Security Engineer - Email Security

Zelis Healthcare, LLC

Morris Township (NJ)

Hybrid

USD 135,000 - 186,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Zelis Healthcare, LLC is seeking a Security Engineer focused on Email Security to harden our enterprise email environment. You will prevent phishing, BEC, and other threats, while administering security controls in Exchange Online and Defender for O365, and supporting mail-flow operations.

The role requires hands-on Exchange Online experience, strong security incident response skills, and collaboration with SOC, Identity, and Infrastructure teams.

Qualifications

  • 5+ years designing and implementing enterprise-grade email security guardrails in regulated fintech or healthcare environments.
  • 3+ years hands-on experience with Microsoft Exchange, Exchange Online, or Microsoft 365 messaging environments.
  • Strong knowledge of email protocols and technologies including SMTP, DNS, SPF, DKIM, DMARC.
  • Experience investigating phishing, spam, malware, spoofing, and BEC incidents.
  • Familiarity with Defender for Office 365, EOP, or similar platforms.

Responsibilities

  • Analyze suspicious messages, including headers, routing, URLs, attachments, sender reputation, and indicators of compromise.
  • Administer and support email security controls within Exchange Online, Defender for O365, EasyDMARC, and Abnormal Security.
  • Troubleshoot mail delivery, mail-flow, quarantine, filtering, and security-policy issues.
  • Review Exchange message traces and mail-flow logs to determine disposition and issues.
  • Configure mail-flow rules, anti-spam/anti-phishing policies, allow/block lists, and quarantine policies.
  • Assist with incident containment/remediation, including blocking, URL/malware controls, and account remediation.

Skills

Email security
Phishing prevention
BEC prevention
Email header analysis
Incident response

Tools

Exchange Online
Defender for Office 365
EOP
Abnormal Security
PowerShell

Job description

A Little About Us

Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts - driving real, measurable results for clients.

A Little About You

You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are.

Position Overview

Zelis is seeking a Security Engineer - Email Security to support and enhance the security, reliability, and protection of our enterprise email environment. This role will focus on identifying and preventing email-based threats, administering email security controls, troubleshooting mail-flow and security issues, and supporting Microsoft 365/Exchange Online environments. The ideal candidate has hands‑on experience with Microsoft Exchange, email security technologies, phishing investigations, mail‑flow analysis, and security incident response. This individual will work closely with Security Operations, Messaging/Infrastructure, Identity, and other technology teams to protect the organization from phishing, business email compromise (BEC), malware, spoofing, and other email‑based threats.

Key Responsibilities
  • Perform detailed analysis of suspicious messages, including email headers, message routing, URLs, attachments, sender reputation, authentication results, and other indicators of compromise.
  • Administer and support email security controls within Exchange Online, Defender for O365, EasyDMARC, and Abnormal Security environments.
  • Troubleshoot email delivery, mail-flow, quarantine, filtering, and security-policy issues.
  • Review and analyze Exchange message traces and mail-flow logs to determine message disposition and identify security or delivery issues.
  • Configure and maintain mail-flow rules, anti-spam policies, anti-phishing protections, allow/block lists, quarantine policies, and related email security controls.
  • Support incident containment and remediation activities, including message removal, sender/domain blocking, URL blocking, mailbox remediation, and escalation of compromised accounts.
  • Assist with administration and tuning of Microsoft Defender for Office 365 or comparable secure email gateway/email security technologies.
  • Analyze and troubleshoot email authentication technologies including SPF, DKIM, and DMARC.
  • Identify false positives and false negatives and recommend improvements to email security policies and detection rules.
  • Document investigations, findings, remediation actions, and recurring email security issues.
  • Create and maintain operational procedures, troubleshooting guides, and knowledge‑base documentation.
  • Collaborate with SOC, Incident Response, Identity and Access Management, Infrastructure, and Messaging teams during security investigations.
  • Assist with email security metrics, reporting, trend analysis, and continuous improvement initiatives.
  • Stay current on emerging phishing techniques, business email compromise tactics, attacker infrastructure, and email security best practices.
Required Qualifications
  • 5+ years of proven experience designing and implementing enterprise‑grade email security guardrails in regulated fintech or healthcare environments with a strong security‑first mindset and expertise in phishing and BEC prevention, email authentication, data loss prevention, policy enforcement, monitoring, and incident response.
  • 3+ years of hands‑on experience with Microsoft Exchange, Exchange Online, or Microsoft 365 messaging environments.
  • Working knowledge of Microsoft Exchange mail flow, connectors, transport/mail-flow rules, message tracking, and message tracing.
  • Experience investigating phishing, spam, malware, spoofing, and business email compromise incidents.
  • Strong understanding of email protocols and technologies, including SMTP, DNS, SPF, DKIM, and DMARC.
  • Experience analyzing email headers and determining message origin, routing, authentication results, and potential indicators of malicious activity.
  • Familiarity with Microsoft Defender for Office 365, Exchange Online Protection (EOP), or similar enterprise email security platforms.
  • Understanding common attacker techniques involving credential phishing, malicious attachments, malicious URLs, impersonation, and account compromise.
  • Strong analytical, troubleshooting, documentation, and communication skills.
  • Ability to independently investigate moderately complex incidents and appropriately elevate high‑risk or advanced threats.
Preferred Qualifications
  • Experience with Microsoft Defender for Office 365, including Safe Links, Safe Attachments, Threat Explorer, automated investigation and response, and related capabilities.
  • Experience using Microsoft Purview, Microsoft Sentinel, or the Microsoft Defender security ecosystem.
  • Experience with PowerShell for Exchange Online administration, investigation, or automation.
  • Familiarity with other Microsoft tools; Defender for Endpoint, Purview, etc. Support administration, monitoring, and policy tuning of EDR/XDR platforms.
  • Experience investigating compromised Microsoft 365 accounts and malicious inbox or forwarding rules.
  • Knowledge of email security gateways or platforms such as Proofpoint, Mimecast, Cisco Secure Email, Abnormal Security, or similar technologies.
  • Familiarity with threat intelligence concepts, indicators of compromise (IOCs), and attacker tactics, techniques, and procedures (TTPs).
  • Knowledge of AI/ML security concepts and emerging threats, data leakage, model abuse, identity and access controls, secure integrations, and protection of sensitive data within AI‑enabled systems.
Core Competencies
  • Email Security & Threat Analysis
  • Microsoft Exchange / Exchange Online
  • Microsoft 365 Security
  • Microsoft Defender for Office 365
  • Email Header & Mail‑Flow Analysis
  • SPF, DKIM & DMARC
  • Troubleshooting & Root Cause Analysis
  • PowerShell / Security Automation
  • Technical Documentation
  • Cross-functional Collaboration

Please note at this time we are unable to proceed with candidates who require visa sponsorship now or in the future.

Location and Workplace Flexibility

Zelis is headquartered in the U.S., with multiple locations across the country and in Hyderabad, India. Check out our locations to learn more about our offices. All employee work locations are based on the needs of the position and are determined by the Leadership team. In‑office work and activities vary based on work and team objectives in accordance with Company policies.

While location expectations vary by role, candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed. Our hybrid approach is flexible, and in‑office presence is guided by team and business needs rather than a fixed weekly schedule.

Base Salary Range

$135,200.00 - $185,900.00

At Zelis we are committed to providing fair and equitable compensation packages. The base salary range allows us to make an offer that considers multiple individualized factors, including experience, education, qualifications, as well as job‑related and industry‑related knowledge and skills, etc. Base pay is just one part of our Total Rewards package, which may also include discretionary bonus plans, commissions, or other incentives depending on the role.

Zelis' full‑time associates are eligible for a highly competitive benefits package as well, which demonstrates our commitment to our employees' health, well‑being, and financial protection. The US‑based benefits include a 401k plan with employer match, flexible paid time off, holidays, parental leaves, life and disability insurance, and health benefits including medical, dental, vision, and prescription drug coverage.

Equal Employment Opportunity

Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. We welcome applicants from all backgrounds and encourage you to apply even if you don't meet 100% of the qualifications for the role. We believe in the value of diverse perspectives and experiences and are committed to building an inclusive workplace for all.

Accessibility Support

We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email TalentAcquisition@zelis.com.

Disclaimer

The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities, duties, and skills from time to time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Email Security
Security Engineer - Email Security

Zelis • Morristown (NJ)

Hybrid
USD 135,000 - 186,000
401k with match
Health benefits
Flexible PTO
Senior Security Operations Center (SOC) Analyst
Senior Security Operations Center (SOC) Analyst

Zelis Healthcare, LLC • Atlanta (GA)

Hybrid
USD 112,000 - 154,000
401k with employer match
Flexible PTO & Holidays
Health, dental, vision benefits
Director, Infrastructure & Security Delivery
Director, Infrastructure & Security Delivery

Zelis • Missouri

On-site
USD 153,000 - 194,000
401k with match
Paid time off
Health insurance
+1
Director, Infrastructure & Security Delivery
Director, Infrastructure & Security Delivery

Zelis Healthcare, LLC • Missouri

On-site
USD 153,000 - 194,000
401k plan with employer match
Health benefits
Manager, Reliability and Observability
Manager, Reliability and Observability

Zelis Healthcare, LLC • Morris Township (NJ)

Hybrid
USD 140,000 - 186,000
Service Reliability Specialist
Service Reliability Specialist

Zelis Healthcare, LLC • Morris Township (NJ)

On-site
USD 65,000 - 83,000
401k with employer match
Hybrid work model
Health benefits
Email Security Engineer — Threat & Incident Response
Email Security Engineer — Threat & Incident Response

Zelis Healthcare, LLC • Morris Township (NJ)

Hybrid
USD 135,000 - 186,000
Senior Systems Engineer
Senior Systems Engineer

Zelis Healthcare, LLC • Atlanta (GA)

On-site
USD 102,000 - 140,000
401k with employer match
Flexible PTO
Holidays
+3
Process Excellence Consultant
Process Excellence Consultant

Zelis Healthcare, LLC • Creve Coeur (MO)

Hybrid
USD 79,000 - 100,000
Health insurance
401k match
Flexible PTO
+2
Senior Systems Engineer
Senior Systems Engineer

Zelis • Atlanta (GA)

Hybrid
USD 102,000 - 140,000
401(k) with employer match
Paid time off
Health insurance
+2