Application Security Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 63d ago
The date the source published, not the day we noticed it (2026-07-13). Last seen at its source 1h ago.
Is it remote?
USA Remote
That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay
$100k–140k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
greenhouse employer's own board first seen 12d ago · last seen 1h ago
The listing
Our Mission
You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.
We’re here to give power to the patient.
For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.
Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting. We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.
Fixing healthcare starts with fixing access to it. And we're still just getting started.
Your Impact to our Mission
Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.
You'll enjoy this role if you...
- Personally motivated by helping teams build secure software and reduce risk before issues reach production.
- Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.
- Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.
- Passionate about application security, secure coding, and improving how teams work within modern development environments.
- A clear communicator who can make security concepts approachable and actionable for technical partners.
- The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.
- Serious about your work, but not about yourself.
Your day to day is...
- Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
- Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
- Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
- Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
- Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
- Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.
- Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails.
You’ll be successful in this role if you have…
- Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.
- A foundational understanding of software development processes and how security fits into agile environments.
- Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java.
- Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows.
- A conceptual understanding of vulnerability categories and web application security standards.
- An interest in emerging technology trends, especially AI security risks and automated workflows.
- Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
- A degree in Computer Science, Cybersecurity, or a related technical field is preferred, though equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly valued.
- Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security.
Benefits
- Flexible work environment
- Unlimited Vacation
- 100% paid employee health benefit options (including medical, dental, and vision)
- 401(k) with employer funded match
- Corporate wellness program with Wellhub
- Sabbatical leave (for employees with 5+ years of service)
- Competitive paid parental leave and fertility/family planning reimbursement
- Cell phone reimbursement
- Employee Resource Groups and ZocClubs to promote shared community and belonging
- Great Place to Work Certified
About us
Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values. Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish.
Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better. We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.
Job Applicant Privacy Notice