Base Salary
$200k - $290k/yr
Responsibilities
- Own the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application software.
- Build context-engine systems that correlate SAST, DAST, SCA, and cloud posture findings to determine true runtime exploitability.
- Implement AI-assisted triage workflows to classify vulnerabilities, reduce false positives, and route validated issues to engineering teams.
- Lead targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.
- Partner with Software Engineering and DevOps to build automated remediation pipelines, including dependency update pull requests and base-image patching workflows.
- Engineer security scanning guardrails into CI/CD pipelines and provide telemetry for continuous compliance and executive risk visibility.
- Use GenAI tools and technology to analyze findings, improve prioritization, and accelerate remediation workflows.
Requirements
- At least 8 years of experience focused on infrastructure, container platforms, and product security.
- Meaningful experience in security engineering, vulnerability management, or software development.
- Proven ability to write production-grade automation scripts and build custom security tooling at scale.
- Hands-on experience planning or executing red teaming, purple teaming, penetration testing, or other offensive security exercises.
- Deep experience securing cloud infrastructure and containerized ecosystems using AWS, GCP, or Azure, along with Docker and Kubernetes.
- Advanced proficiency in Python, Go, or Rust for automation, scanner API integration, and automated patching workflows.
- Familiarity with adversarial frameworks, CVSS, EPSS, OWASP Top 10, and common application and infrastructure attack vectors.
- Experience integrating security scanners into CI/CD workflows and using AI or LLM APIs to analyze code or log data.
- Ability to integrate generative AI tools into daily workflows to automate tasks and improve productivity.
- Advanced security certifications such as OSCE, OSCP, GXPN, or CISSP, or equivalent practical engineering experience, are highly valued.
Benefits
- Flexible work environment and unlimited vacation
- 100% paid employee health benefit options, including medical, dental, and vision
- 401(k) with employer-funded match
- Corporate wellness programs with Headspace and Peloton
- Sabbatical leave for employees with 5+ years of service
- Paid parental leave and fertility/family planning reimbursement
- Cell phone reimbursement
- Employee Resource Groups and ZocClubs
- Remote work arrangement
Categories
About Zocdoc
Zocdoc is the healthcare access infrastructure that connects patients to great care. By powering seamless scheduling wherever patients are seeking care, Zocdoc helps them move from being stuck to being seen. Each month, millions of patients find and book appointments with providers, powered by Zocdoc—on the company’s website and app, and across online search, insurance directories, providers’ websites, practice phone lines, AI platforms, and more—with the typical appointment happening within 24 to 72 hours from booking. With nearly two decades of experience unifying healthcare’s fragmentation, Zocdoc is uniquely positioned to power access across insurance plans, EHRs and PMS systems, specialties, visit types, and provider organizations of every size. By fixing healthcare at the start, Zocdoc empowers patients to get the care they need, when they need it, while delivering scaled patient growth providers can count on.
