Application Security Engineer - Software Composition Analysis (SCA)
Sapphire Digital, Part of Zelis
Missouri · St. Louis, MO · St. Petersburg, FL · Plano, TX · Morristown, NJ · Boston, MA · Atlanta, GA$127k–$161kPosted Jul 22, 2026
Skip to main contentWe use cookies to make the safest and most effective website possible. DeclineAccept CookiesZelis CareersSign InApplication Security Engineer – Software Composition Analysis (SCA) page is loadedApplication Security Engineer – Software Composition Analysis (SCA)ApplylocationsUS TX PlanoUS MA BostonUS FL St. PetersburgUS MO St. Louis (Corp)US GA AtlantaView All 6 Locationstime typeFull timeposted onPosted Yesterdayjob requisition idJR111451At Zelis, we Get Stuff Done. So, let’s get to it! A Little About Us Zelis is modernizing the healthcare financial experience across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.At Zelis, AI is woven into the fabric of how we work. Every associate is expected - and empowered - to partner with AI to challenge the status quo, accelerate innovation, and amplify their impact. This is a place for builders with a growth mindset who act with agility, embrace change, and use modern technology to shape smarter solutions, exceptional experiences, and the future of our industry for our clients, customers, and our culture. A Little About You You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are.Position OverviewZelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and reduce risks associated with open-source and third-party software components in internally developed applications. This role will help integrate scanning tools into CI/CD pipelines and partner with developers, engineering teams to triage vulnerabilities to embed security controls throughout the software development lifecycle.The ideal candidate will have extensive experience integrating SCA and application security tooling into CI/CD pipelines, evaluating vulnerability exploitability, managing open-source license compliance, and enabling developers to build secure applications at scale. Experience with AI/LLM-focused security scanning tools and emerging application security technologies is highly desirable.Key Responsibilities :8+ years of experience in various AppSec domainsLead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks across enterprise applications.Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.Integrate and automate SCA and application security tools within CI/CD pipelines to provide continuous security validation throughout the software development lifecycle.Deploy and manage security platforms such as Synk, Black Duck, Mend, Veracode, Checkmarx ONE, experience with any emerging AI/LLM-based security scanning solutions would be desirable.Experience embedding security guardrails into build pipelines using tools like Jenkins, GitHub Actions, or GitLab CI. Artifactory integration experience in the pipeline and developer workflows would be desirable.Analyze identified vulnerabilities to determine exploitability, reachability, and potential business impact.Perform risk-based prioritization of findings, focusing remediation efforts on vulnerabilities that pose the greatest threat...