Senior Staff Security Engineer, Vulnerability Management
Zocdoc · USA Remote · United States · Remote
Pay: USD 200,000 – 290,000 a year
Posted Jul 14, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Our Mission
You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked.
We’re here to give power to the patient.
For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more.
Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting . We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking.
Fixing healthcare starts with fixing access to it. And we're still just getting started.
Your Impact on our Mission
Zocdoc’s most important asset is our people and our platform. As a Senior Staff Engineer, Vulnerability Management, you’ll play a meaningful role in strengthening both by architecting and scaling our next-generation vulnerability detection and remediation ecosystem across Compliance, Security, and Engineering. In this role, you’ll help move our security posture from reactive firefighting to predictive, continuous risk reduction through intelligent automation, deeper full-stack visibility, and faster remediation across infrastructure, containers, and application code.
You’ll enjoy this role if you are…
Personally motivated by building secure, scalable systems that reduce real-world risk at scale.
Autonomous, urgent, and creative, and you love turning noisy security findings into actionable engineering outcomes.
Highly collaborative and energized by working across Security, Compliance, Engineering, and DevOps teams.
Passionate about offensive security, adversarial validation, and understanding how theoretical vulnerabilities translate into operational exposure.
A systems thinker who can connect infrastructure, application security, compliance, and automation into one cohesive program.
The kind of person who enjoys pairing deep technical judgment with practical execution and measurable impact.
Serious about your work, but not about yourself.
Your day to day is…
Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software.
Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability.
Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams.
Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses.
Partnering directly…