Zocdoc logo

Zocdoc

Senior Staff Security Engineer, Vulnerability Management

Work from home

Remote role where the employee must remain based in a particular country.

United States only

Employer listed it 12 days ago · Added 5 days ago

First listed 12 days ago and still open.

Salary

$200k to $290k per year

Location

United States only

Timezone

US East

Contract

Full-time

Experience

Lead

Category

Finance

Stated by the employer in the job description

Remote flexibility

Work from home

This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.

What the employer says

  • Source listing states candidate location: "USA Remote, New York"

What Nomaders makes of it

  • Residency required in United States
  • Payroll and tax are likely handled in that country only

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

Our Mission

You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.

We’re here to give power to the patient.

For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.

Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting . We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.

Fixing healthcare starts with fixing access to it. And we're still just getting started.

Your Impact on our Mission

Zocdoc’s most important asset is our people and our platform. As a Senior Staff Engineer, Vulnerability Management, you’ll play a meaningful role in strengthening both by architecting and scaling our next-generation vulnerability detection and remediation ecosystem across Compliance, Security, and Engineering. In this role, you’ll help move our security posture from reactive firefighting to predictive, continuous risk reduction through intelligent automation, deeper full-stack visibility, and faster remediation across infrastructure, containers, and application code.

You’ll enjoy this role if you are…

Personally motivated by building secure, scalable systems that reduce real-world risk at scale.

Autonomous, urgent, and creative, and you love turning noisy security findings into actionable engineering outcomes.

Highly collaborative and energized by working across Security, Compliance, Engineering, and DevOps teams.

Passionate about offensive security, adversarial validation, and understanding how theoretical vulnerabilities translate into operational exposure.

A systems thinker who can connect infrastructure, application security, compliance, and automation into one cohesive program.

The kind of person who enjoys pairing deep technical judgment with practical execution and measurable impact.

Serious about your work, but not about yourself.

Your day to day is…

Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software.

Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability.

Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams.

Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.

Partnering directly with Software Engineering and DevOps to build automated remediation pipelines, including dependency update pull requests and base-image patching workflows.

Engineering security scanning guardrails into CI/CD pipelines and providing structured telemetry to support continuous compliance and executive risk visibility.

Working with cutting-edge GenAI tools and technology to analyze findings, improve prioritization, and accelerate remediation workflows.

Requirements

  • ·Your day to day is…
  • ·Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software.
  • ·Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability.
  • ·Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams.
  • ·Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.

Benefits

  • ·Flexible work environment
  • ·Unlimited Vacation
  • ·100% paid employee health benefit options (including medical, dental, and vision)
  • ·401(k) with employer funded match
  • ·Corporate wellness programs with Headspace and Peloton

How to apply

  1. 1Check the flexibility label above, work from home, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Zocdoc, mentioning your remote working experience and working hours (US East).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open finance roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

$200k to $290k per year · You'll be taken to the employer's careers page.