Performant Financial

Security Engineer - Email Security

Performant Financial • $135K — $185K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years designing enterprise email security in regulated environments
  • 3+ years hands-on experience with Microsoft Exchange or 365
  • Working knowledge of email flow, connectors, and rules
  • Experience in phishing and business email compromise investigations
  • Strong grasp of SMTP, DNS, SPF, DKIM, and DMARC
  • Capability to analyze email headers for signs of compromise
  • Familiarity with Microsoft Defender for Office 365 or similar platforms

Responsibilities

  • Analyze suspicious emails and indicators of compromise
  • Administer email security controls in Exchange Online and Defender for O365 environments
  • Troubleshoot mail-flow and security policy issues
  • Review message traces and logs to identify delivery issues
  • Configure anti-phishing and spam policies, and maintain security controls
  • Support incident response activities including containment and remediation
  • Collaborate with cross-functional teams on security investigations

Benefits

  • 401k plan with employer match
  • Flexible paid time off and holidays
  • Parental leave policies
  • Life and disability insurance
  • Comprehensive medical, dental, and vision plans
  • Prescription drug coverage
Full Job Description
Position Overview
Zelis is seeking a Security Engineer - Email Security to support and enhance the security, reliability, and protection of our enterprise email environment. This role will focus on identifying and preventing email-based threats, administering email security controls, troubleshooting mail-flow and security issues, and supporting Microsoft 365/Exchange Online environments.
The ideal candidate has hands-on experience with Microsoft Exchange, email security technologies, phishing investigations, mail-flow analysis, and security incident response. This individual will work closely with Security Operations, Messaging/Infrastructure, Identity, and other technology teams to protect the organization from phishing, business email compromise (BEC), malware, spoofing, and other email-based threats.
Key Responsibilities
  • Perform detailed analysis of suspicious messages, including email headers, message routing, URLs, attachments, sender reputation, authentication results, and other indicators of compromise.
  • Administer and support email security controls within Exchange Online, Defender for O365, EasyDMARC, and Abnormal Security environments.
  • Troubleshoot email delivery, mail-flow, quarantine, filtering, and security-policy issues.
  • Review and analyze Exchange message traces and mail-flow logs to determine message disposition and identify security or delivery issues.
  • Configure and maintain mail-flow rules, anti-spam policies, anti-phishing protections, allow/block lists, quarantine policies, and related email security controls.
  • Support incident containment and remediation activities, including message removal, sender/domain blocking, URL blocking, mailbox remediation, and escalation of compromised accounts.
  • Assist with administration and tuning of Microsoft Defender for Office 365 or comparable secure email gateway/email security technologies.
  • Analyze and troubleshoot email authentication technologies including SPF, DKIM, and DMARC.
  • Identify false positives and false negatives and recommend improvements to email security policies and detection rules.
  • Document investigations, findings, remediation actions, and recurring email security issues.
  • Create and maintain operational procedures, troubleshooting guides, and knowledge-base documentation.
  • Collaborate with SOC, Incident Response, Identity and Access Management, Infrastructure, and Messaging teams during security investigations.
  • Assist with email security metrics, reporting, trend analysis, and continuous improvement initiatives.
  • Stay current on emerging phishing techniques, business email compromise tactics, attacker infrastructure, and email security best practices.
Required Qualifications
  • 5+ years of proven experience designing and implementing enterprise-grade email security guardrails in regulated fintech or healthcare environments with a strong security-first mindset and expertise in phishing and BEC prevention, email authentication, data loss prevention, policy enforcement, monitoring, and incident response.
  • 3+ years of hands-on experience with Microsoft Exchange, Exchange Online, or Microsoft 365 messaging environments.
  • Working knowledge of Microsoft Exchange mail flow, connectors, transport/mail-flow rules, message tracking, and message tracing.
  • Experience investigating phishing, spam, malware, spoofing, and business email compromise incidents.
  • Strong understanding of email protocols and technologies, including SMTP, DNS, SPF, DKIM, and DMARC.
  • Experience analyzing email headers and determining message origin, routing, authentication results, and potential indicators of malicious activity.
  • Familiarity with Microsoft Defender for Office 365, Exchange Online Protection (EOP), or similar enterprise email security platforms.
  • Understanding common attacker techniques involving credential phishing, malicious attachments, malicious URLs, impersonation, and account compromise.
  • Strong analytical, troubleshooting, documentation, and communication skills.
  • Ability to independently investigate moderately complex incidents and appropriately escalate high-risk or advanced threats.
Preferred Qualifications
  • Experience with Microsoft Defender for Office 365, including Safe Links, Safe Attachments, Threat Explorer, automated investigation and response, and related capabilities.
  • Experience using Microsoft Purview, Microsoft Sentinel, or the Microsoft Defender security ecosystem.
  • Experience with PowerShell for Exchange Online administration, investigation, or automation.
  • Familiarity with other Microsoft tools; Defender for Endpoint, Purview, etc. Support administration, monitoring, and policy tuning of EDR/XDR platforms.
  • Experience investigating compromised Microsoft 365 accounts and malicious inbox or forwarding rules.
  • Knowledge of email security gateways or platforms such as Proofpoint, Mimecast, Cisco Secure Email, Abnormal Security, or similar technologies.
  • Familiarity with threat intelligence concepts, indicators of compromise (IOCs), and attacker tactics, techniques, and procedures (TTPs).
  • Knowledge of AI/ML security concepts and emerging threats, data leakage, model abuse, identity and access controls, secure integrations, and protection of sensitive data within AI-enabled systems.
Core Competencies
  • Email Security & Threat Analysis
  • Microsoft Exchange / Exchange Online
  • Microsoft 365 Security
  • Microsoft Defender for Office 365
  • Email Header & Mail-Flow Analysis
  • SPF, DKIM & DMARC
  • Troubleshooting & Root Cause Analysis
  • PowerShell / Security Automation
  • Technical Documentation
  • Cross-functional Collaboration


Please note at this time we are unable to proceed with candidates who require visa sponsorship now or in the future.

Location and Workplace Flexibility

Zelis is headquartered in the U.S., with multiple locations across the country and in Hyderabad, India. Check out our locations to learn more about our offices. All employee work locations are based on the needs of the position and are determined by the Leadership team. In-office work and activities vary based on work and team objectives in accordance with Company policies.

While location expectations vary by role, candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed. Our hybrid approach is flexible, and in-office presence is guided by team and business needs rather than a fixed weekly schedule.

Base Salary Range
$135,200.00 - $185,900.00

At Zelis we are committed to providing fair and equitable compensation packages. The base salary range allows us to make an offer that considers multiple individualized factors, including experience, education, qualifications, as well as job-related and industry-related knowledge and skills, etc. Base pay is just one part of our Total Rewards package, which may also include discretionary bonus plans, commissions, or other incentives depending on the role.

Zelis' full-time associates are eligible for a highly competitive benefits package as well, which demonstrates our commitment to our employees' health, well-being, and financial protection. The US-based benefits include a 401k plan with employer match, flexible paid time off, holidays, parental leaves, life and disability insurance, and health benefits including medical, dental, vision, and prescription drug coverage.

About Performant Financial

Performant Financial Corporation is a business services company that provides technology-enabled recovery and related analytics services in the United States. The company primarily offers recovery services to the government and private clients in various markets, such as healthcare, student loans, and general collections. Performant Financial Corporation was founded in 1976 and is headquartered in Livermore, California.
Learn more about Performant Financial
Size
1,269 employees
Market Cap
$237.8 million
Industry
Net Income
-$21.5 million
Founded
1976
5 Year Trend
-2.5%
Revenue
$159.7 million
NASDAQ

Similar Jobs

More Jobs at Performant Financial

More Information Technology Jobs

Find similar Security Engineer - Email Security jobs: