Senior Staff Security Engineer, Vulnerability Management
Zocdoc
$200,000–$290,000
Jul 14, 2026
—
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor security engineering role focused on building and owning an automated vulnerability management program spanning cloud infrastructure, containers, and application code. The work centers on designing context-aware triage systems, integrating AI-assisted tooling into CI/CD pipelines, and leading offensive security exercises to validate real-world risk. Suits an experienced engineer with deep roots in infrastructure security, production automation, and hands-on penetration testing or red teaming.
Senior level · 8+ years · Remote · Full-time
Pay in the description: $200,000–$290,000
Advertised as Staff, but the requirements read as Senior.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 2,100 people nationally plausibly meet what this posting asks for (information security analysts). range 430–3,150
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The title is 'Senior Staff Engineer' — a compound level not in the standard band set. 'Staff' is used as the level advertised in the title per the title framing, but the actual scope (owning a technical roadmap for one security domain, 8+ years required) is consistent with a Senior individual contributor rather than a true org-wide Staff/Principal authority.
The SOC classification is a close call: the role is roughly half security-engineering (vulnerability scanning, red teaming, SAST/DAST/SCA tooling) and half software development (building production automation, custom tooling, remediation pipelines in Python/Go/Rust). 15-1212 Information Security Analysts is chosen as primary because vulnerability management and security posture are the stated mission; 15-1252 Software Developers is the strong runner-up given the emphasis on writing production-grade code.
Python, Go, and Rust are listed as a single interchangeable requirement ('Python, Go, or Rust'); Python is used as the primary name with Go and Rust as alternatives.
AWS, GCP, and Azure are listed as interchangeable cloud platforms; AWS is used as the primary name.
The generative AI / LLM integration requirement is explicitly called 'Required' in the JD ('Required: the ability to integrate generative AI tools into daily workflows'), so it is treated as a hard gate.
Security certifications (OSCP, OSCE, GXPN, CISSP) are described as 'highly valued' — not required — and are marked as preferred accordingly.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.