency in programming and scripting languages (Typescript/Javascript, Go, Rust) and
experience building secure systems from the code up - Hands-on experience with security testing tools and methodologies (static/dynamic analysis, pen testing, etc.)
- Strong understanding of cloud, containerized, and runtime environments (AWS, GCP, Docker, Kubernetes), with the ability to embed security early in the SDLC
- Excellent analytical, problem-solving, and communication skills, with a collaborative mindset for partnering across product and infrastructure teams
- Curious, proactive, and passionate about building secure, reliable systems in a fast moving startup environment
- A builder mentality; comfortable operating with ambiguity, tackling incomplete systems, and applying hands-on engineering experience to security challenges.
Style Points
- Familiarity with crypto or DeFi systems and their unique security challenges
- Familiarity with threat modeling frameworks and cloud-native security tooling
What We Offer
- Full benefits, including medical, dental, vision, life, disability, HSA/FSA, 401(k) - detailed benefits overview available as we get further in the process
- Paid parental leave
- Unlimited PTO
- $3,000/yr learning and development budget to attend industry conferences
- Multiple team offsites per year
- Lunch stipend
Turnkey is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by law. We encourage individuals of all backgrounds to apply.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Offensive Security Engineer
Wraithwatch CorporationWraithwatch was founded by security engineers from SpaceX, Palantir, and Anduril to build the next generation of AI-powered cyber defense systems for the United States and its allies. We are deployed today to customers spanning Fortune 500, US Federal Government, commercial nuclear, aerospace, defense, maritime, and other emerging technology companies. Our core product is a cyber defense platform utilizing generative artificial intelligence agents to autonomously model a digital twin of an organization's entire IT and cybersecurity environment and analyze it for weaknesses, misconfigurations, and chains of possible attack.
The Offensive Security Engineer will continuously harden the company and product against advanced threats by teaching the system expert attack tradecraft and evolving it to execute autonomously. This role involves daily building and shipping with the core product engineers, focusing on practical application rather than pure research.
Network Security Consultant
CC Pace SystemsCC Pace is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, or any other protected characteristic under federal, state, or local laws. CC Pace is committed to employing only candidates who are legally authorized to work in the United States. For us to comply with the Immigration Reform and Control Act of 1986, all new employees, as a condition of employment, must complete the Employment Eligibility Verification Form I-9 and provide documentation that establishes identity and authorization to work. E-Verify will be used for employment verification as part of your onboarding process. CC Pace values integrity throughout our hiring process. As part of our standard verification procedures, candidates will be asked to provide documentation confirming employment history, education, and work authorization.
We are seeking an experienced Palo Alto Network Security Consultant to lead and support critical network security efforts in our client's transition to public cloud infrastructure. This role is a key contributor to two main initiatives: Migrating Zscaler security policies to Palo...
The Lead Software Engineer will implement key control automation on Microsoft Azure and Amazon AWS, involving managing discussions with Control Owners and mapping control processes. Duties include automating key controls like key recycling, ensuring VM compliance, and developing frameworks for specialized serverless environments.
Identify vulnerabilities and potential exposure across enterprise networks, systems, and applications through continuous security assessments. Conduct technical and non-technical risk assessments of technology environments, including local systems, network infrastructure, applica...