Loading jobs…
Loading jobs…
Zocdoc
Our Mission Healthcare should work for patients, but it doesn’t. In their time of need, they call down outdated insurance directories. Then wait on hold.
Then wait weeks for the privilege of a visit. Then wait in a room solely designed for waiting. Then wait for a surprise bill.
In any other consumer industry, the companies delivering such a poor customer experience would not survive. But in healthcare, patients lack market power. Which means they are expected to accept the unacceptable.
Zocdoc’s mission is to give power to the patient. To do that, we’ve built the leading healthcare marketplace that makes it easy to find and book in-person or virtual care in all 50 states, across +200 specialties and +12k insurance plans. By giving patients the ability to see and choose, we give them power.
In doing so, we can make healthcare work like every other consumer sector, where businesses compete for customers, not the other way around. In time, this will drive quality up and prices down. We’re 18 years old and the leader in our space, but we are still just getting started.
If you like solving important, complex problems alongside deeply thoughtful, driven, and collaborative teammates, read on. Your Impact to our Mission Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence.
In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business. You'll enjoy this role if you... Personally motivated by helping teams build secure software and reduce risk before issues reach production.
Autonomous, urgent, and creative.
Requirements
into practical guidance for developers. Highly collaborative and energized by partnering with engineering squads across the software development lifecycle. Passionate about application security, secure coding, and improving how teams work within modern development environments.
A clear communicator who can make security concepts approachable and actionable for technical partners. The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows. Serious about your work, but not about yourself.
Your day to day is... Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines. Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10. Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable. Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting. Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails. You’ll be successful in this role if you have… Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.
A foundational understanding of software development processes and how security fits into agile environments.