Senior Staff Security Engineer, Vulnerability Management
Job description
About the role
At Zocdoc, our mission is to improve the healthcare experience by empowering patients with innovative digital solutions. As a Senior Staff Security Engineer specializing in Vulnerability Management, you will be a critical part of our security engineering team, responsible for designing and implementing advanced vulnerability detection, assessment, and remediation systems. Your expertise will help us proactively identify security risks across our cloud infrastructure, container environments, and applications, ensuring our platform remains secure and resilient. You will lead efforts to develop automation workflows, AI tools, and collaborate closely with engineering teams to embed security into our development lifecycle. This role offers an to influence the security posture of a fast-growing healthcare technology company and to work on security challenges.
Key facts
What you'll do
- Lead the development and enhancement of an automated vulnerability scanning platform that comprehensively covers cloud infrastructure, container registries, operating systems, and application software components.
- Design and implement models that correlate findings from various security tools, providing contextual insights to assess the real exploitability of vulnerabilities in runtime environments.
- Build AI-driven workflows to classify vulnerabilities, reduce false positives, and prioritize issues based on severity and exploitability, ensuring efficient remediation workflows.
- Conduct red teaming and purple teaming exercises to simulate attacker behaviors, identify exploitable vulnerabilities, and improve runtime security measures across systems.
- Collaborate with Software Engineering and DevOps teams to design and implement automated remediation workflows, including dependency updates, patching base images, and applying security fixes in CI/CD pipelines.
- Integrate vulnerability scanning and security testing into the continuous integration and continuous delivery processes, ensuring security is embedded throughout the development lifecycle.
- Develop and structured telemetry and dashboards to monitor vulnerability trends, compliance status, and risk levels across the organization.
- advanced generative AI tools and large language models (LLMs) to analyze security findings, automate the prioritization of vulnerabilities, and streamline remediation workflows.
- Drive the automation of security processes, including vulnerability detection, analysis, and patching, to reduce manual effort and increase efficiency.
- Support incident response activities by providing insights into vulnerabilities exploited in attacks and recommending mitigation strategies.
- Promote a security-first culture by providing guidance and best practices to engineering teams, fostering awareness of security risks and mitigation techniques.
- Stay current with emerging security threats, attack techniques, and new vulnerabilities, continuously improving our security tools and processes.
Requirements
- Minimum of 8 years of experience in security engineering, vulnerability management, or related software development roles, with a focus on infrastructure security, container security, and product security.
- Proven track record of developing production-quality automation scripts, security tools, and custom solutions at scale.
- Hands-on experience with offensive security operations, including red teaming, purple teaming, or penetration testing, to understand attacker techniques and defenses.
- Deep knowledge of securing cloud environments such as AWS, GCP, or Azure, along with experience managing container orchestration platforms like Docker and Kubernetes.
- Strong programming skills in Python, Go, or Rust, with the ability to develop automation scripts, APIs, and orchestration workflows.
- Familiarity with vulnerability scoring systems such as CVSS and EPSS, and understanding of common attack vectors including those outlined in the OWASP Top 10.
- Experience integrating security scanners into CI/CD pipelines, and utilizing AI or large language model APIs to analyze security data and automate prioritization.
- Ability to incorporate generative AI tools into daily workflows to enhance productivity, automate repetitive tasks, and innovate security processes.
- Relevant security certifications such as Offensive Security Certified Expert (OSCE), Offensive Security Certified Professional (OSCP), GIAC Exploit Researcher and Advanced Penetration Tester (GXPN), CISSP, or equivalent practical experience are highly valued.
- Strong analytical skills, attention to detail, and the ability to work collaboratively across teams to implement security solutions.
- Excellent communication skills to articulate complex security concepts to technical and non-technical stakeholders.
Nice to have
- Experience with security compliance frameworks such as SOC 2, HIPAA, or PCI DSS, and familiarity with regulatory requirements relevant to healthcare technology.
- Knowledge of threat modeling, risk assessment, and security architecture design.
- Experience working in a fast-paced, high-growth environment with evolving security needs.
Skills & tools
- Vulnerability management platforms and tools, cloud security solutions, CI/CD systems, and security automation frameworks.
- AI and large language model (LLM) APIs, such as OpenAI, for security analysis and automation.
- Programming languages: Python, Go, Rust.
- Containerization and orchestration: Docker, Kubernetes.
- Cloud platforms: AWS, GCP, Azure.
- Security frameworks, vulnerability scanners, and telemetry tools.
Practical notes
- This position is on-site at our remote office in the USA. Zocdoc offers a flexible work environment, with the possibility of remote work arrangements. We provide a comprehensive benefits package, including medical, dental, and vision coverage, along with a 401(k) plan featuring employer matching contributions. Our perks include unlimited vacation, wellness programs, and paid parental leave. The salary range for this role is between $200,000 and $290,000 USD, depending on experience and qualifications. We encourage candidates with diverse backgrounds to apply, as we value inclusion and different perspectives.
- This role involves working closely with cross-functional teams, including engineering, product, and compliance, to embed security into all aspects of our platform.
- You will have opportunities to influence our security strategy, contribute to innovative projects, and stay at the forefront of vulnerability management and security automation.
- The position requires a proactive approach to security challenges, excellent problem-solving skills, and the ability to adapt to rapidly changing threat landscapes.
- We are committed to providing a supportive environment that fosters professional growth, learning, and collaboration.
- Candidates should be prepared to demonstrate their technical expertise through interviews, including practical assessments or technical discussions.