Application Security Engineer
Job description
About the role
In this role, you will play a crucial part in guiding our engineering teams to develop secure software solutions. Your collaboration with various departments will be essential in improving application security practices and contributing to the creation of governance frameworks, especially in relation to emerging technologies like artificial intelligence.
Key facts
What you'll do
- Serve as a key resource for engineering teams, ensuring compliance with secure development lifecycle practices.
- Assist developers in evaluating and interpreting alerts generated by security tools, helping to distinguish between genuine vulnerabilities and false positives.
- Provide straightforward, actionable recommendations for mitigating common security vulnerabilities, particularly those outlined in the OWASP Top 10.
- Regularly update and maintain internal security documentation, developer guides, and training resources to clarify compliance requirements.
- Facilitate security governance by monitoring key security milestones and organizing technical documentation for compliance audits.
- Track security metrics related to application vulnerabilities and policy exceptions to support regular reporting to leadership.
- Collaborate with advanced generative AI tools while ensuring that AI-driven processes adhere to privacy and security standards.
- Engage in continuous learning to stay updated on the latest trends in application security and emerging technologies.
Requirements
- Extensive experience in information security, software engineering, or IT audit roles with a focus on application security is essential.
- A strong understanding of software development processes and how to integrate security within agile methodologies is required.
- Familiarity with code review practices and proficiency in at least one major programming language commonly used in cloud environments, such as Python, JavaScript, Go, or Java.
- Basic knowledge of cloud platforms like AWS, GCP, or Azure, along with an understanding of Git workflows is necessary.
- A conceptual understanding of various vulnerability types and web application security standards is important.
- A strong interest in emerging technology trends, particularly concerning AI security challenges and automation, is preferred.
- Required: ability to incorporate generative AI tools into daily tasks to improve efficiency and foster innovation.
- A degree in Computer Science, Cybersecurity, or a related field is preferred, though equivalent practical experience or certifications such as Security+, GSEC, or CEH are also valuable.
- Excellent communication skills, humility, and a collaborative mindset are crucial for engaging with stakeholders across engineering and security teams.
Nice to have
- Experience with specific application security tools and frameworks is a plus.
- Familiarity with threat modeling and risk assessment methodologies would be beneficial.
- Knowledge of compliance standards such as PCI-DSS, HIPAA, or GDPR is advantageous.
Skills & tools
- Proficiency in security tools for static analysis and software composition analysis is essential.
- Familiarity with application security testing methodologies, including dynamic and static testing techniques.
- Experience with CI/CD pipelines and how to integrate security testing into those workflows is beneficial.
Practical notes
- This position is open to candidates who have work authorization in the USA.
- Benefits include a flexible work environment, unlimited vacation, comprehensive employee health benefits, a 401(k) plan with company matching, and a corporate wellness program.
- Zocdoc offers sabbatical leave for employees who have been with the company for over five years, competitive parental leave, and reimbursement for fertility and family planning expenses.
- The base salary for this role ranges from $100,000 to $140,000 USD, depending on experience and qualifications. Additional compensation details will be discussed during the recruitment process.
About us
Zocdoc is a premier digital health marketplace that simplifies the process for patients to find and book medical care. Each month, millions of users rely on our platform to connect with in-network providers, compare options based on verified reviews, and schedule appointments for both in-person and virtual visits. Established in 2007, our mission is to empower patients by enhancing their healthcare experience. We are committed to diversity and collaboration, which is reflected in our workplace culture, ensuring that our teams represent the communities we serve. As an equal opportunity employer, we are dedicated to fostering a work environment that is free from discrimination and harassment.