Job Closed
This listing is no longer active.
As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community!
Application Security Engineer
Location
United States
Posted
82 days ago
Salary
$100K - $156K / year
Seniority
Mid Level
Job Description
Application Security Engineer
Meijer
As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community! Meijer Rewards - Weekly pay - Scheduling flexibility - Paid parental leave - Paid education assistance - Team member discount - Development programs for advancement and career growth Please review the job profile below and apply today! The IT Application Security Engineer is adept at secure application design, threat modeling, and secure coding practices. The position assists software development teams in designing, creating, and implementing secure solutions by ensuring security checks are followed at each step of the software development life cycle (SDLC). This role will define and communicate application security standards to relevant stakeholders. Additionally, this role will identify security knowledge gaps and provide curated security training content to address these gaps. What You'll be Doing: - Develop and provide presentations on application security topics to both technical and non-technical audiences, including leadership. - Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams. - Provide tailored remediation guidance to software developers to address security findings. - Provide architectural and security guidance for third-party platforms and services as they integrate into Meijer environments and/or code. - Review the security of third-party/open-source software used by Meijer. - Provide risk-based analysis of security posture to drive business decisions. - Foster relationships with key business partners to create a culture of security and achieve prioritization of security initiatives. - This job profile is not meant to be all inclusive of the responsibilities of this position. May perform other duties as assigned or required. What You Bring with You (Qualifications): - Bachelor’s degree or above in Computer Science, Information Security, or related field. - At least 2-3 years of professional experience, including a minimum of one year writing code, with relevant experience in a security-related field preferred. - Familiar with object-oriented programming and have written code in at least one programming language (e.g. C#, Java, C++). - Familiarity with secure coding best practices such as the OWASP Top 10. - Agile/Scrum, SAFe, or Lean certification preferred. - Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices). - Foundational knowledge of security practices in one or more applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance. - Knowledge of relevant technology, tools, databases, and development techniques. - Strong focus on team dynamics and interpersonal relationships. - Strong sense of task ownership with consistent follow-through. - Ability to anticipate risks and devise solutions with limited information or context. - Excellent project management, organization, and team collaboration skills. - Curiosity to learn. - Capable of defining and measuring key performance indicators. - Able to work cross-functionally with IT and business partners across all areas of Meijer and vendor partners. - Adaptive, flexible, and responsive to challenges. - Awareness of how security controls influence both internal stakeholders and Meijer customers. - SANS/GIAC, CompTIA, ISC2 (CISSP) or other applicable industry certifications are a plus. We are committed to offering competitive pay that reflects market standards and ensures consistency within our organization. The pay range for this position is listed below. $100,000.00 - $156,000.00 This pay range represents the minimum and maximum base pay for the position, which is determined by factors such as market data, the qualifications required, the level of responsibilities associated with the role and other roles at this same level. Your specific pay rate within this range will be based on your experience, qualifications, and skills compared to the internal team you’ll be joining. We offer a comprehensive benefits package that includes medical, dental, vision, life insurance, a 401(k) plan with employer match, disability leave, and paid time off (PTO). In addition to these core benefits, we are committed to supporting your overall well-being and career growth. Our offerings include a variety of programs designed to support your personal and professional development, such as paid parental leave, paid education assistance (including free education), a childcare subsidy and more. We are dedicated to creating a work environment that promotes work-life balance, long-term health and financial security, and continuous professional development
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Associate Consultant, Offensive Security
KrollKroll Inc. is a risk consulting firm that provides proprietary data and technology to help its clients manage growth, risk, and governance, and therefore, manage complex demands. E
• Execute offensive security and consultative engagements for our clients’ applications, cloud assets, and infrastructure • Author deliverables such as vulnerability reports and executive reports • Engage with our clients to understand their requirements, update them on project status, answer their queries, and present your findings and recommendations • Keep your skills and knowledge up to date with the latest trends in cybersecurity and emerging technology • Willingness to work in EST Time zone
Senior Cyber Security Incident Responder
SwisscomTop quality I Ground-breaking innovations I Connected to people and the environment
• Lead and manage incident response operations related to cyber attacks on the infrastructures of Swisscom B2B customers • Perform host forensics, network forensics, log analysis, and malware scans • Collect and analyze attackers' tactics, techniques, and procedures (TTPs) as well as indicators of compromise (IOCs) • Conduct threat hunting and threat intelligence activities to proactively protect the infrastructures of Swisscom B2B customers
• Lead your team's development to sell multi-year engagements • Build a large sales pipeline to support revenue growth • Develop and deliver accurate sales forecasts • Ensure client engagement strategies align with Optiv's mission and values • Establish and maintain collaborative relationships with technology partners • Work with various organizations to optimize revenue growth.
• Perform security and privacy risk and impact analysis for system additions (ex. new hardware, software, or services), significant changes to systems, and network- and system-level requests for control changes and exceptions. • Support cybersecurity policy and procedure development, risk awareness, and control implementation training initiatives by creating and delivering online and in-person content. • Support continuous assessment and monitoring of NLR's security and privacy posture by observing and reporting trends in risks assessed or observed among NLR'S information systems. • Provide NLR colleagues with technical direction and coaching to remedy security and privacy control weaknesses. • Analyze, prioritize, and report on the results of control weakness remediation. • Champion cybersecurity and privacy best practices to technical and non-technical audiences. • Participate in projects that improve the effectiveness and efficiency of NLR's cybersecurity program, including but not limited to workflow improvements, management tool enhancements, program or NLR strategic initiatives, and user awareness training.



