Application Security Engineer — Secure SDLC Champion

Conagra Brands

Omaha (NE)

Hybrid

USD 74,000 - 109,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) match
Stock purchase plan
Tuition reimbursement
Career development
Paid time off
Parental leave
Flexible work schedules
Volunteer opportunities

Job summary

Conagra Brands is seeking an Application Security SME to design, implement, and maintain secure applications across the organization. You will embed security into the software development lifecycle, reduce risk, and advance the AppSec program through collaboration with development, platform, and cybersecurity teams.

You will lead secure coding practices, threat modeling, and vulnerability remediation across web, mobile, and API workloads, while supporting incident response and tool pilots.

Qualifications

  • Bachelor’s degree in CS/InfoSec/Software Eng or equivalent.
  • 3+ years IT/software eng experience with at least 2 years in app security.
  • Hands-on with SAST, DAST, and SCA tools.
  • Knowledge of OWASP Top 10 and ASVS.
  • Experience reviewing code in Java, C#, Python, JavaScript, or TypeScript.
  • Familiarity with Azure DevOps, GitHub Actions or Jenkins.
  • Knowledge of common vulnerabilities and remediation.
  • Experience with NIST CSF, NIST 800-53, CVSS, ISO 27001, ITIL.
  • Cross-functional collaboration.
  • Strong communication skills to explain technical topics to varied audiences.
  • Certifications such as CISSP, GWAPT, OSCP, CSSLP, CEH are a plus.
  • Experience with API security, containers/Kubernetes, IaC scanning, pentesting, bug bounty, CTF, or coordinated disclosure preferred.
  • Willingness to travel up to 10%.

Responsibilities

  • Integrate SAST/DAST/SCA tools within CI/CD pipelines.
  • Perform threat modeling and secure design reviews for new apps, features, services and APIs.
  • Triage and drive remediation of application vulnerabilities while monitoring SLAs and metrics.
  • Coordinate secure code reviews and app/API penetration testing for high-risk systems.
  • Manage open-source dependency risks and SBOM initiatives.
  • Define, promote, and support secure coding standards and developer education.
  • Partner with cloud/platform teams to secure web, mobile, API, containers, and cloud-native apps.
  • Support security incident response activities for application-layer threats and remediation.
  • Evaluate, pilot, and prove concepts for application security tools and technologies.
  • Apply AS requirements to enterprise releases while escalating risks when appropriate.
  • Support risk assessments and conformance with frameworks like OWASP ASVS and NIST.

Skills

Application security
Vulnerability management
Threat modeling
Secure coding
Cross-functional collaboration
Communication

Education

Bachelor's degree in Computer Science / Information Security / Software Engineering

Tools

SAST tools
DAST tools
SCA tools
Secrets scanning tools
Azure DevOps
GitHub Actions
Jenkins
Kubernetes
IaC scanning tools
Penetration testing tools

Job description

Conagra Brands is seeking an Application Security SME to design, implement, and maintain secure applications across the organization. You will embed security into the software development lifecycle, reduce risk, and advance the AppSec program through collaboration with development, platform, and cybersecurity teams.

You will lead secure coding practices, threat modeling, and vulnerability remediation across web, mobile, and API workloads, while supporting incident response and tool pilots.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AppSec Engineer: Secure SDLC & Vulnerability Remediation
AppSec Engineer: Secure SDLC & Vulnerability Remediation

Yum! Brands • Louisville (KY)

On-site
USD 107,000 - 147,000
Application Security Engineer: DevSecOps & SDLC Expert
Application Security Engineer: DevSecOps & SDLC Expert

Ascensus • New Jersey

On-site
USD 120,000 - 170,000
Senior App Security Engineer - DevSecOps & Secure SDLC
Senior App Security Engineer - DevSecOps & Secure SDLC

Ascensus • Dresher

On-site
USD 120,000 - 170,000
Tuition reimbursement
Paid time off
Medical benefits
+2
Application Security Engineer — Hybrid, SDLC & CI/CD Focus
Application Security Engineer — Hybrid, SDLC & CI/CD Focus

Vanguard • Charlotte (NC)

Hybrid
USD 110,000 - 160,000
Senior App Sec Engineer: Lead Secure SDLC (Remote)
Senior App Sec Engineer: Lead Secure SDLC (Remote)

platacard • United States

Hybrid
USD 120,000 - 180,000
Relocation with visa support
Flexible work office or remote
Healthcare coverage
+3
Senior AppSec & DevSecOps Leader
Senior AppSec & DevSecOps Leader

Credo • San Jose (CA)

On-site
USD 100,000 - 150,000
Discretionary bonus
Equity
Medical benefits
Application Security Engineer - DevSecOps Champion
Application Security Engineer - DevSecOps Champion

Ascensus • Town of Florida (NY)

On-site
USD 120,000 - 150,000
Application Security Engineer - Secure SDLC & Apps
Application Security Engineer - Secure SDLC & Apps

Wawa, Inc. • Media

On-site
USD 110,000 - 160,000
Staff Application Security Engineer: Scale Secure SDLC
Staff Application Security Engineer: Scale Secure SDLC

BetterCloud • Buffalo (NY)

On-site
USD 110,000 - 170,000
Senior Application Security Engineer
Senior Application Security Engineer

High Trail • Arlington (VA)

On-site
USD 140,000 - 190,000