Cybersecurity Engineer
Conagra Brands Omaha, Nebraska, United States · $74K–$109K/yr
Food and Beverage Services · 10,001+ employees
About the role
You will serve as a subject matter expert responsible for designing, implementing, and maintaining secure applications while partnering with development and cybersecurity teams. Key tasks include integrating security tools into CI/CD pipelines, performing threat modeling, and driving vulnerability remediation.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and at least 3 years of IT or software engineering experience, with 2 years specifically in application security. Proficiency in secure coding practices, security frameworks, and common application security testing tools is required.
Benefits
Full description
Reporting to the Director of Information Security, you will serve as a trusted application security subject matter expert responsible for designing, implementing, and maintaining secure applications across Conagra Brands. You will partner with development, platform, and cybersecurity teams to embed security throughout the software development lifecycle, reduce application risk, and advance the organization's Application Security program. You will support secure application design, vulnerability management, developer enablement, incident response activities, and continuous improvement initiatives aligned with enterprise security standards and industry frameworks.
A Taste of Your Responsibilities
- Integrate, operate, and optimize static application security testing, dynamic application security testing, software composition analysis, and secrets-scanning tools within continuous integration and continuous delivery pipelines.
- Perform application threat modeling and secure design reviews for new applications, features, services, and application programming interfaces.
- Triage, prioritize, track, and drive remediation of application vulnerabilities while monitoring service level agreements, risk exposure, and program metrics.
- Conduct or coordinate secure code reviews and application or application programming interface penetration testing for high-risk systems.
- Manage open-source dependency risks and support software bill of materials initiatives.
- Define, promote, and support secure coding standards, developer education, and the security champions program.
- Partner with cloud and platform teams to support web, mobile, application programming interface, container, and cloud-native application security.
- Contribute to security incident response activities involving application-layer threats and support root-cause remediation efforts.
- Support evaluations, pilots, and proofs of concept for application security tools and technologies.
- Apply application security requirements to enterprise initiatives and releases while escalating risks and exceptions when appropriate.
- Support risk assessments and control conformance activities aligned with Open Worldwide Application Security Project Application Security Verification Standard and Open Worldwide Application Security Project Software Assurance Maturity Model.
- Monitor emerging application security and software supply chain threats and communicate relevant findings to cybersecurity leadership.
- Share application security expertise across technical teams and help mature the overall Application Security program.
Ingredients Required for Your Success
- Bachelor’s degree in Computer Science, Information Security, Software Engineering, or a related field, or equivalent professional experience.
- 3+ years of information technology or software engineering experience, including at least 2 years focused on application security.
- Hands-on experience with static application security testing, dynamic application security testing, and software composition analysis tools.
- Working knowledge of the Open Worldwide Application Security Project Top 10 and Application Security Verification Standard.
- Experience reviewing code in one or more languages such as Java, C#, Python, JavaScript, or TypeScript.
- Familiarity with continuous integration and continuous delivery platforms such as Azure DevOps, GitHub Actions, or Jenkins.
- Knowledge of common application vulnerabilities and practical remediation approaches.
- Experience applying cybersecurity and risk management frameworks including NIST Cybersecurity Framework, NIST 800-53, Common Vulnerability Scoring System, ISO 27001, and Information Technology Infrastructure Library.
- Strong collaboration skills with cross-functional teams in a matrixed environment.
- Excellent verbal and written communication skills with experience presenting technical information to both technical and non-technical audiences.
- Preferred certifications include Certified Information Systems Security Professional, Global Web Application Penetration Tester, Offensive Security Certified Professional, Certified Secure Software Lifecycle Professional, Certified Ethical Hacker, or equivalent.
- Experience with application programming interface security, containers, Kubernetes, infrastructure-as-code scanning, penetration testing, bug bounty programs, capture-the-flag competitions, or coordinated vulnerability disclosure is preferred.
- Willingness to travel up to 10%.
Physical Requirements
This role is based on a standard corporate office environment. Occasional availability outside core business hours may be required to support critical security incidents, releases, or business priorities.
Number of Days in Office: 3
#LI-Hybrid #LI-SG1 #LI-Associate
Compensation
Pay Range:$73,600-$109,300
The annual salary listed above is the expected offering for this position. An employee’s actual annual salary will be based on but not limited to: location, relevant experience/level and skillset, while balancing internal Conagra employees’ equity. Conagra Brands will comply with applicable law regarding minimum salaries for exempt employees.
Our Benefits
We care about your total well-being and will support you with the following, subject to your location and role:
- Health: Comprehensive healthcare plans, wellness incentive program, mental wellbeing support and fitness reimbursement
- Wealth: Great pay, bonus incentive opportunity, matching 401(k) and stock purchase plan
- Growth: Career development opportunities, employee resource groups, on-demand learning and tuition reimbursement
- Balance: Paid-time off, parental leave, flexible work-schedules (subject to your location and role) and volunteer opportunities
Our Company
At Conagra Brands, we have a rich heritage of making great food. We aspire to have the most impactful, energized and inclusive culture in food. As a member of our 18,000+ person team across 40+ locations, you are empowered to reach your potential, make an impact and own your career. We're in the business of building champions – within our people and our iconic brands like Birds Eye®, Slim Jim® and Reddi-Wip®.
Our focus on innovation extends beyond making great food, it also reflects our commitment to embracing new solutions that positively impact our team, the communities we serve and the health of our planet. Foodies Welcome.
Conagra Brands is an equal opportunity employer and considers qualified applicants for employment without regard to sex, race, color, religion, ethnic or national origin, gender, sexual orientation, gender identity or expression, age, pregnancy, leave status, disability, veteran status, genetic information and/or any other characteristic or status protected by national, federal, state or local law. Reasonable accommodation may be made upon request.
Similar roles
-
Cybersecurity Test Engineer
GMRE Davis County, Utah, United States
-
Cybersecurity Engineer
Moyasar Financial Company Riyadh, Riyadh Region, Saudi Arabia
-
Cybersecurity Essentials Instructor
Skills For Change Metro Toronto, Ontario, Canada
-
Senior Cloud Security Engineer (GCP) - Engine by Starling
Starling London, England, United Kingdom
-
Senior Security Engineer
AgelessRx United States · $155K–$170K/yr
-
Security Engineer II (Offensive Operations)
Flywire Boston, Massachusetts, United States · $99K–$120K/yr