Trouvez un emploi qui compte. Travaillez avec des personnes
qui se sentent concernées.

Cybersecurity Engineer Sr- Application Security

Détails de l’offre d’emploi

Réf. de l’offre d’emploi:
174461
Lieux:
Providence, RI 02903
Flexibilité géographique:
À distance
Catégorie:
IT
Type d’emploi:
Temps plein
Statut de l’emploi :
Exempté
Date de clôture prévue:
30 janvier 2026
Base de rémunération
Annuel
Échelle salariale
$100200.00 - $193400.00 Annually ($48.17 - $92.98 Hourly)
Marque
UNFI

Job Overview:
The Senior Cybersecurity Engineer (Application Security) is responsible for protecting our organization’s software applications and services from threats by embedding security practices into the software development lifecycle (SDLC).
The role functions as part of the cybersecurity operations team and collaborates cross-functionally with Application Development, Threat Intelligence, Vulnerability Management, Threat Emulation and Security Architecture teams to identify vulnerabilities, perform assessments, to build secure applications and promote a culture of security. This position plays a critical role in safeguarding sensitive data, maintaining compliance, and reducing application‑layer risk in cloud, web, mobile and API environments.
The role is expected to independently lead engagements from conception to completion, communicate technical details to partners and senior leadership, mentor junior staff, and provide technical direction to the program.


Job Responsibilities:

  • Conduct security-focused code reviews, static application security testing (SAST), dynamic application security testing (DAST), software composition analysis (SCA), and interactive application security testing (IAST)
  • Triage and prioritize findings from automated security scans and penetration testing results; provide actionable remediation guidance to developers
  • Collaborate with software development teams to integrate security tools and best practices into CI-CD pipelines (e.g., secret scanning, dependency checking, secure coding standards)
  • Develop and maintain security tools, scripts, frameworks, and automation to scale application security efforts
  • Support vulnerability assessments, penetration testing, and red team exercises on applications
  • Provide security consulting and training to development teams on secure coding practices, common vulnerabilities (e.g., OWASP top 10), and emerging threats
  • Monitor emerging application security trends, vulnerabilities (e.g., CVEs), and attack techniques; contribute to incident response when application exploits occur
  • Ensure applications align with relevant standards and regulations (e.g., NIST, OWASP, PCI-DSS, SOC 2)
  • Create and update security documentation, policies and threat models as needed
  • Compiles and analyzes data for management reporting and metrics as directed
  • Demonstrates expert-level knowledge and skills in the technical, process, organizational, and philosophical aspects of application security
  • Performs other duties as assigned

Job Requirements:

Education / Certifications:

  • BA/BS in Computer or Cybersecurity domain
  • Relevant certifications such as OSCP, GWAPT, CSSLP, CEH, CISSP, or cloud security certs (e.g., AWS Security Specialty)

Experience:

  • 6+ years of experience in application security, secure software development, penetration testing, or related cybersecurity roles, in a large, highly diverse, and distributed environment
  • Strong understanding of web application vulnerabilities, OWASP top 10, and secure coding principles
  • Proficiency in at least one or more programming languages (e.g., Python, Java, JavaScript, C#)
  • Hands-on experience with AppSec tools such as:
    • SAST: SNYK, Veracode, SonarQube, Checkmarx, CodeQL
    • DAST: SNYK, OWASP ZAP, Burp Suite, Veracode
    • SCA: Snyk, Dependabot, Black Duck, OWASP Dependency-Check
    • Other: Wiz, GitHub Advanced Security, or similar
  • Familiarity with cloud platforms (AWS, Azure, GCP) and container/orchestration technologies (Docker, Kubernetes)
  • Experience with DevSecOps practices and integrating security into CI-CD pipelines
  • Knowledge of secure SDLC methodologies, threat modeling (e.g., STRIDE, PASTA), and secure design patterns

Knowledge / Skills / Abilities:

  • Excellent written, verbal, and interpersonal communication skills – able to explain technical security issues to non-technical stakeholders and collaborate effectively with developers
  • Analytical mindset with strong problem-solving abilities
  • Proactive, detail-oriented, and able to manage multiple priorities
  • Ability to translate technical findings into actionable insights
  • Ability to mentor junior staff and transfer technical knowledge as well as contribute to the team’s knowledge sharing
  • Strong independent direction and ability to multi-task
  • Flexible and adaptable to learning and understanding new technologies
  • Ability to work extremely well under pressure while maintaining a professional image and approach
  • Team player with proven ability to work effectively with other business units, IT management and staff, vendors, and consultants
  • Exceptional information analysis abilities: ability to perform independent analysis and distill relevant findings and root cause
  • Comfortable discussing complex findings and issues with variety of audiences, including C‑suite level
  • Self-driven and able to reach deadlines on-time with minimal direction
  • Passion for cybersecurity and staying current with evolving threats

Work Environment:
Remote Role:

  • This position is classified as remote where the associate will perform remote work from their primary residence. Remote associates are welcome to work from the office but are not required to do so. While remote associates are not required to work from an office on a regular basis, they may be required to come to the office or other UNFI locations for necessary business reasons or if directed to do so by their manager.

Physical Environment/Demands:
Office Roles:

  • Most work is performed in a temperature-controlled office environment.
  • Incumbent may sit for long periods of time at a desk or computer terminal.
  • While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear.
  • Incumbent may use calculators, keyboards, telephones, and other office equipment during a normal workday.
  • Stooping, bending, twisting, and reaching may be required in the completion of job duties.

The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and/or location.

UNFI is an Equal Opportunity employer committed to creating an inclusive and respectful environment for all. All qualified applicants will receive equal consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity or expression, national origin, disability, protected veteran status, or other protected ground. Accommodation is available upon request for candidates taking part in all aspects of the job selection process. - M/F/Veteran/Disability. VEVRAA Federal Contractor.

Société:
United Natural Foods Inc.

Rémunération:

UNFI prévoit de payer le taux de rémunération mentionné ci-dessus (ou dans la fourchette de rémunération mentionnée ci-dessus) pour ce poste. La rémunération réelle, le cas échéant, dépendra d’un certain nombre de facteurs, y compris, mais sans s’y limiter, l’éducation, l’expérience, la formation et toute exigence en vertu des conventions collectives applicables. UNFI s’engage à faire preuve de transparence en matière de paie, conformément aux lois applicables des États/provinces et locales en vigueur.

Avantages:

Pour les postes à Washington (ou les postes pouvant être exercés à distance depuis Washington), cliquez ICI pour connaître les détails concernant les congés payés de l’État de Washington.

Les candidats embauchés pour ce poste seront également admissibles aux programmes d’avantages suivants : congé payé ; congé de maladie ; vacances et congé parental ; programme 401K (ou régime d'épargne-retraite au Canada) ; assurance médicale, soins dentaires, soins de la vue, assurance vie et assurance décès/démembrement accidentel ; programme d’assurance invalidité à court et à long terme, allocation de dépenses flexible et/ou compte d’épargne santé (États-Unis uniquement), sous réserve de satisfaire aux conditions d’admissibilité et aux modalités de ces programmes, et sous réserve de toute exigence en vertu des conventions collectives applicables.

Emplois dans le domaine de la vente uniquement : Pour les postes de vente rémunérés à la commission, la fourchette ci-dessus est une estimation de la rémunération totale potentielle à la commission au cours de la première année de l’employé, mais UNFI offre une période d’introduction d’un montant minimum de 680 $ par semaine. Après la période d’introduction, comme il s’agit d’un poste basé à 100 % sur les commissions, il n’y a pas de salaire fixe. Les plans de commission de UNFI ne sont pas plafonnés et les revenus moyens varient en fonction du territoire et des ventes réalisées, ainsi que d’autres facteurs.

Les politiques de UNFI en matière de rémunération, de prestations ou avantages sociaux et de congés payés sont susceptibles d’être modifiées à la seule discrétion de la société, dans le respect de la législation en vigueur. Cette offre d’emploi ne doit pas être interprétée comme une offre d’emploi comprenant certaines modalités ni comme une garantie de revenu minimum.

Joignez-vous à notre réseau de talents

Trouvez l’emploi qui vous convient
chez UNFI