Application Security Engineer

Zelis Healthcare
Atlanta, GA, United States
Full-time

Zelis is hiring an Application Security Engineer to work in collaboration with the corporate application development teams.

The position will be accountable for application security of corporate applications. You'll work with Application Development teams to identify application assets, data flows, threats, and required cyber security controls, as well as with Application Security Testers to measure the effectiveness of identified cyber security controls.

Location and Workplace Flexibility : We have offices in Atlanta GA, Boston MA, Morristown NJ, Plano TX, St. Louis MO, St.

Petersburg FL, and Hyderabad, India. We foster a hybrid and remote friendly culture and all of our employee's work locations are based on the needs of the position and determined by the Leadership team.

In-office work and activities, if applicable, vary based on the work and team objectives in accordance with Company policies.

Responsibilities :

  • Partner closely with corporate stakeholders to understand regulatory, industry, and organizational security requirements
  • Provide security requirements with acceptance criteria to application development teams using the Agile and Waterfall methodologies
  • Conduct threat modeling exercises to identify potential security vulnerabilities in corporate applications
  • Analyze application's components, data flows, and external dependencies to anticipate and mitigate threats
  • Review the architecture of software applications to ensure that security is integrated at every layer, including network, infrastructure, and application levels
  • Implement security controls and best practices to address identified risks and vulnerabilities, including encryption, authentication, access controls, input validation, and other security mechanisms
  • Perform security code reviews to identify and remediate security vulnerabilities in application code. Look for common security flaws such as injection attacks, cross-site scripting (XSS), and insecure configurations
  • Provide guidance and training to development teams on secure coding practices, security principles, and relevant security tools and technologies
  • Evaluate and implement security tools and automation solutions to enhance the security posture of applications and streamline security processes

Qualifications

  • Bachelor's degree in Cyber Security (or) related degree and experience
  • 4+ years of experience in Cyber Security
  • 2+ years of experience in Agile and writing user stories
  • 2+ years of experience in Application Security and Threat Modeling, as well as application development or application secure code review
  • Understanding of API and Web security vulnerabilities
  • 2+ years of experience using Octave or Stride
  • Experience working within a DevSecOps environment

Preferred Qualifications

  • Experience in security coding, source code management, and / or build and deployment technologies
  • Experience with web application firewalls
  • Familiarity with OWASP Top 10 API, Web, and Mobile Application Security Risks
  • Familiarity with MITRE CWE Top 25 Most Dangerous Software Weaknesses
  • CDP, CISSP, E CDE or other relevant certifications
  • Familiarity with regulatory controls and industry best practices such as HIPAA, PCI, CIS, HiTrust, ISO 27001, NIST, etc.)

Zelis is modernizing the healthcare financial experience by providing a connected platform that bridges the gaps and aligns interests across payers, providers, and healthcare consumers.

This platform serves more than 750 payers, including the top 5 national health plans, BCBS insurers, regional health plans, TPAs and self-insured employers, and millions of healthcare providers and consumers.

Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts - driving real, measurable results for clients.

Commitment to Diversity, Equity,Inclusion, and Belonging

At Zelis, we champion diversity, equity, inclusion, and belonging in all aspects of our operations. We embrace the power of diversity and create an environment where people can bring their authentic and best selves to work.

We know that a sense of belonging is key not only to your success at Zelis, but also to your ability to bring your best each day.

Equal Employment Opportunity

Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

We encourage members of traditionally underrepresented communities to apply, even if you do not believe you 100% fit the qualifications of the position, including women, LGBTQIA people, people of color, and people with disabilities.

Accessibility Support

We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and / or interview process, please email [email protected].

SCAM ALERT : There is an active nationwide employment scam which is now using Zelis to garner personal information or financial scams.

This site is secure, and any applications made here are with our legitimate partner. If you're contacted by a Zelis Recruiter, please ensure whomever is contacting you truly represents Zelis Healthcare.

We will never asked for the exchange of any money or credit card details during the recruitment process. Please be aware of any suspicious email activity from people who could be pretending to be recruiters or senior professionals at Zelis.

3 days ago
Related jobs
Promoted
VirtualVocations
Decatur, Georgia

A company is looking for an Application Security Engineer to enhance application security and support development teams. ...

Promoted
Sirius XM Radio, Inc.
Atlanta, Georgia

The Application Security Engineer will join the security organization to support SiriusXM technology objectives. The ideal candidate has a passion for finding opportunities and inspiration to solve security challenges and will do so by providing tools, guidance, context and continuous support to ens...

Promoted
VirtualVocations
Decatur, Georgia

A company is looking for a Senior Application Security Engineer to execute its product security strategy. ...

Promoted
Zelis Healthcare, LLC
Atlanta, Georgia

You'll work with Application Development teams to identify application assets, data flows, threats, and required cyber security controls, as well as with Application Security Testers to measure the effectiveness of identified cyber security controls. Evaluate and implement security tools and automat...

Promoted
Motion Recruitment
Atlanta, Georgia

Senior Application & Cloud Container Security EngineerAtlanta, GAHybridContractUp to $62. We are looking for a Senior Application & Cloud Container Security Engineer to join our team for a 12 month contract in Atlanta, GA (hybrid). Guide development teams in integrating new services and applications...

Cox Communications
Atlanta, Georgia

Senior Application Security Engineer. Reporting to the Director of Application Security and Testing, you’ll evaluate the security of in-house or third-party software and devices across the business. Direct experience in application security or testing of applications or devices. This position will r...

WarnerMedia Services, LLC
Atlanta, Georgia

Strong understanding of application security standards and practices, such as the OWASP Mobile Application Security Verification Standard (MASVS) and Mobile Security Testing Guide (MSTG). Application Security Engineer, you will be an important member of the Warner Bros. This is a key role that will ...

Cox Enterprises
Atlanta, Georgia

LeadApplication Security Engineer. Lead Application Security and Testing Engineer. Reporting to the Director of Application Security and Testing, you’ll evaluate the security of in-house or third-party software and devices across the business. Direct experience in application security or testing of ...

Lockheed Martin
Marietta, Georgia

The Manufacturing Systems Applications Engineer Sr Stf will be an integral part of a cross-organizational team of experts supporting the implementation of various production operations capabilities using the Siemens Xcelerator and Dassault 3DX tool suites. From onsite to remote, we offer flexible wo...

Blackbaud
Remote, Georgia, US
Remote

You are either a security-minded software engineer who has been building modern services using a microservice architecture in an agile development environment or a development-interested security practitioner who understands security best practices, but wants to get closer to development and enginee...