Zocdoc logo
Zocdoc
Posted 13 days agoVerified live 8h ago

Application Security Engineer

Brief overview

Remote
UndergradOr in progress
$100k–$140k/yrStated range
3+ yrsMinimum
18 H-1B approvalsDept. of Labor
10 green cardsCertified filings
Application SecuritySecure Software Development Lifecycle (SSDLC)Code ReviewPythonJavaScriptGoJavaAWSGoogle Cloud Platform (GCP)Microsoft AzureGitWeb Application SecurityOWASP Top 10Generative AI Tools

About the company

Zocdoc is a digital marketplace company that connects healthcare patients and doctors.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
18H-1B approved
95%approval rate
2new H-1B hires
10PERM certified
$248,490median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20234
20243
20259
20262
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
20251
20262
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20233
20242
20255
Top sponsored roles
Staff Software EngineerSenior Account Executive, EnterpriseSenior Product Analyst
Sponsored employees from
IndiaChinaPhilippines

Job description

Summary

Zocdoc is a healthcare marketplace focused on improving access to care for patients. The Application Security Engineer will help development teams build secure software, support the secure software development lifecycle and application security governance, and shape AI governance guardrails. The role also provides vulnerability remediation guidance, maintains security documentation, and supports compliance reporting.

Responsibilities

  • Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines
  • Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives
  • Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10
  • Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable
  • Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits
  • Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting
  • Working with cutting-edge GenAI tools and technology while supporting AI governance frameworks and helping ensure AI-enabled workflows align with privacy and security guardrails

Skills

  • Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus
  • A foundational understanding of software development processes and how security fits into agile environments
  • Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java
  • Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows
  • A conceptual understanding of vulnerability categories and web application security standards
  • An interest in emerging technology trends, especially AI security risks and automated workflows
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity
  • Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security
  • A degree in Computer Science, Cybersecurity, or a related technical field is preferred
  • Equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly valued

Qualifications

Must Haves

  • Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus
  • A foundational understanding of software development processes and how security fits into agile environments
  • Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, JavaScript, Go, or Java
  • Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows
  • A conceptual understanding of vulnerability categories and web application security standards
  • An interest in emerging technology trends, especially AI security risks and automated workflows
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity
  • Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security

Nice to Haves

  • A degree in Computer Science, Cybersecurity, or a related technical field is preferred
  • equivalent hands-on experience or certifications such as Security+, GSEC, or CEH are also highly valued

Benefits

  • Flexible work environment
  • Unlimited Vacation
  • 100% paid employee health benefit options (including medical, dental, and vision)
  • 401(k) with employer funded match
  • Corporate wellness program with Wellhub
  • Sabbatical leave (for employees with 5+ years of service)
  • Competitive paid parental leave and fertility/family planning reimbursement
  • Cell phone reimbursement
  • Employee Resource Groups and ZocClubs to promote shared community and belonging
  • Great Place to Work Certified
  • Certain positions are also eligible for variable pay and/or equity

More jobs like this