We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Vulnerability Management Specialist

Zelis Healthcare, LLC
401(k), remote work
United States, New Jersey, Morristown
340 Mount Kemble Avenue (Show on map)
Mar 28, 2025

At Zelis, we Get Stuff Done. So, let's get to it!

A Little About Us

Zelis is modernizing the healthcare financial experience for all by providing a connected platform that bridges the gaps and aligns interests across payers, providers, and healthcare consumers. This platform serves more than 750 payers, including the top 5 national health plans, BCBS insurers, regional health plans, TPAs and self-insured employers, and millions of healthcare providers and consumers. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts-driving real, measurable results for clients.

A Little About You

You bring a unique blend of personality and professional expertise to your work, inspiring others with your passion and dedication. Your career is a testament to your diverse experiences, community involvement, and the valuable lessons you've learned along the way. You are more than just your resume; you are a reflection of your achievements, the knowledge you've gained, and the personal interests that shape who you are.

Zelis is seeking a dedicated Vulnerability Management Specialist to serve as the single point of contact for disaster recovery and vulnerability management across the divisional IT teams. This role will manage DR recovery documentation, with responsibility to ensure RTO/RPO objectives, testing, and execution during events, and is also responsible for identifying, tracking, and driving the resolution of vulnerabilities in servers and code while establishing and promoting best practices in build and deployment processes.

Additionally, the Vulnerability Management Specialist will ensure that all efforts align with compliance frameworks such as SOC II, PCI DSS, and HIPAA. This critical role will enhance the organization's security posture, reduce risks, and maintain compliance with industry standards.

What You'll Do:

Vulnerability Management:

  • Act as the primary liaison between enterprise IT and divisional IT teams for all disaster recovery and vulnerability-related efforts.

  • Develop, maintain, and update disaster recovery plans for all critical systems and processes.

  • Own and maintain the centralized repository for tracking known vulnerabilities, ensuring visibility and accountability across teams.

  • Develop and manage roadmaps to reduce active vulnerabilities and implement preventative measures.

Testing and Validation:

  • Plan and execute regular DR tests and simulations, ensuring the effectiveness of recovery plans.

  • Identify gaps during testing and implement improvements to strengthen DR readiness.

Compliance and Risk Mitigation:

  • Ensure vulnerability management processes and practices align with SOC II, PCI DSS, and HIPAA requirements.

  • Collaborate with compliance and audit teams to address vulnerabilities identified during assessments or audits.

  • Support external and internal audits by providing evidence of vulnerability remediation and secure practices.

  • Develop and enforce policies and procedures to meet regulatory requirements in server configuration, application development, and data protection.

Prevention and Best Practices:

  • Collaborate with enterprise and divisional teams to establish and enforce best practices in server configuration, code development, and deployment tools.

  • Drive adoption of secure build and deployment processes to prevent vulnerabilities from being introduced into production environments.

  • Implement mechanisms to measure and report on vulnerability aging and "live days," highlighting trends and areas for improvement.

Collaboration and Leadership:

  • Partner with IT, infrastructure, and application teams to align recovery strategies with business objectives.

  • Partner with security, compliance, infrastructure, and development teams to align vulnerability management strategies with organizational goals.

  • Provide regular updates to leadership on vulnerability status, compliance posture, reduction progress, and aging metrics.

  • Champion a culture of security awareness and continuous improvement throughout the organization.

Incident Response:

  • Serve as the primary point of contact during DR incidents, coordinating recovery efforts and communications.

  • Work with internal and external teams to ensure swift resolution of issues and minimal downtime.

Monitoring, Reporting, and Documentation:

  • Develop dashboards and reports to track and communicate the status of vulnerabilities, aging metrics, and risk reduction outcomes.

  • Document processes and workflows to ensure alignment with SOC II, PCI DSS, and HIPAA standards.

  • Analyze trends and provide actionable insights to improve security posture and maintain compliance.

What You'll Bring to Zelis:

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field (or equivalent experience).

  • 3+ years of experience in vulnerability management, cybersecurity, or IT operations.

  • 3+ years of experience in IT operations, disaster recovery, or business continuity roles helpful.

  • Hands-on experience developing and executing disaster recovery plans.

  • Proven track record of reducing vulnerabilities and implementing preventative practices in complex IT environments.

  • Experience working with compliance frameworks such as SOC II, PCI DSS, HIPAA, or ISO 27001.

  • Strong understanding of vulnerability scanning tools (e.g., Nessus, Qualys, or similar) and patch management processes.

  • Knowledge of secure software development practices and deployment pipelines (e.g., CI/CD).

  • Familiarity with enterprise IT infrastructure, including servers, networks, and cloud environments.

  • Strong understanding of regulatory requirements for data protection and security standards.

  • Excellent communication and interpersonal skills, with the ability to work collaboratively across teams and levels.

  • Strong analytical and problem-solving abilities, with attention to detail.

  • Ability to manage multiple priorities and deliver results in a fast-paced environment.

  • Certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Global Information Assurance Certification (GIAC).

  • Hands-on experience supporting audits for SOC II, PCI DSS, or HIPAA compliance.

  • Familiarity with frameworks such as NIST Cybersecurity Framework or ISO 27001.

Location and Workplace Flexibility
We have offices in Atlanta GA, Boston MA, Morristown NJ, Plano TX, St. Louis MO, St. Petersburg FL, and Hyderabad, India. We foster a hybrid and remote friendly culture, and all our employee's work locations are based on the needs of the position and determined by the Leadership team. In-office work and activities, if applicable, vary based on the work and team objectives in accordance with Company policies.

Our Values and Culture

We are always thinking about life beyond the laptop and how we can drive positive change for our clients, our associates, and our communities. Our IMPACT Value Behaviors are how we elevate that thinking and turn it into action:

  • Drive Innovation

  • Embrace a Growth Mindset

  • Put People First

  • Act With Agility

  • Champion Collaboration

  • Build Trust

We look at the big picture when it comes to our associates and our culture. We work to effectively build a thriving, exciting experience for our associates. We leverage these values to continuously evolve an award-winning culture that has a longevity greater than the novelty of a ping pong table in the break room. Our idea of a great workplace is where we can show up as our authentic selves-which is the best way to bring together extraordinary talented people who feel empowered to make a positive IMPACT.

A Lot of Respect

This is a collaborative organization where everyone is on your team. Each person-from the newest intern to the CEO-is in their position because they are an expert, and they view you with the same lens. No matter who you are, where you sit in the organization, or the span of your tenure, everyone at Zelis is treated with respect.

We respect your time (so much so that we aren't asking you to write a cover letter). We make sure you have time to focus by offering Meeting-Free Wednesdays as well as time for you with Zelis Cares Fridays early dismissal.

We respect and prioritize work-life balance. With flexible PTO, a hybrid/remote work environment, and a culture that encourages disconnecting after hours, we ensure you have the time and space to manage life's surprises and fully engage outside of work. Working "9 to 5" isn't just a hit song; we respect business hours and promote wellness offerings to keep you at your best, both on and off the clock.

We respect diverse opinions. There are always seats at the table, and we're eager to add more chairs. We continue to build our Diversity, Equity, and Inclusion initiatives including training, guest speakers, associate-led Business Resource Groups, in-office DEI events, and more.

We respect that everyone has different needs. Zelis has built and continues to add to our benefits offerings by including medical, dental, 401k, fertility and family building, education assistance, pet insurance, menopause and midlife care, and more.

We respect YOU. As an Equal Opportunity Employer, we believe that everyone's voice has a place in the chorus. We encourage members of traditionally underrepresented communities to apply.

Equal Employment Opportunity
Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

We welcome applicants from all backgrounds and encourage you to apply even if you don't meet 100% of the qualifications for the role. We believe in the value of diverse perspectives and experiences and are committed to building an inclusive workplace for all.

Accessibility Support
We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability or a disabled veteran and require a reasonable accommodation with any part of the application and/or interview process, please email TalentAcquisition@zelis.com.

Disclaimer

We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law.

The above statements are intended to describe the general nature and level of work being performed by people assigned to this classification. They are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of personnel so classified. All personnel may be required to perform duties outside of their normal responsibilities, duties, and skills from time to time.

Applied = 0

(web-6468d597d4-98p82)