Performant Financial

Application Security Engineer – Software Composition Analysis (SCA)

Performant Financial$127K — $160K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in various AppSec domains.
  • Deep expertise in Software Composition Analysis (SCA).
  • Strong proficiency in multiple programming languages such as Java, Python, C++, and Ruby.
  • Experience with integrating security tools in CI/CD pipelines and managing open-source license compliance.
  • Knowledge of application security best practices including OWASP Top 10 and Secure Software Development Lifecycle (SSDLC).

Responsibilities

  • Lead the integration and optimization of SCA solutions to assess software for vulnerabilities and compliance.
  • Establish processes to manage risks linked to open-source and third-party dependencies.
  • Automate security tools within CI/CD pipelines for ongoing security validation.
  • Deploy SCA and application security platforms, including emerging AI-based solutions.
  • Analyze vulnerabilities for exploitability and develop remediation prioritization strategies.
  • Provide technical guidance on security best practices to development teams.
  • Maintain open-source software governance policies and validate security findings.

Benefits

  • 401k plan with employer match.
  • Flexible paid time off and holidays.
  • Parental leave policies.
  • Life and disability insurance.
  • Health benefits including medical, dental, vision, and prescription drug coverage.
Full Job Description

Position Overview

Zelis is seeking an experienced Application Security Engineer with deep expertise in Software Composition Analysis (SCA) to strengthen the security of our software supply chain and reduce risks associated with open-source and third-party software components in internally developed applications. This role will help integrate scanning tools into CI/CD pipelines and partner with developers, engineering teams to triage vulnerabilities to embed security controls throughout the software development lifecycle.

The ideal candidate will have extensive experience integrating SCA and application security tooling into CI/CD pipelines, evaluating vulnerability exploitability, managing open-source license compliance, and enabling developers to build secure applications at scale. Experience with AI/LLM-focused security scanning tools and emerging application security technologies is highly desirable.

Key Responsibilities :

  • 8+ years of experience in various AppSec domains
  • Lead the implementation and optimization of Software Composition Analysis (SCA) solutions to identify vulnerabilities, license compliance issues, and software supply chain risks across enterprise applications.
  • Establish and maintain processes for managing risks associated with open-source and third-party software dependencies.
  • Integrate and automate SCA and application security tools within CI/CD pipelines to provide continuous security validation throughout the software development lifecycle.
  • Deploy and manage security platforms such as Synk, Black Duck, Mend, Veracode, Checkmarx ONE, experience with any emerging AI/LLM-based security scanning solutions would be desirable.
  • Experience embedding security guardrails into build pipelines using tools like Jenkins, GitHub Actions, or GitLab CI. Artifactory integration experience in the pipeline and developer workflows would be desirable.
  • Analyze identified vulnerabilities to determine exploitability, reachability, and potential business impact.
  • Perform risk-based prioritization of findings, focusing remediation efforts on vulnerabilities that pose the greatest threat to the organization.
  • Validate findings to reduce false positives and improve overall vulnerability management effectiveness.
  • Develop, maintain, and enforce open-source software governance policies.
  • Provide technical guidance, security coding and best practices to development teams.
  • Strong proficiency in multiple programming languages, including Java, Python, C++, Ruby
  • Strong understanding of how third-party packages are integrated through external public repos(e.g., npm for JavaScript, pip for Python, Maven/Gradle for Java).
  • Knowledge of application security best practices and industry standards, including OWASP Top 10, Secure Software Development Lifecycle (SSDLC), Software Supply Chain Security principles, Vulnerability Management frameworks


Professional Skills :

  • Excellent communication, strong analytical thinking and problem-solving capabilities.
  • Self-motivated with a commitment to continuous learning and staying current with evolving security threats and technologies.


Education :

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical discipline.

Please note at this time we are unable to proceed with candidates who require visa sponsorship now or in the future.


Location and Workplace Flexibility

Zelis is headquartered in the U.S., with multiple locations across the country and in Hyderabad, India. Check out our locations to learn more about our offices. All employee work locations are based on the needs of the position and are determined by the Leadership team. In-office work and activities vary based on work and team objectives in accordance with Company policies.


While location expectations vary by role, candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed. Our hybrid approach is flexible, and in-office presence is guided by team and business needs rather than a fixed weekly schedule.

Base Salary Range

$127,000.00 - $160,550.00

At Zelis we are committed to providing fair and equitable compensation packages. The base salary range allows us to make an offer that considers multiple individualized factors, including experience, education, qualifications, as well as job-related and industry-related knowledge and skills, etc. Base pay is just one part of our Total Rewards package, which may also include discretionary bonus plans, commissions, or other incentives depending on the role.

Zelis’ full-time associates are eligible for a highly competitive benefits package as well, which demonstrates our commitment to our employees’ health, well-being, and financial protection. The US-based benefits include a 401k plan with employer match, flexible paid time off, holidays, parental leaves, life and disability insurance, and health benefits including medical, dental, vision, and prescription drug coverage.

About Performant Financial

Performant Financial Corporation is a business services company that provides technology-enabled recovery and related analytics services in the United States. The company primarily offers recovery services to the government and private clients in various markets, such as healthcare, student loans, and general collections. Performant Financial Corporation was founded in 1976 and is headquartered in Livermore, California.
Learn more about Performant Financial
Size
1,269 employees
Market Cap
$237.8 million
Industry
Net Income
-$21.5 million
Founded
1976
5 Year Trend
-2.5%
Revenue
$159.7 million
NASDAQ

Similar Jobs

More Jobs at Performant Financial

More Information Technology Jobs

Find similar Application Security Engineer – Software Composition Analysis (SCA) jobs: