Application Security Engineer
Zocdoc
midsecurityengineering-management New York City Metropolitan Area 71 days ago via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Application SecuritySecure Software Development LifecycleOWASP Top 10Static AnalysisSoftware Composition AnalysisSecure CodingSecurity GovernanceAgileGenAI SecurityCompliance Audits
About the role
Role: Application Security Engineer
Help Zocdoc build secure software with confidence by partnering with Engineering, Security, and Compliance to strengthen secure development practices and application security governance.
You’ll work on
- Serve as an accessible point of contact for engineering squads on the secure software development lifecycle.
- Review and interpret alerts from static analysis and software composition analysis (SCA) tools; help distinguish true vulnerabilities from false positives.
- Provide clear, actionable remediation guidance for common application security vulnerabilities, aligned to the OWASP Top 10.
- Maintain internal security documentation, developer playbooks, and secure coding training so compliance expectations are understandable and achievable.
- Support application security governance by tracking security milestones and organizing technical evidence from repositories and deployment pipelines for audits.
- Monitor application security metrics (e.g., vulnerability patch timelines and policy exceptions) to support leadership reporting.
- Work with GenAI tools and help ensure AI-enabled workflows align with privacy and security guardrails.
You’ll enjoy this role if you
- Are motivated by reducing risk before issues reach production.
- Communicate security requirements clearly and make them actionable for developers.
- Are collaborative across the software development lifecycle.
- Are interested in emerging technology trends, especially AI security risks and automation.
Requirements / success criteria
- Meaningful experience in an information security role, software engineering role, or IT audit function with an application security focus.
- Foundational understanding of software development processes and how security fits into Agile environments.
- Familiarity with code review and comfort reading at least one major programming language.
Nice to have
- Specific experience with application security governance and compliance audit evidence workflows.
- Experience supporting AI governance frameworks and privacy/security guardrails.
About Zocdoc
Zocdoc is a healthcare marketplace that helps patients find and book in-person or virtual care across the United States. The company focuses on improving the patient experience and giving patients more control through modern consumer-style healthcare services, with broad specialty coverage and insurance plan support.
Scraped 7/14/2026