Security Engineer - Email Security
Data Security
Email Security
Engineer
Enterprise Email Security
Exchange Online Security
Incident Response
Information Security
InfoSec
Investigative Skills
Mail Flow Security
Microsoft 365 Admin
Microsoft 365 Administration
Microsoft 365 Security
Microsoft Defender For Office 365
Microsoft Security
Security
Security Automation
Security Engineer
Security Operations
Job Description
Zelis is seeking a Security Engineer focused on email security to help protect and improve the security, reliability, and resilience of its enterprise email environment. The role centers on detecting and preventing email-based threats, administering email security controls in Microsoft 365, and supporting incident investigation and remediation.
Key Responsibilities
- Conduct in-depth analysis of suspicious messages, including review of email headers, message routing, URLs, attachments, sender reputation, authentication outcomes, and other indicators of compromise.
- Administer and support email security controls within Exchange Online, Defender for O365, EasyDMARC, and Abnormal Security.
- Troubleshoot issues related to email delivery, mail flow, quarantine, filtering, and email security policy behavior.
- Review Exchange message traces and mail-flow logs to assess message disposition and identify delivery or security concerns.
- Configure and maintain mail-flow rules, anti-spam policies, anti-phishing protections, allow/block lists, quarantine policies, and related security controls.
- Support incident containment and remediation activities, including message removal, sender and domain blocking, URL blocking, mailbox remediation, and escalation of compromised accounts.
- Assist with administration and tuning of Microsoft Defender for Office 365 or comparable secure email gateway and email security technologies.
- Analyze and troubleshoot email authentication mechanisms, including SPF, DKIM, and DMARC.
- Identify false positives and false negatives and recommend improvements to email security policies and detection rules.
- Document investigations, findings, remediation actions, and recurring email security issues.
- Create and maintain operational procedures, troubleshooting guides, and knowledge-base documentation.
- Collaborate with SOC, Incident Response, Identity and Access Management, Infrastructure, and Messaging teams during security investigations.
- Support email security metrics, reporting, trend analysis, and continuous improvement efforts.
- Stay current with emerging phishing techniques, business email compromise tactics, attacker infrastructure, and email security best practices.
Required Qualifications
- 5+ years of proven experience designing and implementing enterprise-grade email security guardrails in regulated fintech or healthcare environments, with a strong security-first mindset and demonstrated expertise in phishing and BEC prevention, email authentication, data loss prevention, policy enforcement, monitoring, and incident response.
- 3+ years of hands-on experience with Microsoft Exchange, Exchange Online, or Microsoft 365 messaging environments.
- Working knowledge of Microsoft Exchange mail flow, connectors, transport/mail-flow rules, and message tracking and tracing.
- Experience investigating phishing, spam, malware, spoofing, and business email compromise incidents.
- Strong understanding of email protocols and technologies, including SMTP, DNS, SPF, DKIM, and DMARC.
- Experience analyzing email headers to determine message origin, routing, authentication results, and possible indicators of malicious activity.
- Familiarity with Microsoft Defender for Office 365, Exchange Online Protection (EOP), or similar enterprise email security platforms.
- Understanding of common attacker techniques involving credential phishing, malicious attachments, malicious URLs, impersonation, and account compromise.
- Strong analytical, troubleshooting, documentation, and communication skills.
- Ability to independently investigate moderately complex incidents and escalate high-risk or advanced threats appropriately.
Technologies
- Microsoft 365, Microsoft Exchange, Exchange Online, Exchange Online Protection (EOP)
- Defender for O365, Microsoft Defender for Office 365
- EasyDMARC, Abnormal Security
- SPF, DKIM, DMARC, SMTP, DNS
- PowerShell, PowerShell for Exchange Online administration, investigation, or automation
- Microsoft Purview, Microsoft Sentinel
- Microsoft Defender for Endpoint
- Proofpoint, Mimecast, Cisco Secure Email
- PowerShell / Security Automation
Benefits
- 401k plan with employer match
- Flexible paid time off
- Holidays
- Parental leaves
- Life and disability insurance
- Health benefits including medical, dental, vision, and prescription drug coverage
Preferred Qualifications
- Experience with Microsoft Defender for Office 365, including Safe Links, Safe Attachments, Threat Explorer, automated investigation and response, and related capabilities.
- Experience using Microsoft Purview, Microsoft Sentinel, or the Microsoft Defender security ecosystem.
- Experience with PowerShell for Exchange Online administration, investigation, or automation.
- Familiarity with other Microsoft tools; Defender for Endpoint and Purview included, for administration, monitoring, and policy tuning of EDR/XDR platforms.
- Experience investigating compromised Microsoft 365 accounts and malicious inbox or forwarding rules.
- Knowledge of email security gateways or platforms such as Proofpoint, Mimecast, Cisco Secure Email, Abnormal Security, or similar technologies.
- Familiarity with threat intelligence concepts, indicators of compromise (IOCs), and attacker tactics, techniques, and procedures (TTPs).
- Knowledge of AI/ML security concepts and emerging threats, data leakage, model abuse, identity and access controls, secure integrations, and protection of sensitive data within AI-enabled systems.
Location and Workplace Flexibility
- Morristown, NJ (hybrid).
- Zelis is headquartered in the U.S. with multiple locations across the country and in Hyderabad, India.
- Work location is based on the needs of the position and determined by Leadership.
- In-office work and activities vary based on team and business objectives in line with Company policies.
- Candidates within approximately 50 miles of a U.S. office are generally preferred to support collaboration when needed.
- Hybrid approach is flexible; in-office presence is guided by team and business needs rather than a fixed weekly schedule.
Base Salary Range
$135,200.00 - $185,900.00 per year.
Accessibility Support
For reasonable accommodation with any part of the application and/or interview process, email [email protected].