Zocdoc logo

Application Security Engineer

Zocdoc

United StatesRemoteFull-time$100–140K/yrPosted 1mo agoVerified open 3 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
$100–140K/yr
Location
United StatesRemote
Schedule
Full-time
Work Authorization
Not specified

Job overview

Zocdoc is hiring an Application Security Engineer. Zocdoc seeks an Application Security Engineer to help build secure software, collaborate with engineering squads, and shape AI governance guardrails, supporting the mission to empower patients through a secure healthcare marketplace.

Key focus areas include Serve as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines, Assist developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, and Provide clear, actionable guidance on remediating common application security vulnerabilities aligned to the OWASP Top 10.

Successful candidates bring Meaningful Experience In Information Security Role, Meaningful Experience In Software Engineering Position, and Meaningful Experience In IT Audit Function With Application Security Focus. Important skills include Secure Software Development, Application Security Governance, AI Governance Guardrails, Secure Development Lifecycle Guidelines, Static Analysis Tools, and Software Composition Analysis Tools. Preferred (not required): Reduce Risk, Autonomous, Urgent, and Creative.

Skills & qualifications

RequiredNice to have

Skills

Secure Software DevelopmentApplication Security GovernanceAI Governance GuardrailsSecure Development Lifecycle GuidelinesStatic Analysis ToolsSoftware Composition Analysis ToolsOWASP Top 10Internal Security DocumentationDeveloper PlaybooksSecure Coding Training MaterialsMonitoring Application Security MetricsGenAI ToolsAI Governance FrameworksAI-Enabled WorkflowsPrivacy GuardrailsSecurity GuardrailsSoftware Development ProcessesSecurity in Agile EnvironmentsCode Review ConceptsPythonJavaScriptGoJavaAWSGCPAzureGit WorkflowsVulnerability CategoriesWeb Application Security StandardsIntegrate Generative AI ToolsAutomate TasksFoster InnovationMaximize ProductivitySuperb Communication SkillsHumilityCollaborative ApproachReduce RiskAutonomousUrgentCreativeClear CommunicationAI Security RisksAutomated Workflows

Qualifications

Meaningful Experience in Information Security RoleMeaningful Experience in Software Engineering PositionMeaningful Experience in IT Audit Function With Application Security FocusBachelor's in Computer ScienceBachelor's in CybersecurityBachelor's in Related Technical FieldEquivalent Hands-on ExperienceSecurity+ CertificationGSEC CertificationCEH Certification

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
401(k) Match
Parental Leave
Paid Time Off

Full job description

Our Mission

Healthcare should work for patients, but it doesn’t. In their time of need, they call down outdated insurance directories. Then wait on hold. Then wait weeks for the privilege of a visit. Then wait in a room solely designed for waiting. Then wait for a surprise bill. In any other consumer industry, the companies delivering such a poor customer experience would not survive. But in healthcare, patients lack market power. Which means they are expected to accept the unacceptable.

Zocdoc’s mission is to give power to the patient. To do that, we’ve built the leading healthcare marketplace that makes it easy to find and book in-person or virtual care in all 50 states, across +200 specialties and +12k insurance plans. By giving patients the ability to see and choose, we give them power. In doing so, we can make healthcare work like every other consumer sector, where businesses compete for customers, not the other way around. In time, this will drive quality up and prices down.

We’re 18 years old and the leader in our space, but we are still just getting started. If you like solving important, complex problems alongside deeply thoughtful, driven, and collaborative teammates, read on.

Your Impact to our Mission

Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.

You'll enjoy this role if you...

  • Personally motivated by helping teams build secure software and reduce risk before issues reach production.

  • Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.

  • Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.

  • Passionate about application security, secure coding, and improving how teams work within modern development environments.

  • A clear communicator who can make security concepts approachable and actionable for technical partners.

  • The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.

  • Serious about your work, but not about yourself. Your day to day is...

  • Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.

  • Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.

  • Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.

  • Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.

  • Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.

  • Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.

  • Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails. You’ll be successful in this role if you have…

  • Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.

  • A foundational understanding of software development processes and how security fits into agile environments.

  • Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java.

  • Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows.

  • A conceptual understanding of vulnerability categories and web application security standards.

  • An interest in emerging technology trends, especially AI security risks and automated workflows.

  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.

  • A degree in Computer Science, Cybersecurity, or a related technical field is preferred, though equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly valued.

  • Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security. Benefits

  • Flexible work environment

  • Unlimited Vacation

  • 100% paid employee health benefit options (including medical, dental, and vision)

  • 401(k) with employer funded match

  • Corporate wellness program with Wellhub

  • Sabbatical leave (for employees with 5+ years of service)

  • Competitive paid parental leave and fertility/family planning reimbursement

  • Cell phone reimbursement

  • Employee Resource Groups and ZocClubs to promote shared community and belonging

  • Great Place to Work Certified Zocdoc is committed to fair and equitable compensation practices. Salary ranges are determined through alignment with market data. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills. Certain positions are also eligible for variable pay and/or equity; your recruiter will discuss the full compensation package details. NYC Base Salary Range $100,000 — $140,000 USD About us Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values . Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish.

Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone , we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better. We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.

Job Applicant Privacy Notice

You've read the whole posting — now see how you match it.