Jobs / United States / Zocdoc INC
Senior Staff Security Engineer, Vulnerability Management
Zocdoc INC · 🇺🇸 USA Remote · Remote
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 16 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- What Zocdoc INC paid sponsored hires in similar roles7 certified filings for “Senior Software Engineer” (Software Developers) in NY: $184k–$250k, median $202k. Most were filed at wage level III (57%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Zocdoc INC
The US Department of Labor certified 16 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 1 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Zocdoc INC →
About the role
Our Mission You call. You wait. You call again. In every other part of your life, you book in seconds. In healthcare, you’re blocked. We’re here to give power to the patient. For nearly 20 years, we’ve built the leading healthcare marketplace - helping tens of millions of people find and book the care they need. Now, we’re going further: building our infrastructure beyond Zocdoc’s marketplace to power access to care wherever patients search, from provider websites and insurance directories to search engines, AI platforms, and more. Healthcare still lacks something every other major consumer industry takes for granted: a seamless way to go from seeking to getting . We don’t want to own the front door to care; there isn't one. We want to make sure all of those doors open when patients are knocking. Fixing healthcare starts with fixing access to it. And we're still just getting started. Your Impact on our Mission Zocdoc’s most important asset is our people and our platform. As a Senior Staff Engineer, Vulnerability Management, you’ll play a meaningful role in strengthening both by architecting and scaling our next-generation vulnerability detection and remediation ecosystem across Compliance, Security, and Engineering. In this role, you’ll help move our security posture from reactive firefighting to predictive, continuous risk reduction through intelligent automation, deeper full-stack visibility, and faster remediation across infrastructure, containers, and application code. You’ll enjoy this role if you are… • Personally motivated by building secure, scalable systems that reduce real-world risk at scale. • Autonomous, urgent, and creative, and you love turning noisy security findings into actionable engineering outcomes. • Highly collaborative and energized by working across Security, Compliance, Engineering, and DevOps teams. • Passionate about offensive security, adversarial validation, and understanding how theoretical vulnerabilities translate into operational exposure. • A systems thinker who can connect infrastructure, application security, compliance, and automation into one cohesive program. • The kind of person who enjoys pairing deep technical judgment with practical execution and measurable impact. • Serious about your work, but not about yourself. Your day to day is… • Owning the technical roadmap for an automated, AI-driven vulnerability scanning platform across cloud infrastructure, container registries, operating systems, and application-layer software. • Building context-engine models that correlate findings from SAST, DAST, SCA, and cloud posture tooling to determine true runtime exploitability. • Implementing AI-assisted triage workflows that classify vulnerabilities, reduce false positives, and route validated issues to the right engineering teams. • Leading targeted red teaming and collaborative purple teaming exercises to validate exploitable paths and strengthen runtime defenses. • Partnering directly with Software Engineering and DevOps to build automated remediation pipelines, including dependency update pull requests and base-image patching workflows. • Engineering security scanning guardrails into CI/CD pipelines and providing structured telemetry to support continuous compliance and executive risk visibility. • Working with cutting-edge GenAI tools and technology to analyze findings, improve prioritization, and accelerate remediation workflows. You’ll be successful in this role if you have… • Meaningful experience in security engineering, vulnerability management, or software development, with at least 8 years focused on infrastructure, container platforms, and product security. • A proven track record of writing production-grade automation scripts and building custom security to