Application Security Engineer: Vulnerability & DevSecOps

Core-Mark

United States

Remote

USD 110,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Performance Food Group is seeking an Application Security & Vulnerability Engineer to lead the secure development lifecycle across the company’s software landscape. The role partners with Infrastructure and Development teams to implement scanning, remediation coordination, reporting, and secure coding practices in the CI/CD pipeline.

The candidate will support incident response, threat intelligence, and compliance initiatives as part of the broader Information Security Program, driving secure

Qualifications

  • Associate's degree in Information Technology, Computer Science, Cybersecurity or related field or equivalent 3-5 years direct application security experience
  • 3-5 years of related work experience in information security or application security
  • Demonstrate working knowledge of programming and scripting languages (e.g., RPG, C#, Lansa, and React) and Infrastructure as Code (IaC) concepts to identify, assess, and help remediate application and code-based security vulnerabilities.
  • Hands-on or conceptual experience with application development and/or security tools: static/dynamic code scanning (SAST/DAST), software composition analysis (SCA), and dependency scanning
  • Understanding of secure SDLC practices and how to integrate security into CI/CD pipelines
  • Conceptual understanding of vulnerability scanning solutions, such Tenable/Nessus and code scanning applications
  • Familiarity with web application security fundamentals, including common application vulnerabilities, authentication and authorization concepts, API security basics, and secure coding principles.
  • Knowledge of cybersecurity concepts and countermeasures, including OWASP Top 10, identity and access management, and common attack techniques (IP spoofing, SYN flood, DDoS)
  • Ability to help define and document repeatable application security processes, including intake, testing, remediation tracking, exception handling, and reporting.
  • Ability to analyze large, complex data sets; proficiency with Excel, Power BI, Cognos or other data analytic tools
  • Ability to clearly communicate application security findings, remediation guidance, and risk context to technical teams and business stakeholders, with strong written and verbal communication skills
  • Strong analytical and problem-solving skills

Responsibilities

  • Partner with application development and business teams to build and mature PFG's Application Security program and secure coding practices
  • Conduct application security assessments using code scanning (SAST/DAST), dependency/composition analysis (SCA), and security testing tools; coordinate remediation through closure with application owners
  • Evaluate applications and CI/CD pipelines to integrate security controls, automate vulnerability detection, and improve remediation processes and timelines
  • Advise development teams on secure coding practices and help embed security requirements earlier in the development lifecycle
  • Develop developer security training content and drive adoption of secure development practices across applicable functional areas.
  • Track and report on application vulnerability trends, remediation SLAs, and program maturity to IT leadership and application owners
  • Identify and evaluate security risks within application development and deployment processes, helping promote secure access controls and governance practices.
  • Support enterprise Vulnerability Management program, including scanning, prioritization, remediation tracking, and reporting
  • Monitor threat intelligence feeds for relevant threats and vulnerabilities; work with delivery teams to track, prioritize, and remediate identified gaps
  • Support activities within the Security Incident Response program, Security Education Awareness Program, and other compliance activities as needed
  • Perform other cybersecurity related duties as assigned

Skills

SAST/DAST
SCA
IaC concepts
Secure SDLC
CI/CD security
OWASP Top 10
DevOps/CI/CD integration
Security metrics reporting
Communication with stakeholders

Education

Associate's degree in IT / CS / Cybersecurity
4-6 years direct application security experience

Tools

Tenable/Nessus
Code scanning tools
SAST/DAST tooling

Job description

Performance Food Group is seeking an Application Security & Vulnerability Engineer to lead the secure development lifecycle across the company’s software landscape. The role partners with Infrastructure and Development teams to implement scanning, remediation coordination, reporting, and secure coding practices in the CI/CD pipeline.

The candidate will support incident response, threat intelligence, and compliance initiatives as part of the broader Information Security Program, driving secure

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AppSec & Vulnerability Engineer — Secure DevOps
AppSec & Vulnerability Engineer — Secure DevOps

Performance Food Group (New) • United States

Remote
USD 110,000 - 140,000
Remote Application Security & Vulnerability Engineer
Remote Application Security & Vulnerability Engineer

Performance Food Group • United States

Remote
USD 100,000 - 110,000
Day 1 health benefits
Employee stock purchase plan
401K employer matching
+2
Application Security & Vulnerability Engineer
Application Security & Vulnerability Engineer

Performance Food Group (New) • United States

Remote
USD 110,000 - 140,000
Application Security & Vulnerability Engineer
Application Security & Vulnerability Engineer

Core-Mark • United States

Remote
USD 110,000 - 140,000
Application Security & Vulnerability Engineer
Application Security & Vulnerability Engineer

Performance Food Group • United States

Remote
USD 100,000 - 110,000
Day 1 health benefits
Employee stock purchase plan
401K employer matching
+2
AppSec Engineer: Secure SDLC & Vulnerability Remediation
AppSec Engineer: Secure SDLC & Vulnerability Remediation

Yum! Brands • Louisville (KY)

On-site
USD 107,000 - 147,000
Senior Security Engineer: Secure Cloud & Apps
Senior Security Engineer: Secure Cloud & Apps

Delivery Hero • Town of Greece (NY)

On-site
USD 140,000 - 200,000
Private Medical & Life Insurance
Online mental health platform
Online training platform
+3
Application Security Engineer
Application Security Engineer

BridgeView • New York (NY)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Application Security Analyst I: Secure SDLC & CI/CD
Application Security Analyst I: Secure SDLC & CI/CD

Transaction Network Services (TNS) • Kentucky

On-site
USD 75,000 - 83,000
Medical & dental coverage
Life insurance
Paid holidays and vacations
+1