
Application Security Engineer
Conagra Brands1 day ago
Omaha, NE, USAMid Level
Base Salary
$74k - $109k/yr
Responsibilities
- Integrate, operate, and optimize static application security testing, dynamic application security testing, software composition analysis, and secrets-scanning tools in CI/CD pipelines.
- Perform application threat modeling and secure design reviews for applications, features, services, and APIs.
- Triage, prioritize, track, and drive remediation of application vulnerabilities while monitoring SLAs, risk exposure, and program metrics.
- Conduct or coordinate secure code reviews and application or API penetration testing for high-risk systems.
- Manage open-source dependency risks and support software bill of materials initiatives.
- Define and promote secure coding standards, developer education, and the security champions program.
- Partner with cloud and platform teams on web, mobile, API, container, and cloud-native application security.
- Contribute to application-layer security incident response and root-cause remediation.
- Support application security tool evaluations, pilots, proofs of concept, risk assessments, and control conformance activities.
- Monitor emerging application security and software supply chain threats and communicate findings to cybersecurity leadership.
Requirements
- At least 3 years of information technology or software engineering experience, including at least 2 years focused on application security.
- Bachelor’s degree preferred in computer science, information security, software engineering, or a related field, or equivalent professional experience.
- Hands-on experience with static application security testing, dynamic application security testing, and software composition analysis tools.
- Working knowledge of the OWASP Top 10 and Application Security Verification Standard.
- Experience reviewing code in one or more of Java, C#, Python, JavaScript, or TypeScript.
- Familiarity with Azure DevOps, GitHub Actions, or Jenkins.
- Knowledge of common application vulnerabilities and practical remediation approaches.
- Experience with cybersecurity and risk management frameworks including NIST Cybersecurity Framework, NIST 800-53, CVSS, ISO 27001, and ITIL.
- Strong collaboration, verbal communication, and written communication skills.
- Preferred certifications include CISSP, GWAPT, OSCP, CSSLP, CEH, or equivalent.
- Preferred experience includes API security, containers, Kubernetes, infrastructure-as-code scanning, penetration testing, bug bounty programs, capture-the-flag competitions, or coordinated vulnerability disclosure.
- Willingness to travel up to 10%.
Benefits
- Hybrid work arrangement with three required office days.
- Health benefits, wellness incentives, mental wellbeing support, and fitness reimbursement.
- Bonus incentive opportunity, matching 401(k), and stock purchase plan.
- Career development opportunities, employee resource groups, on-demand learning, and tuition reimbursement.
- Paid time off, parental leave, flexible work schedules, and volunteer opportunities.
- Occasional availability outside core business hours may be required for critical security incidents, releases, or business priorities.
Tech Stack
Categories
About Conagra Brands
Conagra Brands is a publicly traded packaged foods company that develops, manufactures, and markets shelf-stable, frozen, and snack brands for retail and foodservice customers. Its portfolio includes names such as Birds Eye, Healthy Choice, Marie Callender’s, Hunt’s, Orville Redenbacher’s, and Slim Jim. Founded in 1919 and headquartered in Chicago, it sells primarily across North America through grocery, mass, club, and convenience channels.