Twin Health invented the Whole Body Digital Twin™ to help reverse and prevent chronic metabolic diseases.
Application Security Engineer
Location
United States
Posted
5 days ago
Salary
Not specified
Job Description
Role Description
We are seeking a highly motivated Application Security Engineer to join our growing security organization. This role will be instrumental in building and managing our application and cloud security capabilities from the ground up, ensuring Twin Health’s systems and products remain secure as we scale globally.
You will work hands-on with a modern technology stack including AWS Security Hub, GuardDuty, Inspector, and Macie, while leading the implementation of a Cloud Security Posture Management (CSPM) solution through Wiz. You will also own our secure code scanning and vulnerability management pipeline, driving continuous improvement across SAST, DAST, and SOAR Cloud integrations.
This is a highly technical and strategic role suited for someone who thrives in building systems from scratch, automating workflows, and influencing secure development practices across engineering teams. Candidates must be located in EST.
Responsibilities
- Design, implement, and manage application and cloud security tooling across AWS, including Security Hub, GuardDuty, Macie, Inspector, and related automation.
- Lead the deployment and configuration of Wiz CSPM, collaborating with infrastructure and DevOps teams to enhance visibility and remediation workflows.
- Manage secure code scanning processes, integrating SAST (Static Analysis) and DAST (Dynamic Analysis) using Sonar Cloud to identify and remediate vulnerabilities early in the SDLC.
- Develop automated pipelines and playbooks for vulnerability triage, remediation tracking, and reporting of metrics. (MTTD, MTTR)
- Partner with software engineering teams to embed security into CI/CD pipelines and promote secure coding practices.
- Collaborate with the Security, IT, and GRC teams to ensure alignment with SOC 2, HIPAA, and SOX controls.
- Contribute to threat modeling, code review, and incident response related to application vulnerabilities.
- Evaluate and implement new security tools and processes to enhance the overall application security posture.
- Support vendor risk assessments and penetration testing efforts related to application components.
- Create and maintain security documentation, architecture diagrams, and operational runbooks.
- Participate in on-call rotations as part of the broader security operations program.
- Other duties as assigned.
Qualifications
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 1-3+ years of experience in Application Security, DevSecOps, or Cloud Security Engineering roles.
- Hands-on experience with AWS security services (Security Hub, GuardDuty, Inspector, Macie, IAM, KMS).
- Familiarity with Wiz or similar CSPM platforms.
- Proven experience integrating SAST/DAST tools (e.g., Soar Cloud, Veracode, Snyk, Checkmarx, Burp Suite, etc.) into CI/CD pipelines.
- Familiarity with Docker, K8S, and microservices-based architectures.
- Experience with WAF, endpoint security, and IAM.
- Strong understanding of secure software development lifecycle (SSDLC) and common vulnerabilities (OWASP Top 10, CWE, CVSS).
- Proficiency in at least one scripting or automation language (Python, Bash, or similar).
- Proficiency in Java.
- Knowledge of threat modeling, code review, and cloud infrastructure security best practices.
- Excellent collaboration and communication skills with both technical and non-technical stakeholders.
- Experience with compliance frameworks such as SOC 2, HIPAA, or HiTrust is a plus.
- Experience working in a high-growth or regulated environment is preferred.
Compensation and Benefits
- The compensation range for this position is $110,000 - $120,000 annually.
- A competitive compensation package in line with leading technology companies.
- A remote and accomplished global team.
- Opportunity for equity participation.
- Unlimited vacation with manager approval.
- 16 weeks of 100% paid parental leave for delivering parents; 8 weeks of 100% paid parental leave for non-delivering parents.
- 100% Employer sponsored healthcare, dental, and vision for you, and 80% coverage for your family; Health Savings Account and Flexible Spending Account options.
- 401k retirement savings plan.
Job Requirements
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 1-3+ years of experience in Application Security, DevSecOps, or Cloud Security Engineering roles.
- Hands-on experience with AWS security services (Security Hub, GuardDuty, Inspector, Macie, IAM, KMS).
- Familiarity with Wiz or similar CSPM platforms.
- Proven experience integrating SAST/DAST tools (e.g., Soar Cloud, Veracode, Snyk, Checkmarx, Burp Suite, etc.) into CI/CD pipelines.
- Familiarity with Docker, K8S, and microservices-based architectures.
- Experience with WAF, endpoint security, and IAM.
- Strong understanding of secure software development lifecycle (SSDLC) and common vulnerabilities (OWASP Top 10, CWE, CVSS).
- Proficiency in at least one scripting or automation language (Python, Bash, or similar).
- Proficiency in Java.
- Knowledge of threat modeling, code review, and cloud infrastructure security best practices.
- Excellent collaboration and communication skills with both technical and non-technical stakeholders.
- Experience with compliance frameworks such as SOC 2, HIPAA, or HiTrust is a plus.
- Experience working in a high-growth or regulated environment is preferred.
- Compensation and Benefits
- The compensation range for this position is $110,000 - $120,000 annually.
- A competitive compensation package in line with leading technology companies.
- A remote and accomplished global team.
- Opportunity for equity participation.
- Unlimited vacation with manager approval.
- 16 weeks of 100% paid parental leave for delivering parents; 8 weeks of 100% paid parental leave for non-delivering parents.
- 100% Employer sponsored healthcare, dental, and vision for you, and 80% coverage for your family; Health Savings Account and Flexible Spending Account options.
- 401k retirement savings plan.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
This opportunity as a Traveling Electronic Security Systems Technician is perfect for an experienced low-voltage technician who enjoys traveling! Installs, repairs, tests, and maintains security projects Serves as the face of Evergreen to our customers onsite by providing top-not...
The role involves assisting with the onboarding, design, performance, implementation, and capacity of the Splunk platform, coordinating with in-house teams to translate customer Cybersecurity & IT needs into secure solutions. Responsibilities include designing data models, programming data pipelines, improving data quality, implementing automation, and developing/enhancing applications and integrations.
Cybersecurity Program Lead
JobgetherWe use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
This role plays a critical part in supporting cybersecurity policy and oversight services. You will provide leadership and operational management to ensure the effective delivery of cybersecurity services across various programs. Collaborating closely with government leadership, ...
Cybersecurity Assessment and Authorization SME supporting DoD compliance and authorization processes.