SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Staff Security Engineer, Vulnerability Management

Zocdoc - Remote - Remote - posted 2026-07-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Zocdoc is a healthcare marketplace platform that empowers patients to find and book in-person or virtual care across all 50 states, 200+ specialties, and 12,000+ insurance plans. As a Senior Staff Security Engineer focused on Vulnerability Management, you will architect and scale Zocdoc's next-generation vulnerability detection and remediation ecosystem, moving the organization from reactive security firefighting to predictive, continuous risk reduction. Your core responsibilities include owning the technical roadmap for an automated, AI-driven vulnerability scanning platform spanning cloud infrastructure, container registries, operating systems, and application-layer software. You will build context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tools to determine true runtime exploitability. You'll implement AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the appropriate engineering teams. You will lead targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses. Working directly with Software Engineering and DevOps teams, you'll build automated remediation pipelines including dependency update pull requests and base-image patching workflows. You'll engineer security scanning guardrails into CI/CD pipelines and provide structured telemetry to support continuous compliance and executive risk visibility. This role requires at least 8 years of security engineering, vulnerability management, or software development experience, with deep focus on infrastructure, container platforms, and product security. You should have a proven track record of writing production-grade automation scripts and building custom security tooling at scale. Hands-on experience with offensive security exercises, red teaming, penetration testing, and cloud infrastructure security (AWS, GCP, Azure) is essential. Advanced proficiency in Python, Go, or Rust is required, along with strong familiarity with adversarial frameworks, CVSS/EPSS scoring, OWASP Top 10, and experience integrating security scanners into CI/CD workflows using AI/LLM APIs.

Similar roles