Application Security Engineer

Zocdoc

United States

Remote

USD 100,000 - 140,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work environment
Unlimited Vacation
Health benefit options
401(k) with employer match
Sabbatical leave
Parental leave
Cell phone reimbursement
Wellness program
Employee Resource Groups

Job summary

Zocdoc seeks an Application Security Engineer to strengthen our secure software development lifecycle and AI governance. You will work with Compliance, Security, and Engineering to prevent vulnerabilities and guide developers through secure practices.

You’ll review alerts, provide remediation guidance, and help maintain security playbooks while coordinating with teams across the SDLC and GenAI initiatives. This role offers a flexible work environment and growth opportunities.

Qualifications

  • Experience in information security with software engineering focus.
  • Understanding of software development in agile environments.
  • Familiarity with code review concepts and major cloud languages (Python/JS/Go/Java).
  • Exposure to AWS, GCP, or Azure and Git workflows.
  • Interest in AI security risks and automated workflows.
  • Ability to integrate generative AI tools into daily workflows.

Responsibilities

  • Serve as a point of contact for engineering squads to follow secure development lifecycle guidelines.
  • Review alerts from static analysis and SCA tools and differentiate true vulnerabilities from false positives.
  • Provide actionable remediation guidance aligned to OWASP Top 10.
  • Maintain security documentation, playbooks, and secure coding training materials.
  • Support governance by tracking milestones and compiling evidence for audits.
  • Monitor vulnerability patch timelines and policy exceptions for leadership reporting.
  • Work with GenAI tools while aligning AI workflows with privacy and security guardrails.

Skills

Application security
Secure coding
Collaboration with engineering
Security governance
AI/security automation

Education

B.S. in Computer Science or related field
Security certifications (Security+, GSEC, CEH)

Tools

Static analysis tools
Software composition analysis
Cloud platforms (AWS, GCP, Azure)
Git workflows

Job description

Our Mission

Healthcare should work for patients, but it doesn’t. In their time of need, they call down outdated insurance directories. Then wait on hold. Then wait weeks for the privilege of a visit. Then wait in a room solely designed for waiting. Then wait for a surprise bill. In any other consumer industry, the companies delivering such a poor customer experience would not survive. But in healthcare, patients lack market power. Which means they are expected to accept the unacceptable.

Zocdoc’s mission is to give power to the patient. To do that, we’ve built the leading healthcare marketplace that makes it easy to find and book in-person or virtual care in all 50 states, across +200 specialties and +12k insurance plans. By giving patients the ability to see and choose, we give them power. In doing so, we can make healthcare work like every other consumer sector, where businesses compete for customers, not the other way around. In time, this will drive quality up and prices down.

We’re 18 years old and the leader in our space, but we are still just getting started. If you like solving important, complex problems alongside deeply thoughtful, driven, and collaborative teammates, read on.

Your Impact to our Mission

Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.

You’ll enjoy this role if you…
  • Personally motivated by helping teams build secure software and reduce risk before issues reach production.
  • Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.
  • Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.
  • Passionate about application security, secure coding, and improving how teams work within modern development environments.
  • A clear communicator who can make security concepts approachable and actionable for technical partners.
  • The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.
  • Serious about your work, but not about yourself.
Your day to day is…
  • Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
  • Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
  • Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
  • Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
  • Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
  • Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.
  • Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails.
You’ll be successful in this role if you have…
  • Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.
  • A foundational understanding of software development processes and how security fits into agile environments.
  • Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java.
  • Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows.
  • A conceptual understanding of vulnerability categories and web application security standards.
  • An interest in emerging technology trends, especially AI security risks and automated workflows.
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
  • A degree in Computer Science, Cybersecurity, or a related technical field is preferred, though equivalent hands‑on experience or certifications such as Security+, GSEC, or CEH are also highly valued.
  • Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security.
Benefits
  • Flexible work environment
  • Unlimited Vacation
  • 100% paid employee health benefit options (including medical, dental, and vision)
  • 401(k) with employer funded match
  • Corporate wellness program with Wellhub
  • Sabbatical leave (for employees with 5+ years of service)
  • Competitive paid parental leave and fertility/family planning reimbursement
  • Cell phone reimbursement
  • Employee Resource Groups and ZocClubs to promote shared community and belonging
  • Great Place to Work Certified

Zocdoc is committed to fair and equitable compensation practices. Salary ranges are determined through alignment with market data. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills. Certain positions are also eligible for variable pay and/or equity; your recruiter will discuss the full compensation package details.

NYC Base Salary Range

$100,000–$140,000 USD

About us

Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values. Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish.

Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better. We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.

Job Applicant Privacy Notice

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

Zocdoc • New York (NY)

On-site
USD 100,000 - 140,000
Flexible work environment
Unlimited vacation
100% paid employee health benefits
+7
Staff Software Engineer, Clinical Fit
Staff Software Engineer, Clinical Fit

Zocdoc • New York (NY)

On-site
USD 210,000 - 270,000
Unlimited Vacation
100% paid health benefits
401(k) with employer match
+3
Senior Software Engineer, Data
Senior Software Engineer, Data

Zocdoc • United States

On-site
USD 174,000 - 220,000
Flexible work environment
Unlimited Vacation
Health benefits
Client Success Manager, Enterprise Sales
Client Success Manager, Enterprise Sales

Zocdoc • New York (NY)

Hybrid
USD 85,000 - 115,000
Hybrid work
Unlimited vacation
Health benefits
+9
Staff Software Engineer, Scheduling
Staff Software Engineer, Scheduling

Zocdoc • New York (NY)

On-site
USD 180,000 - 270,000
Unlimited Vacation
100% paid employee health benefits
401(k) with employer match
+3
Staff Data Scientist, Marketplace Analytics
Staff Data Scientist, Marketplace Analytics

Zocdoc • New York (NY)

On-site
USD 200,000 - 270,000
Unlimited Vacation
100% paid employee health benefits
Commuter Benefits
+6
Lead Sales Recruiter
Lead Sales Recruiter

Francisco Partners • United States

On-site
USD 135,000 - 160,000
Unlimited Vacation
Health benefits
Commuter Benefits
+6
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Zocdoc • New York (NY)

Hybrid
USD 180,000 - 220,000
Unlimited Vacation
Health benefits
Commuter Benefits
+3
Data Science Manager Provider Product
Data Science Manager Provider Product

Zocdoc • Palo Alto (CA)

On-site
USD 190,000 - 270,000
Unlimited Vacation
Health benefits
401(k) with match
+1
Senior Director, Enterprise Sales
Senior Director, Enterprise Sales

Zocdoc • New York (NY)

On-site
USD 221,000 - 298,000
Hybrid work environment
Health benefits
401(k) match
+4