Zocdocremote

Salary
$100,000–$140,000
Posted
Jul 12, 2026
Location
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

An application security engineer role embedded within a development organization, focused on supporting secure software development practices across engineering teams. Day-to-day work involves triaging static analysis and software composition analysis alerts, advising developers on vulnerability remediation, maintaining security documentation and playbooks, and tracking compliance evidence. The role also involves contributing to AI governance frameworks as generative AI tools are adopted across the business.

Mid level · Remote · Full-time

Must have (6)
SASTOWASP Top 10Python, JavaScript, Go or JavaAWS, GCP or AzureGitGenAI
Nice to have (1)
Security+, Gsec or Ceh

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 5,100 people nationally plausibly meet what this posting asks for (information security analysts). range 2,150–7,600

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
Python62%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

No overall years-of-experience figure is stated; the JD uses 'meaningful experience' without a number.

A degree in Computer Science or Cybersecurity is described as 'preferred' and explicitly accepts equivalent hands-on experience or certifications (Security+, GSEC, CEH) — the degree requirement is therefore None.

The SAST/SCA skill is emitted as a single entry because the JD treats them as a paired tooling category; SCA is listed as an alternative rather than a separate gate.

Python/JavaScript/Go/Java are presented as interchangeable examples of 'at least one major language' — emitted as one skill with alternatives.

AWS/GCP/Azure are presented as interchangeable cloud environment examples — emitted as one skill with alternatives.

GenAI integration into daily workflows is explicitly marked 'Required' in the JD, making it a hard gate despite its novelty.

Security+/GSEC/CEH certifications appear under the degree/credential discussion as alternatives to a degree, not as standalone hard gates — marked preferred.

No compensation figures are provided in the posting.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗