Sr. Cybersecurity Engineer- Application Security
UNFI
Job Overview Senior Cybersecurity Engineer (Application Security) is responsible for protecting our organization’s software applications and services from threats by embedding security practices into the software development lifecycle (SDLC). The role functions as part of the cybersecurity operations team and collaborates cross‑functionally with Application Development, Threat Intelligence, Vulnerability Management, Threat Emulation, and Security Architecture teams to identify vulnerabilities, perform assessments, build secure applications, and promote a culture of security. This position plays a critical role in safeguarding sensitive data, maintaining compliance, and reducing application‑layer risk in cloud, web, mobile, and API environments. The role is expected to independently lead engagements from conception to completion, communicate technical details to partners and senior leadership, mentor junior staff, and provide technical direction to the program. What does it mean to be part of the Information Technology Team? A role in Information Technology at UNFI involves being part of the transformation of food for all through many innovative technology products such as myUNFI, our customer ordering platform, and our warehouse management systems that optimize service. You will have an opportunity to be part of the technology journey to transform food for all through collaboration and building solutions across teams that directly contribute to our OneUNFI strategy. Roles include network automation, infrastructure unification and modernization, data services and analytics, and digital offering. Job Responsibilities Conduct security‑focused code reviews, static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and interactive application security testing (IAST) Triage and prioritize findings from automated security scans and penetration testing results; provide actionable remediation guidance to developers Collaborate with software development teams to integrate security tools and best practices into CI‑CD pipelines (e.g., secret scanning, dependency checking, secure coding standards) Develop and maintain security tools, scripts, frameworks, and automation to scale application security efforts Support vulnerability assessments, penetration testing, and red team exercises on applications Provide security consulting and training to development teams on secure coding practices, common vulnerabilities (e.g., OWASP top 10), and emerging threats Monitor emerging application security trends, vulnerabilities (e.g., CVEs), and attack techniques; contribute to incident response when application exploits occur Ensure applications align with relevant standards and regulations (e.g., NIST, OWASP, PCI‑DSS, SOC2) Create and update security documentation, policies and threat models as needed Compile and analyze data for management reporting and metrics as directed Demonstrate expert‑level knowledge and skills in the technical, process, organizational, and philosophical aspects of application security Perform other duties as assigned Job Requirements Education / Certifications BA/BS in Computer or Cybersecurity domain Relevant certifications such as OSCP, GWAPT, CSSLP, CEH, CISSP, or cloud security certs (e.g., AWS Security Specialty) Experience 6+ years of experience in application security, secure software development, penetration testing, or related cybersecurity roles, in a large, highly diverse, and distributed environment Strong understanding of web application vulnerabilities, OWASP top 10, and secure coding principles Proficiency in at least one or more programming languages (e.g., Python, Java, JavaScript, C#) Hands‑on experience with AppSec tools such as: SAST: SNYK, Veracode, SonarQube, Checkmarx, CodeQL DAST: SNYK, OWASP ZAP, Burp Suite, Veracode SCA: Snyk, Dependabot, Black Duck, OWASP Dependency‑Check Other: Wiz, GitHub Advanced Security, or similar Familiarity with cloud platforms (AWS, Azure, GCP) and container/orchestration technologies (Docker, Kubernetes) Experience with DevSecOps practices and integrating security into CI‑CD pipelines Knowledge of secure SDLC methodologies, threat modeling (e.g., STRIDE, PASTA), and secure design patterns Knowledge / Skills / Abilities Excellent written, verbal, and interpersonal communication skills – able to explain technical security issues to non‑technical stakeholders and collaborate effectively with developers Analytical mindset with strong problem‑solving abilities Proactive, detail‑oriented, and able to manage multiple priorities Ability to translate technical findings into actionable insights Ability to mentor junior staff and transfer technical knowledge as well as contribute to the team’s knowledge sharing Strong independent direction and ability to multi‑task Flexible and adaptable to learning and understanding new technologies Ability to work extremely well under pressure while maintaining a professional image and approach Team player with proven ability to work effectively with other business units, IT management and staff, vendors, and consultants Exceptional information analysis abilities: ability to perform independent analysis and distill relevant findings and root cause Comfortable discussing complex findings and issues with a variety of audiences, including C‑suite level Self‑driven and able to reach deadlines on time with minimal direction Passion for cybersecurity and staying current with evolving threats Work Environment Remote Role This position is classified as remote where the associate will perform remote work from their primary residence. Remote associates are welcome to work from the office but are not required to do so. While remote associates are not required to work from an office on a regular basis, they may be required to come to the office or other UNFI locations for necessary business reasons or if directed to do so by their manager. Physical Environment/Demands Office Roles Most work is performed in a temperature‑controlled office environment. Incumbent may sit for long periods of time at a desk or computer terminal. While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear. Incumbent may use calculators, keyboards, telephones, and other office equipment during a normal workday. Stooping, bending, twisting, and reaching may be required in the completion of job duties. The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location. About UNFI We are North America’s premier grocery wholesaler, delivering the widest variety of fresh, branded, and owned brand products to community grocers and retail chains alike. A pioneer in natural and organic foods, we are growing and transforming to meet the needs of an evolving workplace. Our 29,000+ employees work across America in our 50 Distribution Centers and corporate offices. Benefits Competitive 401k, Flexible PTO, Remote, Health benefits – first of the month following 30 days of employment, mentorship program/developmental opportunities. UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. All qualified applicants will receive equal consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or other protected ground. Accommodation is available upon request for candidates taking part in all aspects of the job selection process. M/F/Veteran/Disability. VEVRAA Federal Contractor. Compensation UNFI anticipates paying the above‑referenced pay rate (or within the above‑referenced pay range) for this position. Actual Pay, where applicable, will depend on a number of factors, including, but not limited to, education, experience, training, and any requirements under applicable collective bargaining agreements. UNFI is committed to transparency in pay in compliance with applicable state and local laws. Benefits For Washington positions (or positions that may be performed remotely from Washington), for Washington‑specific paid time off details. Candidates hired into this position will also be eligible to participate in the following benefits programs: Paid Time Off; Sick Time; paid holidays and parental leave; 401K Program; medical, dental, vision, life, and accidental death/dismemberment insurance; short‑term and long‑term disability insurance program, Flexible Spending Account and/or Health Savings Account, subject to meeting the eligibility requirements and the terms and conditions of these programs, and subject to any requirements under applicable collective bargaining agreements. UNFI’s compensation, benefits, and paid time off policies are subject to change in the Company’s sole discretion, consistent with applicable law. This job posting should not be construed as an offer of employment with certain terms, nor should it be construed as a guaranteed minimum. Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act. #J-18808-Ljbffr
$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice – the... ...your career in information security! The opportunity The... ...with infrastructure, cloud, application, and security operations teams... ...Manager in Cybersecurity Engineering, where you will play a...ApplicationSeniorSummer holidayRemote workFlexible hours$89k - $143.75k
...Function: R&D Software/Systems Engineering Job Category:... ...for the best talent for a Cybersecurity Software Engineer, to be in... ...periodic risk assessment of security vulnerabilities in software... ...working with multi-threaded applications. ~ Familiarity with shell...ApplicationFull timeTemporary workWork at officeLocal areaRemote workNight shift$161.63k - $222.24k
...Sr. Lead, Enterprise Architect (Digital Commerce... ...Architect with an application specialization in Commerce... ...experience as a lead engineer or solutions architect... ...Impact Design scalable, secure, and high-performance... ...Contribute to cybersecurity, privacy and AI governance...ApplicationSeniorFull timeLocal areaRemote workWorldwideRelocation- ...Overview Your Future. Secured. ISC2 is a force for... ...organization for cybersecurity professionals, our core... ...Position Summary The Sr. Salesforce Developer... ...with a talented software engineering team, building custom... ...and resolve Salesforce application issues in coordination...ApplicationSeniorWork experience placementWork at officeRemote work
- ...SME) functions, including managing all applications within the collaboration platform as well... ...systems operational. Develop the security architecture and manage access and permissions... ...Utilize knowledge of DoD web policies, cybersecurity policies and regulations along with...ApplicationFull timeContract workPart timeLocal areaFlexible hours
$152k - $199k
...central to ensuring the reliable and secure operation of business‑critical batch,... ...development, product management, software engineering, cybersecurity and departmental executives to drive... ...highly available customer‑facing applications, in a GDHA setting Experience building...ApplicationWork at officeLocal areaRelocationMonday to FridayFlexible hours$150k - $170k
...for strengthening internal security assurance across enterprise... ...internal security testing across applications, cloud platforms,... ...and Skills • 10+ years of cybersecurity experience with strong focus... ...collaborate and influence across engineering, risk, audit, and...ApplicationLocal areaFlexible hours- ...Title Senior Incident Response Engineer (Incident Response, Forensics, Healthcare... ...threat hunting within the Information Security group. The companys mission is to secure... ...resume black holes. No spray-and-pray applications. Just smarter matching and real visibility...ApplicationRemote work
$94.1k - $144.8k
...data services across complex application portfolios. It also establishes database standards, security baselines, and governance practices... ...and analytics workloads. Engineer and oversee high-availability... ...with architecture and cybersecurity teams. Compensation Ranges...ApplicationSeniorContract workWork experience placementWork at office$87.7k - $164k
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle... ...in Computer Science, Information Systems, Engineering or a related field 5+ years experience in...ApplicationSummer holidayLocal areaFlexible hours- ...in a fast paced and sophisticated environment ~ Solid grasp of the financial services industry, attained through training and application experience. ~ Can effectively multi-task, manage issues, and drive to resolution in a timely manner. ~ Proactive, detailed, standout...ApplicationSenior
$40 per hour
...company specializing in AI is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This role... ...to apply. Certifications are a plus. Successful applicants will have the opportunity to shape the next generation...Hourly payRemote work$104.8k - $192.2k
...evolving IT landscape, organizations face increasingly complex cybersecurity risks and regulatory pressures. Identity—both human and non-... ..., workflows, and access certification campaigns. Onboard applications and integrate with directories, HR systems, and cloud...ApplicationSeniorWork experience placementSummer holidayFlexible hours$86.38k - $142.54k
...SUMMARY: Under the general supervision of the Application System Manager, provide analysis and programming to assist in the selection, implementation and ongoing support of application software including all interfaces necessary to assure a high value, widely accessible...ApplicationSeniorFull timeWork at officeImmediate startShift work$144.9k - $265.8k
...organizations face increasingly complex cybersecurity risks and regulatory... ...Conduct current state and application access assessments Perform... ...Ping, Saviynt Design cloud security and IAM architectures for... ...management) Design and re‑engineer processes for centralized cloud...ApplicationWork experience placementSummer holidayFlexible hours$94.15k - $150k
...currently hiring for a remote Master Network Engineer to support the US Courts.... ...operate next-generation firewall and web security proxy solutions, ensuring secure, high-availability... ..., based on information provided in your application Employee Perks At GovCIO, we...ApplicationFull timeCurrently hiringRemote workFlexible hours$104.8k - $192.2k
...evolving IT landscape, organizations face increasingly complex cybersecurity risks and regulatory pressures. Identity—both human and non‑... ..., workflows, and access certification campaigns. Onboard applications and integrate with directories, HR systems, and cloud...ApplicationSeniorWork experience placementSummer holidayFlexible hours- ...provider is looking for a Presales Solutions Engineer - Data Protection to become a customer-facing cloud security expert. You will take a consultative approach... ...role requires a Bachelor's degree, substantial cybersecurity experience, and strong communication skills. Remote...Remote work
$110.7k
...Business Sys Analyst Sr - req1597 OVERVIEW Responsible for optimization and streamlining the organization's Quote 2 Cash workstream... ...goals. Develop optimum solutions based on extensive application functional knowledge and business knowledge, to fulfill user needs...ApplicationSeniorRemote work$116k - $144k
...global leader in advanced engineering and innovative technology solutions... ...challenges in science, security and sustainability.... ...expertise in DevOps practices, cybersecurity, and cloud technologies. As... ...Kubernetes). Knowledge of application security principles,...ApplicationSeniorHourly payContract workLocal area- ...Description Summary The Commercial Engine Services Business Intelligence... ...architect data pipelines that feed the AI applications you build, establish secure development workflows, and ship... ...aligns with enterprise standards, cybersecurity requirements, data governance...ApplicationSeniorContract workRemote workRelocation package
$190k - $250k
...company redefining the future of cybersecurity. The company's... ...with responsibly architected security. More at . Role Overview... ..., working closely with UX, Engineering, and Hardware teams to drive... ...workflows and machine learning applications, anomaly detection, LLMs,...ApplicationFlexible hours$146k - $241k
...OverviewPosition OverviewThe Principal Data/AI Engineer helps drive the technical strategy and... ...latency and throughput.Partner with cybersecurity and compliance teams to ensure... ...processes personal data relating to job applicants. The organization is committed to being...ApplicationWork from home$120k - $180k
...yours. Job Summary The Senior Cloud Engineer will play a leadership role on SHI's... ...closely with development, DevOps, and security teams to deliver reliable, scalable, and... ...design, implement, and support multi-tier applications and cloud-based architectures to meet...ApplicationSeniorWorldwideFlexible hours- ...Conduct advanced penetration tests on web applications, mobile applications, network... ...stakeholder teams to uncover and verify security weaknesses. • Develop, plan and execute... ...results. • Keep up with the latest cybersecurity threats, vulnerabilities and trends....ApplicationContract workImmediate start
- ...Summary: The Senior Wireless Deployment Engineer is a critical technical role responsible... ...HPE Aruba Networking Professional - Security Juniper JNCIA-MistAI-Wired Juniper... ...equal opportunity employer. All qualified applicants will receive consideration for...ApplicationSenior
$150k - $250k
...the technology you need to thrive - in our offices or yours. Job Summary The Security Engineer - Google collaborates with account and specialty teams to assess customer cybersecurity needs. They will be a customer-facing cloud security expert.?They will take a...Work experience placementWork at officeWorldwideFlexible hours$126.07k - $196.98k
...chemistry, our products are used in applications that make the products we... ...full stack software engineer who has a track record of designing... ...with related teams (ie. Cybersecurity, Infrastructure, Data Engineering... ...approvals, architecture, security & governance reviews...ApplicationSeniorWork at officeLocal areaRemote work$40 per hour
...We are looking for experienced cybersecurity professionals to join our team to help train AI... ...this role, you will evaluate AI-generated security content, solve technical cybersecurity... ...teaming, incident response, detection engineering, DFIR, malware analysis, threat...SeniorHourly payFull timePart timeRemote work- ...the business Experience with cloud SaaS based solutions or web applications Strong communication skills and the ability to speak and... ...Comply with all regulations regarding corporate integrity and security obligations Report unethical, fraudulent or unlawful behavior...ApplicationSeniorTemporary workWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Cybersecurity Engineer- Application Security. Be the first to apply!
- remote cyber security analyst Providence, RI
- cyber security analyst Providence, RI
- information security consultant Providence, RI
- senior development executive Providence, RI
- senior manager data science Providence, RI
- senior platform engineer Providence, RI
- senior procurement Providence, RI
- senior director product management Providence, RI
- senior compliance officer Providence, RI
- senior tax director Providence, RI


