Application Security Engineer

Application Security Engineer

Vollzeit 100000 - 140000 € / Jahr (geschätzt) Homeoffice (teilweise)
Zocdoc

Auf einen Blick

  • Aufgaben: Entwickle sichere Software und unterstütze Teams bei der Einhaltung von Sicherheitsrichtlinien.
  • Unternehmen: Zocdoc, führender digitaler Gesundheitsmarktplatz mit einer mission-driven Kultur.
  • Vorteile: Flexible Arbeitszeiten, unbegrenzter Urlaub und umfassende Gesundheitsleistungen.
  • Weitere Informationen: Dynamisches Team mit großartigen Wachstumschancen und einem Fokus auf Zusammenarbeit.
  • Warum dieser Job: Gestalte die Zukunft der Gesundheitsversorgung und mache einen echten Unterschied für Patienten.
  • Qualifikationen: Erfahrung in Informationssicherheit oder Softwareentwicklung und Kenntnisse in Cloud-Umgebungen.

Das prognostizierte Gehalt liegt zwischen 100000 - 140000 € pro Jahr.

Our Mission

Healthcare should work for patients, but it doesn’t.

In their time of need, they call down outdated insurance directories.

Then wait on hold.

Then wait weeks for the privilege of a visit.

Then wait in a room solely designed for waiting.

Then wait for a surprise bill.

In any other consumer industry, the companies delivering such a poor customer experience would not survive.

But in healthcare, patients lack market power.

Which means they are expected to accept the unacceptable.

Zocdoc’s mission is to give power to the patient.

To do that, we’ve built the leading healthcare marketplace that makes it easy to find and book in-person or virtual care in all 50 states, across +200 specialties and +12k insurance plans.

By giving patients the ability to see and choose, we give them power.

In doing so, we can make healthcare work like every other consumer sector, where businesses compete for customers, not the other way around.

In time, this will drive quality up and prices down.

We’re 18 years old and the leader in our space, but we are still just getting started.

If you like solving important, complex problems alongside deeply thoughtful, driven, and collaborative teammates, read on.

Your Impact to our Mission

Zocdoc’s most important asset is our people.

As an Application Security Engineer, you’ll play a meaningful role in helping our development organization build secure software with confidence.

In this role, you’ll work closely with our Compliance, Security, and Engineering teams to support our secure software development lifecycle, strengthen application security governance, and help shape emerging AI governance guardrails across the business.

  • You’ll enjoy this role if you…
  • Personally motivated by helping teams build secure software and reduce risk before issues reach production.
  • Autonomous, urgent, and creative. You genuinely love turning security requirements into practical guidance for developers.
  • Highly collaborative and energized by partnering with engineering squads across the software development lifecycle.
  • Passionate about application security, secure coding, and improving how teams work within modern development environments.
  • A clear communicator who can make security concepts approachable and actionable for technical partners.
  • The kind of person who is excited by emerging technology trends, especially AI security risks and automated workflows.
  • Serious about your work, but not about yourself.
  • Your day to day is…
  • Serving as an accessible point of contact for engineering squads, helping teams understand and follow secure development lifecycle guidelines.
  • Assisting developers in reviewing and interpreting alerts from static analysis and software composition analysis tools, including helping distinguish true vulnerabilities from false positives.
  • Providing clear, actionable guidance on remediating common application security vulnerabilities, including issues aligned to the OWASP Top 10.
  • Helping maintain internal security documentation, developer playbooks, and secure coding training materials so that compliance expectations are clear and achievable.
  • Supporting application security governance by tracking key security milestones and organizing technical evidence from repositories and deployment pipelines for compliance audits.
  • Monitoring application security metrics, including vulnerability patch timelines and policy exceptions, to support regular leadership reporting.
  • Working with cutting‑edge Gen AI tools and technology while supporting AI governance frameworks and helping ensure AI‑enabled workflows align with privacy and security guardrails.
  • You’ll be successful in this role if you have…
  • Meaningful experience in an information security role, software engineering position, or IT audit function with an application security focus.
  • A foundational understanding of software development processes and how security fits into agile environments.
  • Familiarity with code review concepts and comfort reading at least one major language used in cloud environments, such as Python, Java Script, Go, or Java.
  • Basic exposure to cloud environments such as AWS, GCP, or Azure, along with an understanding of Git workflows.
  • A conceptual understanding of vulnerability categories and web application security standards.
  • An interest in emerging technology trends, especially AI security risks and automated workflows.
  • Required: the ability to integrate generative AI tools into daily workflows to automate tasks, foster innovation, and maximize productivity.
  • A degree in Computer Science, Cybersecurity, or a related technical field is preferred, though equivalent hands‑on experience or certifications such as Security+, GSEC, or CEH are also highly valued.
  • Superb communication skills, humility, and a collaborative approach to supporting stakeholders across engineering and security.

Benefits

  • Flexible work environment
  • Unlimited Vacation
  • 100% paid employee health benefit options (including medical, dental, and vision)
  • 401(k) with employer funded match
  • Corporate wellness program with Wellhub
  • Sabbatical leave (for employees with 5+ years of service)
  • Competitive paid parental leave and fertility/family planning reimbursement
  • Cell phone reimbursement
  • Employee Resource Groups and Zoc Clubs to promote shared community and belonging
  • Great Place to Work Certified

Zocdoc is committed to fair and equitable compensation practices.

Salary ranges are determined through alignment with market data.

Base salary offered is determined by a number of factors including the candidate’s experience, qualifications, and skills.

Certain positions are also eligible for variable pay and/or equity; your recruiter will discuss the full compensation package details.

NYC Base Salary Range

About us

Zocdoc is the country’s leading digital health marketplace that helps patients easily find and book the care they need.

Each month, millions of patients use our free service to find nearby, in-network providers, compare choices based on verified patient reviews, and instantly book in‑person or video visits online.

Providers participate in Zocdoc’s Marketplace to reach new patients to grow their practice, fill their last‑minute openings, and deliver a better healthcare experience.

Founded in 2007 with a mission to give power to the patient, our work each day in pursuit of that mission is guided by our six core values.

Zocdoc is a private company backed by some of the world’s leading investors, and we believe we’re still only scratching the surface of what we plan to accomplish.

Zocdoc is a mission‑driven organization dedicated to building teams as diverse as the patients and providers we aim to serve.

In the spirit of one of our core values - Together, Not Alone, we are a company that prides itself on being highly collaborative, and we believe that diverse perspectives, experiences and contributors make our community and our platform better.

We’re an equal opportunity employer committed to providing employees with a work environment free of discrimination and harassment.

Applicants are considered for employment regardless of race, color, ethnicity, ancestry, religion, national origin, gender, sex, gender identity, gender expression, sexual orientation, age, citizenship, marital or parental status, disability, veteran status, or any other class protected by applicable laws.

  • Job Applicant Privacy Notice
  • #J-18808-Ljbffr

Application Security Engineer Arbeitgeber: Zocdoc

Zocdoc ist ein hervorragender Arbeitgeber, der seinen Mitarbeitern eine flexible Arbeitsumgebung und unbegrenzten Urlaub bietet, um eine ausgewogene Work-Life-Balance zu fördern. Mit einem starken Fokus auf Teamarbeit und Vielfalt, unterstützt das Unternehmen die persönliche und berufliche Weiterentwicklung seiner Mitarbeiter durch Schulungen und Ressourcen, während es gleichzeitig an der Spitze der digitalen Gesundheitsversorgung steht. In New York City gelegen, profitieren Mitarbeiter von einem dynamischen Umfeld, das Innovation und Zusammenarbeit fördert, sowie von umfassenden Gesundheitsleistungen und einem wettbewerbsfähigen Gehalt.

Zocdoc

Kontaktdaten:

Zocdoc Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Application Security Engineer erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Zocdoc kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Zocdoc zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Zocdoc.

Wir glauben, dass du diese Fähigkeiten brauchst, um Application Security Engineer mit Bravour zu bestehen

Anwendungs- und Anwendungssicherheit
Sichere Softwareentwicklung
Agile Entwicklungsmethoden
Code-Überprüfung
Python
JavaScript
Go

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei Zocdoc vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Zocdoc könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Zocdoc sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird Zocdoc auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!