Job Closed
This listing is no longer active.
As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community!
Senior IT Application Engineer
Location
United States
Posted
59 days ago
Salary
$120K - $191K / year
Seniority
Senior
Job Description
Senior IT Application Engineer
Meijer
As a family company, we serve people and communities. When you work at Meijer, you’re provided with career and community opportunities centered around leadership, personal growth and development. Consider joining our family – take care of your career and your community! Grab the Good Stuff: - Weekly pay - Team member discount - 401(k) with company contributions - Paid parental leave - Paid education assistance - Development programs for advancement and career growth - Medical/dental/vision - And more! Please review the job profile below and apply today! The Senior IT Application Security Engineer is recognized as a subject matter expert in secure application design, threat modeling, and secure coding practices. You will assist software development teams in designing, creating, and implementing secure solutions by ensuring that security checks are followed throughout each phase of the software development life cycle (SDLC). You are expected to take a proactive leadership role in driving application security initiatives and define, communicate, and enforce application security standards across the organization. You will lead opportunities to enhance security processes and mentor team members by sharing your expertise. You will also identify security knowledge gaps and present training to IT stakeholders. Additionally, you will champion efforts to advance the maturity of the application security program to help foster a culture of continuous improvement. What You'll be Doing: - Develop and provide presentations on application security topics to both technical and non-technical audiences. - Advise executive leadership on current and evolving threats to enable risk-informed decisions. - Mentor members of the information security team on matters of application security. - Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams. - Provide tailored remediation guidance to software developers to address security findings. - Provide architectural and security guidance for third-party platforms and services as they integrate into Meijer environments and/or code. - Review the security of third-party/open-source software used by Meijer. - Provide risk-based analysis of security posture to drive business decisions. - Foster relationships with key business partners to create a culture of security and achieve prioritization of security initiatives. - Develop internal security tooling for identifying or remediating security risks. - Assist/lead on matters of application security in the event of an incident. - This job profile is not meant to be all inclusive of the responsibilities of this position. May perform other duties as assigned or required. What You Bring with You (Qualifications): - Bachelor’s degree or above in Computer Science, Information Security, or related field. - At least four years of professional experience, with at least two years in a security field and at least one year with direct experience writing code. - Familiar with object-oriented programming and have written code in one or more programming languages (e.g. C#, Java, C++). - Agile/Scrum, SAFe, or Lean certification preferred. - Familiarity with secure coding best practices such as the OWASP Top 10. - Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices). - Foundational knowledge of security practices in several applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance. - Knowledge of relevant technology, tools, databases, and development techniques. - Strong focus on team dynamics and interpersonal relationships. - Strong sense of task ownership with consistent follow-through. - Ability to anticipate risks and devise solutions with limited information or context. - Excellent project management, organization, and team collaboration skills. - Curiosity to learn. - Capable of defining and measuring key performance indicators. - Able to work cross-functionally with IT and business partners across all areas of Meijer and vendor partners. - Adaptive, flexible, and responsive to challenges. - Awareness of how security controls influence both internal stakeholders and Meijer customers. - SANS/GIAC, CompTIA, ISC2 (e.g. CISSP) or other applicable industry certifications preferred. We are committed to offering competitive pay that reflects market standards and ensures consistency within our organization. The pay range for this position is listed below. $120,750.00 - $191,000.00 This pay range represents the minimum and maximum base pay for the position, which is determined by factors such as market data, the qualifications required, the level of responsibilities associated with the role and other roles at this same level. Your specific pay rate within this range will be based on your experience, qualifications, and skills compared to the internal team you’ll be joining. We offer a comprehensive benefits package that includes medical, dental, vision, life insurance, a 401(k) plan with employer match, disability leave, and paid time off (PTO). In addition to these core benefits, we are committed to supporting your overall well-being and career growth. Our offerings include a variety of programs designed to support your personal and professional development, such as paid parental leave, paid education assistance (including free education), a childcare subsidy and more. We are dedicated to creating a work environment that promotes work-life balance, long-term health and financial security, and continuous professional development The interview process is intended to learn more about your personal skills and experience. To this end, we ask that candidates do not use AI tools during the hiring process. Please note: - Cameras must be turned on during all virtual interviews. - AI tools may not be used during any part of the interview process.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cloud - Lead Security Engineer
Ministère des armées. Liberté, égalité, fraternité.Personnes à contacter : dcsca-arcueil.gestionnaire.fct@intradef.gouv.fr stephanie.porcher@intradef.gouv.fr
Role Description Ce recrutement s'inscrit dans le projet d'infrastructure cloud pour le numérique de défense — conçue, intégrée et opérée par nos équipes — en se dotant d'une stack maîtrisée, sécurisée, performante et résiliente, déployée sur l'ensemble du territoire national. Vos missions seront les suivantes : - Concevoir, challenger, déployer et opérer l'architecture IAM (infrastructure et utilisateurs) ; - Implémenter et maintenir les mécanismes d'autorisation inter-domaines et multi-tenants ; - Opérer la gestion des secrets et certificats à l'échelle de la plateforme ; - Implémenter les durcissements de sécurité à tous les niveaux de manière pragmatique : matériel (secure boot, firmware, TPM), système (SELinux/AppArmor, isolation), réseaux (µsegmentation) en collaboration avec les équipes ; - Intégrer les dispositifs LID : déployer les sondes, configurer les points de collecte ; - En partenariat avec le RSSI projet, porter le dialogue avec la chaîne SSI et défendre les choix d’architecture ; - Participer à la gestion de crise ; - Rédaction des procédures d’exploitation et de la documentation technique ; - Encadrer techniquement les ingénieurs sur les questions SSI ; contribuer au recrutement et à la montée en compétences. Qualifications - 8+ ans d'expérience en sécurité des systèmes d'information et sécurité cloud - Conception et déploiement d'architectures IAM (Identity and Access Management) à l'échelle - Durcissement de plateformes cloud sur l'ensemble de la stack (matériel, système, réseau) - Gestion de secrets et PKI dans des environnements de production critiques - Mise en œuvre de solutions de sécurité dans des contextes multi-tenants et multi-domaines - Approche DevSecOps : intégration de la sécurité dans les chaînes CI/CD Requirements - IAM : conception d'architectures d'authentification et d'autorisation (OIDC, SAML, RBAC/ABAC) - PKI et gestion de secrets : déploiement et opération (HashiCorp Vault, cert-manager, ou équivalents) - Hardening système : SELinux/AppArmor, isolation par namespaces, secure boot, TPM - Sécurité réseau : microsegmentation, Zero Trust, politiques réseau Kubernetes - Détection d'intrusion : déploiement de sondes LID, configuration de points de collecte - Kubernetes : sécurisation de clusters (Pod Security Standards, Network Policies, admission controllers) - Infrastructure as Code : Terraform, Ansible, GitOps Benefits - Rigoureux : Capacité à concevoir et maintenir des infrastructures critiques avec une attention méticuleuse aux détails, particulièrement dans les aspects de sécurité et de reproductibilité - Innovant : Capacité à proposer des solutions techniques avancées et à implémenter des bonnes pratiques - Ancré dans une culture d'analyse factuelle et d'amélioration continue - Pédagogue : Capacité à transmettre votre expertise, encadrer techniquement et défendre vos choix face à des interlocuteurs techniques ou institutionnels Company Description - Atouts appréciés : - Expérience avec des environnements air-gapped - Connaissance des référentiels SSI : ANSSI, IGI 1300, SecNumCloud - Contributions open source. Éléments de candidature Documents à transmettre : Pour postuler à cette offre, l'envoi du CV et d'une lettre de motivation est obligatoire. Personnes à contacter - dc-dirisi-sdorh-rrh-gpc-gpec.mobilite.fct@intradef.gouv.fr - laurent.prosperi@intradef.gouv.fr
Senior Security Engineer
Lightning LabsA new media product development consultancy founded in 2011, Lightning Labs scales blockchains and leverages cryptography and smart contracts to offer low-cost,
• Designing and deploying active fuzzing, black+white box testing and penetration testing infrastructure for open source and production systems • Performing security audits and review of both internal production systems as well as open source software which interacts with Bitcoin+Lightning in a security critical manner • Provide mentorship and guidance to level up your teammates • Creating global security policy, standards, guidelines, and procedures to ensure ongoing maintenance of security • Overseeing security aspects of software release processes and infrastructure • Determining security team requirements for future growth • Developing and ensuring responsiveness of security incident management processes • Performing risk management assessments
Security Engineer – Cloud Security Engineer, FedRAMP Control Implementation & Automation Support
C2 Labs, Inc.Your IT transformation partner specializing in full stack development, automation/DevOps, and cybersecurity compliance
• Implement and tune cloud security controls (IAM, logging, vulnerability management, configuration baselines, incident readiness). • Configure security tooling and integrations to produce repeatable evidence for authorization and ConMon. • Support remediation and hardening workstreams, including vulnerability scan remediation support. • Help automate evidence exports/reporting inputs where feasible and keep operations sustainable post-authorization.
Senior Security Engineer
Stellus RxTrusted, pharmacist-led health support in every moment that matters.
• Leverage AI-powered security tooling to continuously monitor for threats, anomalies, and policy violations across cloud and application environments • Respond to and resolve or escalate security incidents; use AI-assisted analysis to accelerate root cause investigation and postmortem documentation • Investigate and resolve security violations by providing postmortem analysis that illuminates causes, solutions, and AI-informed preventative measures • Use AI tools to model attack scenarios and prioritize remediation efforts based on risk • Assess, design, implement, automate, and document security solutions for public and private cloud environments • Implement "security as code" using cloud services and CI/CD components • Develop baseline cloud, container, and application security standards and integrate them into CI/CD pipelines • Work with diverse technical and business stakeholders on security best practices • Document security systems, procedures, and controls; drive compliance through adherence to information security policies


