Application Security Engineer – Software Composition Analysis (SCA)

Zelis

Plano (TX)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Zelis is seeking an experienced Application Security Engineer to strengthen our software supply chain by integrating SCA tools into CI/CD pipelines and collaborating with development teams to triage vulnerabilities. You will drive secure coding practices and OSS governance across enterprise applications.

The ideal candidate has 8+ years in AppSec, hands-on experience with SCA platforms, and a strong background in Java, Python, C++, and Ruby, plus familiarity with AI/LLM-based scanning tools.

Qualifications

  • Proven experience leading SCA solutions across enterprise apps.
  • Experience integrating SCA tools into CI/CD pipelines.
  • Strong knowledge of OSS governance and license compliance.
  • Familiarity with AI/LLM-based security scanning is a plus.
  • Proficient in multiple languages and secure SDLC practices.

Responsibilities

  • Lead SCA solution implementation and optimization across apps.
  • Automate SCA and app security in CI/CD pipelines for continuous validation.
  • Assess vulnerability exploitability and risk-based prioritization.
  • Embed security guardrails in build pipelines (Jenkins, GitHub Actions, GitLab).
  • Guide developers on secure coding and open-source governance.
  • Analyze findings and reduce false positives in assessments.
  • Collaborate with teams to embed security controls in SDLC.

Skills

AppSec experience
CI/CD security
Java
Python
C++
Ruby
Vulnerability analysis
Threat modeling

Education

Bachelor's degree in CS/IT/Cybersecurity/Engineering

Tools

Synk
Black Duck
Mend
Veracode
Checkmarx ONE
Jenkins
GitHub Actions
GitLab CI
Artifactory

Job description

At Zelis, we Get Stuff Done. So, let’s get to it!

A Little About Us

Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.

At Zelis, AI is woven into the fabric of how we work. Every associate is expected - and empowered - to partner with AI to challenge the status quo, accelerate innovation, and amplify their impact. This is a place for builders with a growth mindset who act with agility, embrace change, and use modern technology to shape smarter solutions, exceptional experiences, and the future of our industry for our clients, customers, and our culture.

A Little About You

You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are.

Position Overview

Zelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and reduce risks associated with open-source and third-party software components in internally developed applications. This role will help integrate scanning tools into CI/CD pipelines and partner with developers, engineering teams to triage vulnerabilities to embed security controls throughout the software development lifecycle.

The ideal candidate will have extensive experience integrating SCA and application security tooling into CI/CD pipelines, evaluating vulnerability exploitability, managing open-source license compliance, and enabling developers to build secure applications at scale. Experience with AI/LLM-focused security scanning tools and emerging application security technologies is highly desirable.

Key Responsibilities

  • 8+ years of experience in various AppSec domains
  • Lead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks across enterprise applications.
  • Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
  • Integrate and automate SCA and application security tools within CI/CD pipelines to provide continuous security validation throughout the software development lifecycle.
  • Deploy and manage security platforms such as Synk, Black Duck, Mend, Veracode, Checkmarx ONE, experience with any emerging AI/LLM-based security scanning solutions would be desirable.
  • Experience embedding security guardrails into build pipelines using tools like Jenkins, GitHub Actions, or GitLab CI. Artifactory integration experience in the pipeline and developer workflows would be desirable.
  • Analyze identified vulnerabilities to determine exploitability, reachability, and potential business impact.
  • Perform risk-based prioritization of findings, focusing remediation efforts on vulnerabilities that pose the greatest threat to the organization.
  • Validate findings to reduce false positives and improve overall vulnerability management effectiveness.
  • Develop, maintain, and enforce open-source software governance policies.
  • Provide technical guidance, security coding and best practices to development teams.
  • Strong proficiency in multiple programming languages, including Java, Python, C++, Ruby
  • Strong understanding of how third-party packages are integrated through external public repos(e.g., npm for JavaScript, pip for Python, Maven/Gradle for Java).
  • Knowledge of application security best practices and industry standards, including OWASP Top 10, Secure Software Development Lifecycle (SSDLC), Software Supply Chain Security principles, Vulnerability Management frameworks

Professional Skills

  • Excellent communication, strong analytical thinking and problem-solving capabilities.
  • Self-motivated with a commitment to continuous learning and staying current with evolving security threats and technologies.

Education

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer – Software Composition Analysis (SCA)
Application Security Engineer – Software Composition Analysis (SCA)

LE018 Zelis Healthcare, LLC • Plano (TX)

On-site
USD 127,000 - 161,000
401(k) plan with employer match
PTO & holidays
Life insurance
+1
Application Security Engineer - Software Composition Analysis (SCA)
Application Security Engineer - Software Composition Analysis (SCA)

Zelis Healthcare, LLC • Plano (TX)

Hybrid
USD 127,000 - 161,000
401k with employer match
Health benefits
Senior SCA & AppSec Engineer for Secure CI/CD
Senior SCA & AppSec Engineer for Secure CI/CD

Zelis • Plano (TX)

On-site
USD 120,000 - 180,000
SCA & AppSec Engineer — Secure Software Supply Chain
SCA & AppSec Engineer — Secure Software Supply Chain

Zelis Healthcare, LLC • Plano (TX)

Hybrid
USD 127,000 - 161,000
401k with employer match
Health benefits
Application Security Engineer: SCA & Secure CI/CD Expert
Application Security Engineer: SCA & Secure CI/CD Expert

LE018 Zelis Healthcare, LLC • Plano (TX)

On-site
USD 127,000 - 161,000
401(k) plan with employer match
PTO & holidays
Life insurance
+1
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
DevSecOps Tech Lead
DevSecOps Tech Lead

CIBR Warriors • Charlotte (NC)

On-site
USD 120,000 - 150,000
Application Security Engineer
Application Security Engineer

ALLTECH CONSULTING SVC INC • Georgia

On-site
USD 100,000 - 130,000