Security Engineer - Email Security
Data Security
Email Security
Enterprise Email Security
Exchange Online Security
Incident Response
Information Security
InfoSec
Investigative Skills
Mail Flow Security
Microsoft 365 Admin
Microsoft 365 Administration
Microsoft 365 Security
Microsoft Defender For Office 365
Microsoft Security
Security
Security Automation
Security Engineer
Security Operations
Job Description
Zelis is seeking a Security Engineer to strengthen the security, reliability, and protection of its enterprise email environment. In this hybrid role based in Morristown, NJ, you will help detect and prevent email-based threats, administer email security controls in Microsoft 365, and support investigations across the mail flow lifecycle.
Role Focus
- Support and enhance email security for the enterprise email environment
- Identify and prevent phishing, BEC, spoofing, spam, malware, and other email-borne threats
- Administer and troubleshoot Microsoft 365 and Exchange Online security controls and mail flow
Responsibilities
- Analyze suspicious messages, including email headers, message routing, URLs, attachments, sender reputation, authentication results, and other indicators of compromise
- Administer and support email security controls in Exchange Online, Defender for O365, EasyDMARC, and Abnormal Security environments
- Troubleshoot email delivery and mail-flow issues, including quarantine, filtering, and security-policy problems
- Review Exchange message traces and mail-flow logs to determine message disposition and identify security or delivery issues
- Configure and maintain mail-flow rules, anti-spam and anti-phishing protections, allow/block lists, quarantine policies, and related email security controls
- Support incident containment and remediation, including message removal, sender/domain blocking, URL blocking, mailbox remediation, and escalation for compromised accounts
- Assist with administration and tuning of Microsoft Defender for Office 365 or comparable secure email gateway/email security technologies
- Analyze and troubleshoot email authentication technologies including SPF, DKIM, and DMARC
- Identify false positives and false negatives, and recommend improvements to policies and detection rules
- Document investigations, findings, remediation actions, and recurring email security issues
- Create and maintain operational procedures, troubleshooting guides, and knowledge-base documentation
- Collaborate with SOC, Incident Response, Identity and Access Management, Infrastructure, and Messaging teams during security investigations
- Support email security metrics, reporting, trend analysis, and continuous improvement initiatives
- Stay current on emerging phishing techniques, business email compromise tactics, attacker infrastructure, and email security best practices
Requirements
- 5+ years proven experience designing and implementing enterprise-grade email security guardrails in regulated fintech or healthcare environments with a security-first mindset, including phishing and BEC prevention, email authentication, data loss prevention, policy enforcement, monitoring, and incident response
- 3+ years hands-on experience with Microsoft Exchange, Exchange Online, or Microsoft 365 messaging environments
- Working knowledge of Microsoft Exchange mail flow, connectors, transport/mail-flow rules, and message tracking/message tracing
- Experience investigating phishing, spam, malware, spoofing, and business email compromise incidents
- Strong understanding of email protocols and technologies including SMTP, DNS, SPF, DKIM, and DMARC
- Experience analyzing email headers to determine message origin, routing, authentication results, and potential malicious indicators
- Familiarity with Microsoft Defender for Office 365, Exchange Online Protection (EOP), or similar enterprise email security platforms
- Understanding of attacker techniques such as credential phishing, malicious attachments, malicious URLs, impersonation, and account compromise
- Strong analytical, troubleshooting, documentation, and communication skills
- Ability to independently investigate moderately complex incidents and escalate high-risk or advanced threats appropriately
Technologies
- Microsoft 365, Microsoft Exchange, Exchange Online
- Exchange Online Protection (EOP), Defender for O365, Microsoft Defender for Office 365
- EasyDMARC, Abnormal Security
- SPF, DKIM, DMARC, SMTP, DNS
- PowerShell, PowerShell for Exchange Online administration, investigation, or automation
- Microsoft Purview, Microsoft Sentinel, Microsoft Defender for Endpoint
- Proofpoint, Mimecast, Cisco Secure Email
- PowerShell / Security Automation
Benefits
- 401k plan with employer match
- Flexible paid time off
- Holidays
- Parental leaves
- Life and disability insurance
- Health benefits including medical, dental, vision, and prescription drug coverage
Preferred Qualifications
- Experience with Microsoft Defender for Office 365, including Safe Links, Safe Attachments, Threat Explorer, and automated investigation and response
- Experience using Microsoft Purview, Microsoft Sentinel, or the Microsoft Defender security ecosystem
- Experience with PowerShell for Exchange Online administration, investigation, or automation
- Familiarity with other Microsoft tools; support administration, monitoring, and policy tuning of EDR/XDR platforms such as Defender for Endpoint and Purview
- Experience investigating compromised Microsoft 365 accounts and malicious inbox or forwarding rules
- Knowledge of email security gateways or platforms such as Proofpoint, Mimecast, Cisco Secure Email, Abnormal Security, or similar technologies
- Familiarity with threat intelligence concepts, indicators of compromise (IOCs), and attacker TTPs
- Knowledge of AI/ML security concepts including data leakage, model abuse, identity and access controls, secure integrations, and protection of sensitive data within AI-enabled systems
Location and Work Flexibility
- Hybrid role based in Morristown, NJ
- Zelis is headquartered in the U.S., with multiple locations across the country and in Hyderabad, India
- All employee work locations are based on the needs of the position and are determined by Leadership
- In-office work and activities vary based on work and team objectives in accordance with Company policies
- Candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed
- Hybrid approach is flexible, with in-office presence guided by team and business needs rather than a fixed weekly schedule
Compensation
- Base salary range: USD 135,200 - 185,900 per year
Accessibility Support
Email [email protected] for reasonable accommodation with any part of the application and/or interview process.