At Zelis, we Get Stuff Done. So, let's get to it!
Zelis is modernizing the healthcare financial experience for all by providing a connected platform that bridges the gaps and aligns interests across payers, providers, and healthcare consumers. This platform serves more than 750 payers, including the top 5 national health plans, BCBS insurers, regional health plans, TPAs and self-insured employers, and millions of healthcare providers and consumers. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts-driving real, measurable results for clients.
You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are. Position Overview Reporting to the Head of Application Security, you will be a key contributor to securing our corporate applications by collaborating closely with application development teams. This role is accountable for application security through threat modeling, DevSecOps automation, and implementation of security controls.
The ideal candidate brings strong security expertise with scripting and automation skills but is not expected to have deep software engineering or programming experience. You will work cross-functionally to identify application assets, map data flows, evaluate threats, and ensure cybersecurity controls are embedded and continuously measured.
What You'll Do
Lead threat modeling exercises to proactively identify security risks across applications and infrastructure layers. Collaborate with agile and waterfall development teams to integrate security requirements and acceptance criteria throughout the SDLC. Analyze application components, data flows, and external dependencies to anticipate and mitigate vulnerabilities. Automate security build pipelines and scanning processes, focusing on Docker container security and security scanning automation using scripting languages such as Python, PowerShell, or Ruby. Conduct security code reviews targeting common vulnerabilities (e.g., injection, XSS, insecure configurations), without requiring deep programming expertise. Implement and maintain security controls including encryption, authentication, access controls, and input validation. Provide guidance and training on secure coding practices and security tool usage to development teams. Evaluate and deploy security tools and automation solutions to enhance application security posture and streamline operations. Partner closely with Application Security Testers to measure control effectiveness and identify gaps. Ensure alignment with regulatory frameworks and industry best practices including HIPAA, PCI, NIST, and others.
What You Bring Required:
Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience). 12+ years of cybersecurity experience with 4+ years specifically in application security and threat modeling. 2+ years working in Agile environments, writing user stories including security acceptance criteria. Proficiency in scripting languages (Python, PowerShell, Ruby) to automate security processes, with a focus on container and build pipeline automation. Strong understanding of API, web application, and container security vulnerabilities. Experience in Microsoft technology stack (.NET and related). Excellent verbal and written communication skills and strong customer service orientation. Comfortable working cross-functionally with development, security testing, and operations teams.
Preferred:
Hands-on experience with secure code review and application development. Familiarity with source code management, build/deployment pipelines, and web application firewalls. Knowledge of OWASP Top 10, MITRE CWE Top 25, and secure coding standards. Relevant certifications such as CISSP, CDP, E|CDE. Experience with compliance and regulatory standards such as HIPAA, PCI, CIS, HiTrust, ISO 27001, NIST.
Location and Workplace Flexibility We have offices in Atlanta GA, Boston MA, Morristown NJ, Plano TX, St. Louis MO, St. Petersburg FL, and Hyderabad, India. We foster a hybrid and remote friendly culture, and all our employee's work locations are based on the needs of the position and determined by the Leadership team. In-office work and activities, if applicable, vary based on the work and team objectives in accordance with Company policies.
Equal Employment Opportunity Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. We welcome applicants from all backgrounds and encourage you to apply even if you don't meet 100% of the qualifications for the role. We believe in the value of diverse perspectives and experiences and are committed to building an inclusive workplace for all.
Accessibility Support We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email TalentAcquisition@zelis.com.
We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.
The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities, duties, and skills from time to time.
|