About Us
Zelis is modernizing the healthcare financial experience in the United States (U.S.) across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.
At Zelis, AI is woven into the fabric of how we work. Every associate is expected - and empowered - to partner with AI to challenge the status quo, accelerate innovation, and amplify their impact. This is a place for builders with a growth mindset who act with agility, embrace change, and use modern technology to shape smarter solutions, exceptional experiences, and the future of our industry for our clients, customers, and our culture.
Why We Do What We Do
In the U.S., consumers, payers, and providers face significant challenges throughout the healthcare financial journey. Zelis helps streamline the process by offering solutions that improve transparency, efficiency, and communication among all parties involved. By addressing the obstacles that patients face in accessing care, navigating the intricacies of insurance claims, and the logistical challenges healthcare providers encounter with processing payments, Zelis aims to create a more seamless and effective healthcare financial system.
Zelis India plays a crucial role in this mission by supporting various initiatives that enhance the healthcare financial experience. The local team contributes to the development and implementation of innovative solutions, ensuring that technology and processes are optimized for efficiency and effectiveness. Beyond operational expertise, Zelis India cultivates a collaborative work culture, leadership development, and global exposure, creating a dynamic environment for professional growth. With hybrid work flexibility, comprehensive healthcare benefits, financial wellness programs, and cultural celebrations, we foster a holistic workplace experience. Additionally, the team plays a vital role in maintaining high standards of service delivery and contributes to Zelis’ award-winning culture.
Position Overview
Looking for an experienced Application Security Engineer with a strong focus on Software Composition Analysis (SCA) to join our growing security team. The ideal candidate will have hands-on expertise managing open-source and third-party dependency risk across artifact repositories and package management ecosystems, along with working knowledge of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST).Zelis is one of the leading healthcare technology Product organizations with $1.4 Billion revenue with year-on-year growth of 22% and client retention rate of 120%. we offer wide range of innovative solutions to the healthcare payers, providers, and consumers. Our services include network analytics, payment integrity and optimization, provider credentialing, and provider engagement.
Zelis is an US based Software Product development organization founded in 1995 with a headcount 2400+ talented professionals working in 7 offices in US and 1 global capacity center located in Hyderabad, India.
SCA Lead Engineer
Job Summary
We are looking for an experienced Application Security Engineer with a strong focus on Software Composition Analysis (SCA) to join our growing security team. The ideal candidate will have hands-on expertise managing open-source and third-party dependency risk across artifact repositories and package management ecosystems, along with working knowledge of Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). This role will be responsible for identifying, assessing, and remediating vulnerabilities and license risks across our application portfolio, and driving a culture of secure dependency management across engineering teams.
Experience Required
8 to 10 years of relevant experience in Application Security, DevSecOps, or a related field.
Key Responsibilities
Software Composition Analysis (Primary Focus):
- Own and drive the Software Composition Analysis (SCA) program end-to-end — identifying, tracking, and remediating vulnerabilities and license compliance risks in open-source and third-party components/dependencies.
- Configure, manage, and optimize artifact repositories and package registries (JFrog Artifactory/Xray, Sonatype Nexus Repository, Azure Artifacts, GitHub Packages, GitLab Package Registry, AWS CodeArtifact, Google Artifact Registry) with embedded SCA scanning and policy enforcement.
- Establish dependency governance policies (approved/blocked components, license risk thresholds, version pinning strategies) across engineering teams.
- Monitor for newly disclosed CVEs affecting existing dependencies and drive timely remediation or patching across affected applications.
- Maintain a Software Bill of Materials (SBOM) process and ensure traceability of open-source usage across the application portfolio.
SAST / DAST & Broader AppSec:
- Configure, maintain, and optimize SAST and DAST tools across the CI/CD pipeline to enable early detection of security vulnerabilities.
- Integrate security scanning tools (SCA, SAST, DAST) into build and deployment pipelines (Jenkins, GitLab CI, Azure DevOps, GitHub Actions, etc.).
- Triage, prioritize, and track remediation of vulnerabilities identified through SCA, SAST, and DAST scans in collaboration with development teams.
- Conduct manual code reviews and validate automated scan findings to reduce false positives.
- Partner with development, DevOps, and QA teams to embed security practices into the SDLC (Shift-Left Security).
- Develop and maintain application security policies, standards, and guidelines.
- Support periodic penetration testing efforts and coordinate remediation of findings with relevant stakeholders.
- Track and report key application security metrics (vulnerability trends, MTTR, tool coverage, etc.) to leadership.
- Stay current with emerging threats, vulnerabilities (OWASP Top 10, CWE/SANS Top 25), and industry best practices.
- Provide guidance and training to development teams on secure coding practices and remediation techniques.
Required Technical Skills & Tools
Software Composition Analysis (SCA) / Artifact & Package Management (Core Requirement):
- JFrog Artifactory / JFrog Xray
- Sonatype Nexus Repository (Nexus IQ)
- Azure Artifacts
- GitHub Packages
- GitLab Package Registry
- AWS CodeArtifact
- Google Artifact Registry
- Experience with SBOM generation (CycloneDX, SPDX) and open-source license compliance scanning
- Hands-on experience with at least 2-3 of the above artifact repository/package registry tools is required
SAST Tools (any of the following):
- Veracode
- Checkmarx
- HCL AppScan
- SonarQube
DAST Tools (any of the following):
- Invicti (Netsparker)
- Acunetix
- OWASP ZAP
- Veracode DAST / Burp Suite (a plus)
Other Technical Skills:
- Strong understanding of OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes
- Familiarity with CI/CD tools (Jenkins, GitLab CI, Azure DevOps, GitHub Actions)
- Working knowledge of at least one programming/scripting language (Java, Python, JavaScript, .NET, or similar) to review and understand code-level vulnerabilities
- Understanding of container security and cloud security concepts (AWS/Azure/GCP) is a plus
- Familiarity with API security testing and secure API design principles
- Knowledge of security frameworks and standards (NIST, ISO 27001, PCI-DSS) is a plus
Preferred Qualifications
- Bachelor's degree in computer science, Information Security, or a related field (or equivalent practical experience)
- Industry certifications such as: CEH, OSCP, GWAPT, CSSLP, or Security+ (preferred, not mandatory)
- Prior experience working in Agile/DevOps environments
Soft Skills
- Strong analytical and problem-solving skills with attention to detail
- Excellent communication skills to explain technical vulnerabilities to both technical and non-technical stakeholders
- Ability to work collaboratively across cross-functional teams (Development, DevOps, QA, Compliance)
- Self-motivated with the ability to manage multiple priorities in a fast-paced environment
What We Offer
- Opportunity to build and shape a growing Application Security program
- Exposure to modern DevSecOps tools and practices
- Collaborative work culture with continuous learning opportunities
- Competitive compensation and benefits package
Commitment to Diversity, Equity, Inclusion, and Belonging
At Zelis, we champion diversity, equity, inclusion, and belonging in all aspects of our operations. We embrace the power of diversity and create an environment where people can bring their authentic and best selves to work. We know that a sense of belonging is key not only to your success at Zelis, but also to your ability to bring your best each day.
Equal Employment Opportunity
Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
Accessibility Support
We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability and require reasonable accommodation with any part of the application and/or interview process, please email talentacquisition@zelis.com.