Zelis
Posted 3w ago

Application Security Engineer – Software Composition Analysis (SCA)

Zelis
Plano, Texas, United States
HybridFull Time
Responsibilities
  • integrating tools
  • triaging vulnerabilities
  • managing risks
Requirements
  • 8+ years AppSec experience with SCA
  • Integrating security tools into CI/CD
  • Evaluating vulnerabilities
  • Managing open-source license compliance, and guiding developers
  • Strong Java/Python/C++/Ruby skills
Technical tools mentioned
SynkBlack DuckMendVeracodeCheckmarx ONEJenkinsGitHub ActionsGitLab CIArtifactoryCI/CDAI/LLMJavaPythonC++RubynpmpipMaven/GradleOWASP Top 10

Job description

At Zelis, we Get Stuff Done. So, let’s get to it! 

  

A Little About Us 

Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.

At Zelis, AI is woven into the fabric of how we work. Every associate is expected - and empowered - to partner with AI to challenge the status quo, accelerate innovation, and amplify their impact. This is a place for builders with a growth mindset who act with agility, embrace change, and use modern technology to shape smarter solutions, exceptional experiences, and the future of our industry for our clients, customers, and our culture.

  

A Little About You 

You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are.

Position Overview

Zelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and reduce risks associated with open-source and third-party software components in internally developed applications. This role will help integrate scanning tools into CI/CD pipelines and partner with developers, engineering teams to triage vulnerabilities to embed security controls throughout the software development lifecycle.

The ideal candidate will have extensive experience integrating SCA and application security tooling into CI/CD pipelines, evaluating vulnerability exploitability, managing open-source license compliance, and enabling developers to build secure applications at scale. Experience with AI/LLM-focused security scanning tools and emerging application security technologies is highly desirable.

Key Responsibilities :

  • 8+ years of experience in various AppSec domains
  • Lead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks across enterprise applications.
  • Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
  • Integrate and automate SCA and application security tools within CI/CD pipelines to provide continuous security validation throughout the software development lifecycle.
  • Deploy and manage security platforms such as Synk, Black Duck, Mend, Veracode, Checkmarx ONE, experience with any emerging AI/LLM-based security scanning solutions would be desirable.
  • Experience embedding security guardrails into build pipelines using tools like Jenkins, GitHub Actions, or GitLab CI. Artifactory integration experience in the pipeline and developer workflows would be desirable.
  • Analyze identified vulnerabilities to determine exploitability, reachability, and potential business impact.
  • Perform risk-based prioritization of findings, focusing remediation efforts on vulnerabilities that pose the greatest threat to the organization.
  • Validate findings to reduce false positives and improve overall vulnerability management effectiveness.
  • Develop, maintain, and enforce open-source software governance policies.
  • Provide technical guidance, security coding and best practices to development teams.
  • Strong proficiency in multiple programming languages, including Java, Python, C++, Ruby
  • Strong understanding of how third-party packages are integrated through external public repos(e.g., npm for JavaScript, pip for Python, Maven/Gradle for Java).
  • Knowledge of application security best practices and industry standards, including OWASP Top 10, Secure Software Development Lifecycle (SSDLC), Software Supply Chain Security principles, Vulnerability Management frameworks


Professional Skills :

  • Excellent communication, strong analytical thinking and problem-solving capabilities.
  • Self-motivated with a commitment to continuous learning and staying current with evolving security threats and technologies.


Education :

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

Please note at this time we are unable to proceed with candidates who require visa sponsorship now or in the future.


Location and Workplace Flexibility

Zelis is headquartered in the U.S., with multiple locations across the country and in Hyderabad, India. Check out our locations to learn more about our offices. All employee work locations are based on the needs of the position and are determined by the Leadership team. In-office work and activities vary based on work and team objectives in accordance with Company policies.


While location expectations vary by role, candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed. Our hybrid approach is flexible, and in-office presence is guided by team and business needs rather than a fixed weekly schedule.

  

Equal Employment Opportunity  
Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. 
 
We welcome applicants from all backgrounds and encourage you to apply even if you don’t meet 100% of the qualifications for the role. We believe in the value of diverse perspectives and experiences and are committed to building an inclusive workplace for all. 

 

Accessibility Support 
We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email [email protected]

  

Disclaimer 

The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities, duties, and skills from time to time. 

About Zelis

Providing healthcare payment and claims cost management solutions.

Year founded
1995
Employees
2800
Organization type
Private
Latest investment
Raised $7.03B Funding Round (2024) — led by Mubadala
Headquarters
US

Similar jobs

Application Security Engineer roles near Plano, Texas
7h
Save
Mark Applied
Hide
Engineering, Cybersecurity, Application Security Engineer, Vice President
Fort Worth, Texas, United States
OnsiteFull Time
TPG
TPGNASDAQ: TPG: Global alternative asset manager across private equity and credit.
3+ YOERequires 3+ years in application security, 7+ cumulative years in software development and information security, AI security expertise, identity protocols, SDLC, CI/CD, testing tools, cloud architectures, and code literacy.
Model Context Protocol (MCP), OWASP Top 10, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, MITRE ATLAS, OAuth 2.0, OpenID Connect, SAML, JWT, SDLC, DevOps, CI/CD, Kubernetes, SAST, DAST, SCA, Python, JavaScript/TypeScript, Java, C#, Go, CWE, CVSS, AWS, Azure, GCP, GitHub Actions, GitLab CI, Jenkins, GitHub Advanced Security, Dependabot, NIST Secure Software Development Framework (SSDF), OWASP SAMM, SLSA
11h
Save
Mark Applied
Hide
Specialist - CyberSecurity
Dallas or Fort Worth
$62-$66/hr HybridFull Time
LTIMindtree
LTIMindtreeNational Stock Exchange of India: LTIM: Global technology consulting and digital solutions.
3+ YOEBachelor's degree or equivalent experience; 3+ years in cybersecurity engineering, with cloud security, application vulnerabilities, security automation, compliance, and threat response experience.
PowerShell, Python, Java, JavaScript, C#, AWS, Microsoft Azure, Google Cloud, Electronic Medical Records (EMR)
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Global manufacturer and distributor of snacks and beverages.
3+ YOEBachelor's in CS/Engineering or related and 3+ years experience; application security, vulnerability management, cloud-native security, Python/Go, SAST/SCA/DAST, WAF, and CI/CD security experience.
Python, Go, AWS, Azure, GCP, SAST, SCA, DAST, WAF, OPA, HashiCorp Sentinel, OAuth, JWT, CDN
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Produces and distributes global snack and beverage products.
3+ YOEBachelor's in computer science/engineering or equivalent, 3+ years experience, hands-on application security and vulnerability management, cloud and tooling experience, Python or Go proficiency.
Python, Go, AWS, Azure, GCP, OPA, HashiCorp Sentinel, SAST, SCA, DAST, WAF, CDN
1w
Save
Mark Applied
Hide
Application Security | Application Security Engineer
Plano, Texas, United States
$80k-$134k/yr OnsiteFull Time
PepsiCo
PepsiCoNASDAQ: PEP: Global food and beverage manufacturer and distributor.
3+ YOEBachelor's in CS/Engineering or equivalent,3+ years experience,proficiency with Python or Go,experience with SAST/SCA/DAST,WAF,policy-as-code (OPA/Sentinel),cloud security (AWS/Azure/GCP),and vulnerability management.
Python, Go, AWS, Azure, GCP, SAST, SCA, DAST, WAF, OPA, HashiCorp Sentinel, OAuth, JWT
2w
Save
Mark Applied
Hide
Staff App Sec Engineer-Austin, Dallas or San Antonio, TX
Austin or Dallas or San Antonio
HybridFull Time
HEB: A retail grocery operating technology and digital teams to support store and customer operations.
10+ YOE10+ years building and supporting system and security solutions; advanced cloud, infrastructure-as-code, scripting, container, and API security skills; CISSP/CISA/CEH/GIAC or cloud certs preferred; Bachelor's or equivalent.
AWS, Azure, Google Cloud Platform, Terraform, CloudFormation, Pulumi, Ansible, Python, Golang, PowerShell, Java, Shell script, Linux, Windows Server, CI/CD
2w
Save
Mark Applied
Hide
Staff App Sec Engineer-Austin, Dallas or San Antonio, TX
Austin or Dallas or San Antonio
HybridFull Time
H-E-B
H-E-B: Operates a major supermarket chain in Texas and Mexi
10+ YOE10+ years building and supporting security solutions; strong cloud, CI/CD, container, and application security skills; bachelor's or equivalent; professional security certification preferred.
AWS, Azure, Google Cloud Platform, Terraform, CloudFormation, Pulumi, Ansible, Python, Golang, PowerShell, Java, Shell script
2w
Save
Mark Applied
Hide
Senior Application Security Engineer
Malvern or Charlotte or Plano or Dallas
HybridFull Time
Vanguard
Vanguard: Global investment management and financial services provider.
Requires a related undergraduate degree or equivalent experience, strong DAST deployment and CI/CD integration experience, application security expertise, and familiarity with NIST, OWASP, and MITRE.
DAST, CI/CD, SAST, SCA, IAST, RASP, NIST, OWASP, MITRE