xelys jobs xelys jobs

Application Security Engineer

Zocdoc

midsecurityengineering-management New York City Metropolitan Area 71 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Application SecuritySecure Software Development LifecycleOWASP Top 10Static AnalysisSoftware Composition AnalysisSecure CodingSecurity GovernanceAgileGenAI SecurityCompliance Audits

About the role

Role: Application Security Engineer

Help Zocdoc build secure software with confidence by partnering with Engineering, Security, and Compliance to strengthen secure development practices and application security governance.

You’ll work on

  • Serve as an accessible point of contact for engineering squads on the secure software development lifecycle.
  • Review and interpret alerts from static analysis and software composition analysis (SCA) tools; help distinguish true vulnerabilities from false positives.
  • Provide clear, actionable remediation guidance for common application security vulnerabilities, aligned to the OWASP Top 10.
  • Maintain internal security documentation, developer playbooks, and secure coding training so compliance expectations are understandable and achievable.
  • Support application security governance by tracking security milestones and organizing technical evidence from repositories and deployment pipelines for audits.
  • Monitor application security metrics (e.g., vulnerability patch timelines and policy exceptions) to support leadership reporting.
  • Work with GenAI tools and help ensure AI-enabled workflows align with privacy and security guardrails.

You’ll enjoy this role if you

  • Are motivated by reducing risk before issues reach production.
  • Communicate security requirements clearly and make them actionable for developers.
  • Are collaborative across the software development lifecycle.
  • Are interested in emerging technology trends, especially AI security risks and automation.

Requirements / success criteria

  • Meaningful experience in an information security role, software engineering role, or IT audit function with an application security focus.
  • Foundational understanding of software development processes and how security fits into Agile environments.
  • Familiarity with code review and comfort reading at least one major programming language.

Nice to have

  • Specific experience with application security governance and compliance audit evidence workflows.
  • Experience supporting AI governance frameworks and privacy/security guardrails.

About Zocdoc

Zocdoc is a healthcare marketplace that helps patients find and book in-person or virtual care across the United States. The company focuses on improving the patient experience and giving patients more control through modern consumer-style healthcare services, with broad specialty coverage and insurance plan support.

Scraped 7/14/2026