SlipstreamJobsFresh Startup & VC-Backed Jobs

Application Security Engineer

Zocdoc - Remote - Remote - posted 2026-07-13

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Zocdoc is a healthcare marketplace platform that empowers patients to find and book in-person or virtual care across all 50 states, 200+ specialties, and 12,000+ insurance plans. As an Application Security Engineer, you'll be a key member of the security organization, working closely with Compliance, Security, and Engineering teams to embed security into the software development lifecycle. Your primary responsibilities include serving as a trusted security advisor to engineering squads, helping teams understand and follow secure development guidelines. You'll assist developers in reviewing alerts from static analysis and software composition analysis tools, distinguishing true vulnerabilities from false positives. You'll provide clear, actionable remediation guidance for common application security vulnerabilities aligned to OWASP Top 10 standards. You'll maintain internal security documentation, developer playbooks, and secure coding training materials to ensure compliance expectations are clear and achievable. You'll support application security governance by tracking security milestones, organizing technical evidence from repositories and deployment pipelines for compliance audits, and monitoring key metrics including vulnerability patch timelines and policy exceptions for leadership reporting. A significant part of this role involves working with emerging GenAI tools and technology, supporting AI governance frameworks, and ensuring AI-enabled workflows align with privacy and security guardrails. You should have meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus. You'll need a foundational understanding of software development processes in agile environments, familiarity with code review concepts, and comfort reading at least one major language (Python, JavaScript, Go, or Java). Basic exposure to cloud environments (AWS, GCP, Azure) and Git workflows is expected. You should understand vulnerability categories and web application security standards, with a strong interest in AI security risks and automated workflows. A degree in Computer Science, Cybersecurity, or related field is preferred; equivalent hands-on experience or certifications (Security+, GSEC, CEH) are highly valued. Superb communication skills, humility, and a collaborative approach are essential.

Similar roles