Zocdoc
Application Security Engineer
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 12 days ago · Added 5 days ago
First listed 12 days ago and still open.
Salary
$100k to $140k per year
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Mid
Category
Finance
Stated by the employer in the job description
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "USA Remote, New York"
What Nomaders makes of it
- Residency required in United States
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Our Mission
You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.
We’re here to give power to the patient.
For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.
Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting . We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.
Fixing healthcare starts with fixing access to it. And we're still just getting started.
Your Impact to our Mission
Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.
You'll enjoy this role if you...
Personally motivated by helping teams build secure software and reduce risk before issues reach production.
Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.
Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.
Passionate about application security, secure coding, and improving how teams work within modern development environments.
A clear communicator who can make security concepts approachable and actionable for technical partners.
The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.
Serious about your work, but not about yourself.
Your day to day is...
Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.
Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails.
Requirements
- ·Your day to day is...
- ·Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
- ·Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
- ·Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
- ·Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
Benefits
- ·Flexible work environment
- ·Unlimited Vacation
- ·100% paid employee health benefit options (including medical, dental, and vision)
- ·401(k) with employer funded match
- ·Corporate wellness program with Wellhub
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Zocdoc, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open finance roles with comparable remote rules.
Free to apply, no account needed.
$100k to $140k per year · You'll be taken to the employer's careers page.