Senior IT Application Security Engineer
About the role
The Senior IT Application Security Engineer is recognized as a subject matter expert in secure application design, threat modeling, and secure coding practices. You will assist software development teams in designing, creating, and implementing secure solutions by ensuring that security checks are followed throughout each phase of the software development life cycle (SDLC).
Responsibilities
- Develop and provide presentations on application security topics to both technical and non-technical audiences.
- Advise executive leadership on current and evolving threats to enable risk-informed decisions.
- Mentor members of the information security team on matters of application security.
- Facilitate third-party penetration tests, triage findings, and create remediation plans with development teams.
- Provide tailored remediation guidance to software developers to address security findings.
- Provide architectural and security guidance for third-party platforms and services as they integrate into Meijer environments and/or code.
- Review the security of third-party/open-source software used by Meijer.
- Provide risk-based analysis of security posture to drive business decisions.
- Foster relationships with key business partners to create a culture of security and achieve prioritization of security initiatives.
- Develop internal security tooling for identifying or remediating security risks.
- Absorb on matters of application security in the event of an incident.
Requirements
- Bachelor’s degree or above in Computer Science, Information Security, or related field.
- At least four years of professional experience, with at least two years in a security field and at least one year with direct experience writing code.
- Familiar with object-oriented programming and have written code in one or more programming languages (e.g. C#, Java, C++).
- Agile/Scrum, SAFe, or Lean certification preferred.
- Familiarity with secure coding best practices such as the OWASP Top 10.
- Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices).
- Foundational knowledge of security practices in several applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance.
- Knowledge of relevant technology, tools, databases, and development techniques.
- Strong focus on team dynamics and interpersonal relationships.
- Strong sense of task ownership with consistent follow-through.
- Able to anticipate risks and devise solutions with limited information or context.
- Excellent project management, organization, and team collaboration skills.
- Curiosity to learn.
- Capable of defining and measuring key performance indicators.
- Able to work cross-functionally with IT and business partners across all areas of Meijer and vendor partners.
- Adaptive, flexible, and responsive to challenges.
- Awareness of how security controls influence both internal stakeholders and Meijer customers.
- SANS/GIAC, CompTIA, ISC2 (e.g. CISSP) or other applicable industry certifications preferred.
Qualifications
- Bachelor’s degree or above in Computer Science, Information Security, or related field.
- At least four years of professional experience, with at least two years in a security field and at least one year with direct experience writing code.
- Familiar with object-oriented programming and have written code in one or more programming languages (e.g. C#, Java, C++).
- Agile/Scrum, SAFe, or Lean certification preferred.
- Familiarity with secure coding best practices such as the OWASP Top 10.
- Knowledge of common application architectures and the relative risks associated with them (e.g. single page apps, client-server, native mobile, microservices).
- Foundational knowledge of security practices in several applied contexts, e.g. networking, cloud infrastructure, containerization, operations, audit, or governance.
- Knowledge of relevant technology, tools, databases, and development techniques.
- Strong focus on team dynamics and interpersonal relationships.
- Strong sense of task ownership with consistent follow-through.
- Able to anticipate risks and devise solutions with limited information or context.
- Excellent project management, organization, and team collaboration skills.
- Curiosity to learn.
- Capable of defining and measuring key performance indicators.
- Able to work cross-functionally with IT and business partners across all areas of Meijer and vendor partners.
- Adaptive, flexible, and responsive to challenges.
- Awareness of how security controls influence both internal stakeholders and Meijer customers.
- SANS/GIAC, CompTIA, ISC2 (e.g. CISSP) or other applicable industry certifications preferred.
Skills
- Subject Matter Expert in Secure Application Design, Threat Modeling, and Secure Coding Practices.
- Proactive Leadership Role in Driving Application Security Initiatives.
- Define, Communicate, and Enforce Application Security Standards Across the Organization.
- Lead Opportunities to Enhance Security Processes.
- Mentor Team Members by Sharing Expertise.
- Identify Security Knowledge Gaps and Present Training to IT Stakeholders.
- Champion Efforts to Advance the Maturity of the Application Security Program.
- Develop Internal Security Tooling for Identifying or Remediating Security Risks.
- Assist/Led on Matters of Application Security in the Event of an Incident.
Benefits
Comprehensive benefits package that includes medical, dental, vision, life insurance, a 401(k) plan with employer match, disability leave, and paid time off (PTO). In addition to these core benefits, we are committed to supporting your overall well-being and career growth. Our offerings include a variety of programs designed to support your personal and professional development, such as paid parental leave, paid education assistance (including free education), a childcare subsidy and more.
Pay
The pay range for this position is $120,750.00 - $191,000.00. This pay range represents the minimum and maximum base pay for the position, which is determined by factors such as market data, the qualifications required, the level of responsibilities associated with the role and other roles at this same level. Your specific pay rate within this range will be based on your experience, qualifications, and skills compared to the internal team you’ll be joining.
Schedule
Not specified.
Legal Compliance
We are committed to offering competitive pay that reflects market standards and ensures consistency within our organization. We are dedicated to creating a work environment that promotes work-life balance, long-term health and financial security, and continuous professional development.