Senior Staff Security Engineer, Vulnerability Management

Reposted One Month Ago
Easy Apply
Hiring Remotely in USA
Remote or Hybrid
200K-290K Annually
Senior level
Healthtech • Information Technology • Software • Telehealth
The Role
Lead architecture and scaling of an automated, AI-driven vulnerability detection and remediation platform across cloud, containers, and applications. Correlate SAST/DAST/SCA findings, implement AI-assisted triage, run red/purple team validation, and build automated remediation pipelines integrated into CI/CD for continuous compliance and risk reduction.
Summary Generated by Built In

Our Mission

You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.  

We’re here to give power to the patient. 

For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.

Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting. We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.

Fixing healthcare starts with fixing access to it. And we're still just getting started.


Your Impact on our Mission

Zocdoc’s most important asset is our people and our platform. As a Senior Staff Engineer, Vulnerability Management, you’ll play a meaningful role in strengthening both by architecting and scaling our next-generation vulnerability detection and remediation ecosystem across Compliance, Security, and Engineering. In this role, you’ll help move our security posture from reactive firefighting to predictive, continuous risk reduction through intelligent automation, deeper full-stack visibility, and faster remediation across infrastructure, containers, and application code.

You’ll enjoy this role if you are…
  • Personally motivated by building secure, scalable systems that reduce real-world risk at scale.
  • Autonomous, urgent, and creative, and you love turning noisy security findings into actionable engineering outcomes.
  • Highly collaborative and energized by working across Security, Compliance, Engineering, and DevOps teams.
  • Passionate about offensive security, adversarial validation, and understanding how theoretical vulnerabilities translate into operational exposure.
  • A systems thinker who can connect infrastructure, application security, compliance, and automation into one cohesive program.
  • The kind of person who enjoys pairing deep technical judgment with practical execution and measurable impact.
  • Serious about your work, but not about yourself.
Your day to day is…
  • Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software.
  • Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability.
  • Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams.
  • Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.
  • Partnering directly with Software Engineering and DevOps to build automated remediation pipelines, including dependency update pull requests and base-image patching workflows.
  • Engineering security scanning guardrails into CI/CD pipelines and providing structured telemetry to support continuous compliance and executive risk visibility.
  • Working with cutting-edge GenAI tools and technology to analyze findings, improve prioritization, and accelerate remediation workflows.
You’ll be successful in this role if you have…
  • Meaningful experience in security engineering, vulnerability management, or software development, with at least 8 years focused on infrastructure, container platforms, and product security.
  • A proven track record of writing production-grade automation scripts and building custom security tooling at scale.
  • Hands-on experience planning or executing offensive security exercises, red teaming, purple teaming, or penetration testing.
  • Deep experience securing cloud infrastructure and containerized ecosystems using platforms such as AWS, GCP, or Azure, along with Docker and Kubernetes.
  • Advanced proficiency in Python, Go, or Rust to build automation, integrate scanner APIs, and orchestrate automated patching workflows.
  • Strong familiarity with adversarial frameworks, vulnerability scoring systems such as CVSS and EPSS, and common application and infrastructure attack vectors including the OWASP Top 10.
  • Experience integrating security scanners into CI/CD workflows and using AI or LLM APIs to analyze code or log data for rapid prioritization.
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
  • Advanced security certifications such as OSCE, OSCP, GXPN, CISSP, or equivalent practical engineering experience are highly valued.

Benefits:

  • Flexible work environment
  • Unlimited Vacation
  • 100% paid employee health benefit options (including medical, dental, and vision)
  • 401(k) with employer funded match
  • Corporate wellness programs with Headspace and Peloton
  • Sabbatical leave (for employees with 5+ years of service)
  • Competitive paid parental leave and fertility/family planning reimbursement
  • Cell phone reimbursement
  • Employee Resource Groups and ZocClubs to promote shared community and belonging
  • Great Place to Work Certified

Zocdoc is committed to fair and equitable compensation practices. Salary ranges are determined through alignment with market data. Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills. Certain positions are also eligible for variable pay and/or equity.

Remote Base Salary Range
$200,000$290,000 USD

About us
Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need. Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in-person or video visits online. Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last-minute openings, and deliver a better healthcare experience. Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values. Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish. 

Zocdoc is a mission-driven organization dedicated to building teams as diverse as the patients and providers we aim to serve. In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better.  We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment. Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.
Job Applicant Privacy Notice


Skills Required

  • At least 8 years focused on infrastructure, container platforms, and product security.
  • Meaningful experience in security engineering, vulnerability management, or software development.
  • Proven track record of writing production-grade automation scripts and building custom security tooling at scale.
  • Hands-on experience planning or executing offensive security exercises, red teaming, purple teaming, or penetration testing.
  • Deep experience securing cloud infrastructure and containerized ecosystems using AWS, GCP, or Azure, with Docker and Kubernetes.
  • Advanced proficiency in Python, Go, or Rust for automation, scanner integration, and patching workflows.
  • Experience integrating security scanners into CI/CD workflows and using AI or LLM APIs to analyze code or logs for prioritization.
  • Strong familiarity with adversarial frameworks, vulnerability scoring systems such as CVSS and EPSS, and OWASP Top 10.
  • Ability to integrate generative AI tools into daily workflows to automate tasks and accelerate remediation.
  • Advanced security certifications such as OSCE, OSCP, GXPN, CISSP or equivalent practical engineering experience.

What the Team is Saying

Nick Finger
Kylie Sharp
Meaghan Fenton
Brandon LaRue
Tony
Brian
Natalie
Faith
Brandie

Zocdoc Compensation & Benefits Highlights

  • Healthcare Strength Healthcare is portrayed as comprehensive, with job postings specifying employer-paid options for medical, dental, vision, and dedicated mental health support. Wellness programs and everyday perks further complement the core health coverage.
  • Leave & Time Off Breadth Time-off policies highlight competitive PTO, unlimited vacation for many salaried roles, paid company holidays, and a sabbatical after five years. Role listings and the careers site present these as standard parts of the package.
  • Parental & Family Support Family benefits include fully paid parental leave with a structured return-to-work program, plus fertility and adoption assistance. Family medical leave is also available where eligibility criteria are met.

Zocdoc Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
900 Employees
Year Founded: 2007

What We Do

Zocdoc is the tech company at the beginning of a better healthcare experience. Each month, millions of patients use Zocdoc to find in-network neighborhood doctors, instantly book appointments online, see what other real patients have to say, get reminders for upcoming appointments and preventive check-ups, fill out their paperwork online, and more.

Why Work With Us

Zocdoc's forward-thinking approach prioritizes collaboration, agility, and continuous learning in service of our long-term vision. This has helped us drive significant innovation in a complex, slow-moving industry, and our talented team is looking for impact-minded individuals to join us as we continue to re-imagine the healthcare experience.

Gallery

Gallery
Gallery
Gallery
Gallery

Zocdoc Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Our NYC office is accessible to all employees five days a week, though working in-office remains completely voluntary; everyone is invited but nobody is required to work in the office.

Typical time on-site: Not Specified
HQNew York, NY
Pune, IN
Learn more

Similar Jobs

Zocdoc Logo Zocdoc

Specialist, Customer Experience

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Remote or Hybrid
USA
900 Employees
23-27 Annually

Zocdoc Logo Zocdoc

Engineering Manager

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Remote or Hybrid
USA
900 Employees
210K-270K Annually

Zocdoc Logo Zocdoc

Staff Software Engineer

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Remote or Hybrid
USA
900 Employees
180K-265K Annually

Zocdoc Logo Zocdoc

Director, Marketing Data Science

Healthtech • Information Technology • Software • Telehealth
Easy Apply
Remote or Hybrid
6 Locations
900 Employees
220K-300K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account