Cybersecurity Engineer
Conagra Brands · Omaha, NE · 2 days ago
Hybrid$74k–$109k/yrFull-time
About the role
Reporting to the Director of Information Security, you will serve as a trusted application security subject matter expert responsible for designing, implementing, and maintaining secure applications across Conagra Brands. You will partner with development, platform, and cybersecurity teams to embed security throughout the software development lifecycle, reduce application risk, and advance the organization's Application Security program. You will support secure application design, vulnerability management, developer enablement, incident response activities, and continuous improvement initiatives aligned with enterprise security standards and industry frameworks.
Responsibilities
- Integrate, operate, and optimize static application security testing, dynamic application security testing, software composition analysis, and secrets-scanning tools within continuous integration and continuous delivery pipelines.
- Perform application threat modeling and secure design reviews for new applications, features, services, and application programming interfaces.
- Triage, prioritize, track, and drive remediation of application vulnerabilities while monitoring service level agreements, risk exposure, and program metrics.
- Conduct or coordinate secure code reviews and application or application programming interface penetration testing for high-risk systems.
- Manage open-source dependency risks and support software bill of materials initiatives.
- Define, promote, and support secure coding standards, developer education, and the security champions program.
- Partner with cloud and platform teams to support web, mobile, application programming interface, container, and cloud-native application security.
- Contribute to security incident response activities involving application-layer threats and support root-cause remediation efforts.
- Support evaluations, pilots, and proofs of concept for application security tools and technologies.
- Apply application security requirements to enterprise initiatives and releases while escalating risks and exceptions when appropriate.
- Support risk assessments and control conformance activities aligned with Open Worldwide Application Security Project Application Security Verification Standard and Open Worldwide Application Security Project Software Assurance Maturity Model.
- Monitor emerging application security and software supply chain threats and communicate relevant findings to cybersecurity leadership.
- Share application security expertise across technical teams and help mature the overall Application Security program.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field, or equivalent professional experience.
- 3+ years of information technology or software engineering experience, including at least 2 years focused on application security.
- Hands-on experience with static application security testing, dynamic application security testing, and software composition analysis tools.
- Working knowledge of the Open Worldwide Application Security Project Top 10 and Application Security Verification Standard.
- Experience reviewing code in one or more languages such as Java, C#, Python, JavaScript, or TypeScript.
- Familiarity with continuous integration and continuous delivery platforms such as Azure DevOps, GitHub Actions, or Jenkins.
- Knowledge of common application vulnerabilities and practical remediation approaches.
- Experience applying cybersecurity and risk management frameworks including NIST Cybersecurity Framework, NIST 800-53, Common Vulnerability Scoring System, ISO 27001, and Information Technology Infrastructure Library.
- Strong collaboration skills with cross-functional teams in a matrixed environment.
- Excellent verbal and written communication skills with experience presenting technical information to both technical and non-technical audiences.
- Preferred certifications include Certified Information Systems Security Professional, Global Web Application Penetration Tester, Offensive Security Certified Professional, Certified Secure Software Lifecycle Professional, Certified Ethical Hacker, or equivalent.
- Experience with application programming interface security, containers, Kubernetes, infrastructure-as-code scanning, penetration testing