Jobs Companies Zocdoc Senior Staff Security Engineer, Vulnerability Management

À propos de ce poste Senior Staff Security Engineer, Vulnerability Management chez Zocdoc

Zocdoc · Télétravail · USA Remote

Our Mission

Healthcare should work for patients, but it doesn’t. In their time of need, they call down outdated insurance directories. Then wait on hold. Then wait weeks for the privilege of a visit. Then wait in a room solely designed for waiting. Then wait for a surprise bill. In any other consumer industry, the companies delivering such a poor customer experience would not survive. But in healthcare, patients lack market power. Which means they are expected to accept the unacceptable.

 

Zocdoc’s mission is to give power to the patient. To do that, we’ve built the leading healthcare marketplace that makes it easy to find and book in-person or virtual care in all 50 states, across +200 specialties and +12k insurance plans. By giving patients the ability to see and choose, we give them power. In doing so, we can make healthcare work like every other consumer sector, where businesses compete for customers, not the other way around. In time, this will drive quality up and prices down. 

 

We’re 18 years old and the leader in our space, but we are still just getting started. If you like solving important, complex problems alongside deeply thoughtful, driven, and collaborative teammates, read on.

 

Your Impact on our Mission

Zocdoc’s most important asset is our people and our platform. As a Senior Staff Engineer, Vulnerability Management, you’ll play a meaningful role in strengthening both by architecting and scaling our next-generation vulnerability detection and remediation ecosystem across Compliance, Security, and Engineering. In this role, you’ll help move our security posture from reactive firefighting to predictive, continuous risk reduction through intelligent automation, deeper full-stack visibility, and faster remediation across infrastructure, containers, and application code.

You’ll enjoy this role if you are…

  • Personally motivated by building secure, scalable systems that reduce real-world risk at scale.
  • Autonomous, urgent, and creative, and you love turning noisy security findings into actionable engineering outcomes.
  • Highly collaborative and energized by working across Security, Compliance, Engineering, and DevOps teams.
  • Passionate about offensive security, adversarial validation, and understanding how theoretical vulnerabilities translate into operational exposure.
  • A systems thinker who can connect infrastructure, application security, compliance, and automation into one cohesive program.
  • The kind of person who enjoys pairing deep technical judgment with practical execution and measurable impact.
  • Serious about your work, but not about yourself.

Your day to day is…

  • Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software.
  • Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability.
  • Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams.
  • Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.
  • Partnering directly with Software Engineering and DevOps to build automated remediation pipelines, including dependency update pull requests and base-image patching workflows.
  • Engineering security scanning guardrails into CI/CD pipelines and providing structured telemetry to support continuous compliance and executive risk visibility.
  • Working with cutting-edge GenAI tools and technology to analyze findings, improve prioritization, and accelerate remediation workflows.

You’ll be successful in this role if you have…

  • Meaningful experience in security engineering, vulnerability management, or software development, with at least 8 years focused on infrastructure, container platforms, and product security.
  • A proven track record of writing production-grade automation scripts and building custom security tooling at scale.
  • Hands-on experience planning or executing offensive security exercises, red teaming, purple teaming, or penetration testing.
  • Deep experience securing cloud infrastructure and containerized ecosystems using platforms such as AWS, GCP, or Azure, along with Docker and Kubernetes.
  • Advanced proficiency in Python, Go, or Rust to build automation, integrate scanner APIs, and orchestrate automated patching workflows.
  • Strong familiarity with adversarial frameworks, vulnerability scoring systems such as CVSS and EPSS, and common application and infrastructure attack vectors including the OWASP Top 10.
  • Experience integrating security scanners into CI/CD workflows and using AI or LLM APIs to analyze code or log data for rapid prioritization.
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
  • Advanced security certifications such as OSCE, OSCP, GXPN, CISSP, or equivalent practical engineering experience are highly valued.

Benefits:

  • Flexible work environment
  • Unlimited Vacation
  • 100% paid employee health benefit options (including medical, dental, and vision)
  • 401(k) with employer funded match
  • Corporate wellness programs with Headspace and Peloton
  • Sabbatical leave (for employees with 5+ years of service)
  • Competitive paid parental leave and fertility/family planning reimbursement
  • Cell phone reimbursement
  • Employee Resource Groups and ZocClubs to promote shared community and belonging
  • Great Place to Work Certified

Zocdoc is committed to fair and equitable compensation practices. Salary ranges are determined through alignment with market data. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills. Certain positions are also eligible for variable pay and/or equity.

Remote Base Salary Range
$200,000$290,000 USD

About us
Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values. Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish. 

Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better.  We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.

Job Applicant Privacy Notice

 

Prêt à postuler chez Zocdoc ?
Postuler chez Zocdoc

Comment se compare ce salaire pour Security Engineer

Ce poste paie $245,000/yrau-dessus de la fourchette habituelle pour les postes Security Engineer.

$128,100 la médiane $177,500 $288,200

Fourchette typique $155,000–$219,150/yr, à partir de 35 annonces Security Engineer comparables sur JobsRadar (rémunération annualisée en USD). Voir les aperçus de salaire pour Security Engineer →

Emplois similaires

Red Cell Partners
Forward Deployed Engineer, Federal/National Security
Red Cell Partners
⚡ Postuler tôt Remote (USA) · lieu restreint $180,000–$240,000
● Nouveau 👁 Vu ✓ Postulé il y a 22 h
Collibra
Senior Product Security Engineer
Collibra
⚡ Postuler tôt Raleigh, North Carolina, USA Sur site $168,000–$210,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
Collibra
Senior Product Security Engineer
Collibra
⚡ Postuler tôt Remote, USA · lieu restreint $168,000–$210,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
Collibra
Engineer, Security Operations & Engineering
Collibra
⚡ Postuler tôt Remote, USA · lieu restreint $116,000–$145,000
● Nouveau 👁 Vu ✓ Postulé il y a 1 j
Smartsheet
Senior Security Engineer I – Customer Trust (Remote Eligible)
Smartsheet
⚡ Postuler tôt -REMOTE, USA- · lieu restreint $145,000–$210,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
Smartsheet
Senior Security Engineer I – GRC FedRAMP (Remote Eligible)
Smartsheet
⚡ Postuler tôt -REMOTE, USA- · lieu restreint $145,000–$210,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
Smartsheet
Senior Security Engineer II, Application Security (Remote Eligible)
Smartsheet
⚡ Postuler tôt -REMOTE, USA- · lieu restreint $175,000–$245,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
Ping Identity
Senior Software Engineer — PingOne Platform Administration & Security
Ping Identity
⚡ Postuler tôt USA - Remote · lieu restreint $110,218–$137,773
● Nouveau 👁 Vu ✓ Postulé il y a 3 j
PlayStation Global
Staff Cloud Security Engineer
PlayStation Global
⚡ Postuler tôt United States, Remote · lieu restreint $197,600–$296,400
● Nouveau 👁 Vu ✓ Postulé il y a 4 j

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez Zocdoc

Voir tous les emplois chez Zocdoc →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit