Application Security & Vulnerability Engineer

Performance Food Group

United States

Remote

USD 100,000 - 110,000

Full time

44 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Day 1 health benefits
Employee stock purchase plan
401K employer matching
Education assistance
Paid time off

Job summary

Performance Food Group is seeking an Application Security & Vulnerability Engineer to lead the secure development and vulnerability management efforts across the organization. You will partner with Infrastructure and Development teams to implement scanning, remediation, reporting, and secure development practices throughout the SDLC.

This is a fully remote opportunity! You will support incident response, threat intelligence, and compliance activities as part of the broader Information Security

Qualifications

  • Associate's degree in IT, CS, Cybersecurity or related field, or equivalent 3–5 years of direct application security experience.
  • 3–5 years of related work experience in information security or application security.
  • Familiarity with IaC concepts and secure SDLC integration into CI/CD pipelines.
  • Knowledge of OWASP Top 10 and common web app vulnerabilities.

Responsibilities

  • Build and mature the Application Security program and secure coding practices across development teams.
  • Conduct security assessments using SAST/DAST, SCA, and dependency scanning; coordinate remediation.
  • Integrate security controls into CI/CD pipelines and automate vulnerability detection.
  • Develop developer security training content and promote secure development practices.
  • Track vulnerability trends and remediation SLAs; report to IT leadership.

Skills

Application security
Secure coding practices
Communication skills

Education

Associate's degree in IT/CS/Cybersecurity

Tools

SAST/DAST
SCA
IaC security tooling

Job description

  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
We Deliver the Goods
  • Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
  • Growth opportunities performing essential work to support America’s food distribution system
  • Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary

Performance Food Group is looking for a talented Application Security & Vulnerability Engineer to lead efforts in securing PFG's application landscape and enterprise vulnerability management program. This role partners closely with Infrastructure and Application Development teams to establish the foundational application security program by implementing scanning processes, coordinating remediation with application teams, building reporting and metrics, and supporting secure development practices across the software development lifecycle throughout the CI/CD pipeline. The candidate will also support the broader Information Security Program, including incident response, threat intelligence, and compliance initiatives.

This is a fully remote opportunity!

Position Responsibilities
Application Security (Primary Focus)
  • Partner with application development and business teams to build and mature PFG's Application Security program and secure coding practices
  • Conduct application security assessments using code scanning (SAST/DAST), dependency/composition analysis (SCA), and security testing tools; coordinate remediation through closure with application owners
  • Evaluate applications and CI/CD pipelines to integrate security controls, automate vulnerability detection, and improve remediation processes and timelines
  • Advise development teams on secure coding practices and help embed security requirements earlier in the development lifecycle
  • Develop developer security training content and drive adoption of secure development practices across applicable functional areas.
  • Track and report on application vulnerability trends, remediation SLAs, and program maturity to IT leadership and application owners
  • Identify and evaluate security risks within application development and deployment processes, helping promote secure access controls and governance practices.
Vulnerability & Threat Management
  • Support enterprise Vulnerability Management program, including scanning, prioritization, remediation tracking, and reporting
  • Monitor threat intelligence feeds (SANS, software manufacturer alerts, industry news) for relevant threats and vulnerabilities; work with delivery teams to track, prioritize, and remediate identified gaps
  • Support activities within the Security Incident Response program, Security Education Awareness Program, and other compliance activities as needed
  • Perform other cybersecurity related duties as assigned
Required Qualifications
  • Associate's degree in Information Technology, Computer Science, Cybersecurity or related field or equivalent 3–5 years direct application security experience
  • 3-5 years of related work experience in information security or application security
  • Demonstrate working knowledge of programming and scripting languages (e.g., RPG, C#, Lansa, and React) and Infrastructure as Code (IaC) concepts to identify, assess, and help remediate application and code-based security vulnerabilities.
  • Hands-on or conceptual experience with application development and/or security tools: static/dynamic code scanning (SAST/DAST), software composition analysis (SCA), and dependency scanning
  • Understanding of secure SDLC practices and how to integrate security into CI/CD pipelines
  • Conceptual understanding of vulnerability scanning solutions, such Tenable/Nessus and code scanning applications
  • Familiarity with web application security fundamentals, including common application vulnerabilities, authentication and authorization concepts, API security basics, and secure coding principles.
  • Knowledge of cybersecurity concepts and countermeasures, including OWASP Top 10, identity and access management, and common attack techniques (IP spoofing, SYN flood, DDoS)
  • Ability to help define and document repeatable application security processes, including intake, testing, remediation tracking, exception handling, and reporting.
  • Ability to analyze large, complex data sets; proficiency with Excel, Power BI, Cognos or other data analytic tools
  • Ability to clearly communicate application security findings, remediation guidance, and risk context to technical teams and business stakeholders, with strong written and verbal communication skills
  • Strong analytical and problem-solving skills
Compensation

$100,000 - $110,000 + 15% Bonus Opportunity

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security & Vulnerability Engineer
Application Security & Vulnerability Engineer

Core-Mark • United States

Remote
USD 110,000 - 140,000
Application Security & Vulnerability Engineer
Application Security & Vulnerability Engineer

Performance Food Group (New) • United States

Remote
USD 110,000 - 140,000
Remote Application Security & Vulnerability Engineer
Remote Application Security & Vulnerability Engineer

Performance Food Group • United States

Remote
USD 100,000 - 110,000
Day 1 health benefits
Employee stock purchase plan
401K employer matching
+2
Application Security Engineer: Vulnerability & DevSecOps
Application Security Engineer: Vulnerability & DevSecOps

Core-Mark • United States

Remote
USD 110,000 - 140,000
AppSec & Vulnerability Engineer — Secure DevOps
AppSec & Vulnerability Engineer — Secure DevOps

Performance Food Group (New) • United States

Remote
USD 110,000 - 140,000
Application Security Analyst
Application Security Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 90,000
Ongoing investment in professional development
Exposure to modern security platforms
Collaborative team environment
Security Engineer, Application
Security Engineer, Application

gnw • Richmond (VA)

Hybrid
USD 78,000 - 117,000
Competitive compensation
Comprehensive healthcare coverage
401(k) with employer match
+2
Application Security Engineer
Application Security Engineer

Tential Solutions • United States

On-site
USD 120,000 - 180,000
PTO
Benefits package
Career growth
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • West Palm Beach (FL)

On-site
USD 120,000 - 170,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Blacksburg (VA)

On-site
USD 120,000 - 170,000
Professional growth
Competitive compensation
Exciting projects
+1