应用安全工程师
Application Security Engineer
我们的使命
你打电话。你等待。你再次打电话。在生活的其他方面,你几秒钟就能完成预订。但在医疗领域,你却受阻了。
我们致力于赋予患者力量。
近20年来,我们打造了领先的医疗市场——帮助数千万人找到并预约他们需要的医疗服务。现在,我们进一步拓展:将我们的基础设施从Zocdoc市场扩展到患者搜索医疗资源的任何地方,包括医疗机构网站、保险公司目录、搜索引擎、AI平台等。
医疗行业仍然缺乏其他主要消费行业所拥有的东西:一种从寻求到获得的无缝体验。我们不想拥有医疗的入口;没有这样的入口。我们想确保当患者敲门时,所有的门都能打开。
解决医疗问题始于解决获取医疗的途径。而我们才刚刚开始。
你的贡献
Zocdoc最重要的资产是我们的员工。作为应用安全工程师,你将在帮助开发团队自信地构建安全软件方面发挥重要作用。在这个职位上,你将与合规、安全和工程团队紧密合作,支持我们的安全软件开发生命周期,加强应用安全治理,并帮助塑造整个业务中的新兴AI治理准则。
如果你...
- 个人动机来自于帮助团队在问题进入生产环境之前构建安全的软件并降低风险。
- 自主、紧迫且富有创造力。你真正热爱将安全需求转化为对开发者的实用指导。
- 高度协作,乐于与工程团队在整个软件开发生命周期中合作。
- 对应用安全、安全编码以及改进团队在现代开发环境中的工作方式充满热情。
- 是一位清晰的沟通者,能够将安全概念转化为技术合作伙伴可理解且可操作的内容。
- 是那种对新兴技术趋势感到兴奋的人,尤其是AI安全风险和自动化流程。
- 认真对待工作,但不自视过高。
你的日常职责包括...
- 成为工程团队的可接触联系人,帮助团队理解并遵循安全开发生命周期指南。
- 协助开发人员审查和解读静态分析和软件组成分析工具的警报,包括帮助区分
查看英文原文
Our Mission
You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.
We’re here to give power to the patient.
For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.
Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting. We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.
Fixing healthcare starts with fixing access to it. And we're still just getting started.
Your Impact to our Mission
Zocdoc’s most important asset is our people. As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence. In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.
You'll enjoy this role if you...
- Personally motivated by helping teams build secure software and reduce risk before issues reach production.
- Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.
- Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.
- Passionate about application security, secure coding, and improving how teams work within modern development environments.
- A clear communicator who can make security concepts approachable and actionable for technical partners.
- The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.
- Serious about your work, but not about yourself.
Your day to day is...
- Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
- Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
- Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
- Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
- Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
- Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.
- Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails.
You’ll be successful in this role if you have…
- Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.
- A foundational understanding of software development processes and how security fits into agile environments.
- Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java.
- Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows.
- A conceptual understanding of vulnerability categories and web application security standards.
- An interest in emerging technology trends, especially AI security risks and automated workflows.
- Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
- A degree in Computer Science, Cybersecurity, or a related technical field is preferred, though equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly valued.
- Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security.
Benefits
- Flexible work environment
- Unlimited Vacation
- 100% paid employee health benefit options (including medical, dental, and vision)
- 401(k) with employer funded match
- Corporate wellness program with Wellhub
- Sabbatical leave (for employees with 5+ years of service)
- Competitive paid parental leave and fertility/family planning reimbursement
- Cell phone reimbursement
- Employee Resource Groups and ZocClubs to promote shared community and belonging
- Great Place to Work Certified
Zocdoc is committed to fair and equitable compensation practices. Salary ranges are determined through alignment with market data. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills. Certain positions are also eligible for variable pay and/or equity; your recruiter will discuss the full compensation package details.
NYC Base Salary Range
$100,000—$140,000 USD
About us
Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values. Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish.
Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better. We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.
Job Applicant Privacy Notice