Application Security & Vulnerability Engineer
PFG | Performance Good Group Virginia, United States · $100K–$110K/yr
Food and Beverage Services · 10,001+ employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Application Security & Vulnerability Engineer will lead the application security program by implementing scanning processes and coordinating remediation with development teams. Additionally, the role supports the enterprise vulnerability management program, threat intelligence monitoring, and incident response activities.
What they look for
Requirements
Candidates must have an associate degree or equivalent and 3-5 years of direct application security experience. Proficiency in programming languages like C# or React, along with knowledge of secure SDLC practices and vulnerability scanning tools, is required.
Benefits
Full description
Company Description
Performance Food Group is a customer-centric foodservice distribution leader headquartered in Richmond, Va. Grounded by roots that date back to a grocery peddler in 1885, PFG has a nationwide network of approximately 150 distribution centers, 35,000-plus talented associates, and thousands of valued suppliers across the country. With the goal of helping customers thrive, PFG markets and delivers quality food and related products to independent and chain restaurants, schools, business and industry locations, convenience operations, healthcare facilities, vending distributors, office coffee service distributors, big box retailers, and theaters across the U.S. Job Description
We Deliver the Goods:• Competitive pay and benefits, including Day 1 Health & Wellness Benefits, Employee Stock Purchase Plan, 401K Employer Matching, Education Assistance, Paid Time Off, and much more
- Growth opportunities performing essential work to support America’s food distribution system
- Safe and inclusive working environment, including culture of rewards, recognition, and respect
Position Summary: Performance Food Group is looking for a talented Application Security & Vulnerability Engineer to lead efforts in securing PFG's application landscape and enterprise vulnerability management program. This role partners closely with Infrastructure and Application Development teams to establish the foundational application security program by implementing scanning processes, coordinating remediation with application teams, building reporting and metrics, and supporting secure development practices across the software development lifecycle throughout the CI/CD pipeline. The candidate will also support the broader Information Security Program, including incident response, threat intelligence, and compliance initiatives.
Position Responsibilities: Application Security (Primary Focus)• Partner with application development and business teams to build and mature PFG's Application Security program and secure coding practices
- Conduct application security assessments using code scanning (SAST/DAST), dependency/composition analysis (SCA), and security testing tools; coordinate remediation through closure with application owners
- Evaluate applications and CI/CD pipelines to integrate security controls, automate vulnerability detection, and improve remediation processes and timelines
- Advise development teams on secure coding practices and help embed security requirements earlier in the development lifecycle
- Develop developer security training content and drive adoption of secure development practices across applicable functional areas.
- Track and report on application vulnerability trends, remediation SLAs, and program maturity to IT leadership and application owners
- Identify and evaluate security risks within application development and deployment processes, helping promote secure access controls and governance practices.
Vulnerability & Threat Management• Support enterprise Vulnerability Management program, including scanning, prioritization, remediation tracking, and reporting
- Monitor threat intelligence feeds (SANS, software manufacturer alerts, industry news) for relevant threats and vulnerabilities; work with delivery teams to track, prioritize, and remediate identified gaps
- Support activities within the Security Incident Response program, Security Education Awareness Program, and other compliance activities as needed
- Perform other cybersecurity related duties as assigned
Required Qualifications
- Associate's degree in Information Technology, Computer Science, Cybersecurity or related field or equivalent 3–5 years direct application security experience
- 3-5 years of related work experience in information security or application security
- Demonstrate working knowledge of programming and scripting languages (e.g., RPG, C#, Lansa, and React) and Infrastructure as Code (IaC) concepts to identify, assess, and help remediate application and code-based security vulnerabilities.
- Hands-on or conceptual experience with application development and/or security tools: static/dynamic code scanning (SAST/DAST), software composition analysis (SCA), and dependency scanning
- Understanding of secure SDLC practices and how to integrate security into CI/CD pipelines
- Conceptual understanding of vulnerability scanning solutions, such Tenable/Nessus and code scanning applications
- Familiarity with web application security fundamentals, including common application vulnerabilities, authentication and authorization concepts, API security basics, and secure coding principles.
- Knowledge of cybersecurity concepts and countermeasures, including OWASP Top 10, identity and access management, and common attack techniques (IP spoofing, SYN flood, DDoS)
- Ability to help define and document repeatable application security processes, including intake, testing, remediation tracking, exception handling, and reporting.
- Ability to analyze large, complex data sets; proficiency with Excel, Power BI, Cognos or other data analytic tools
- Ability to clearly communicate application security findings, remediation guidance, and risk context to technical teams and business stakeholders, with strong written and verbal communication skills
- Strong analytical and problem-solving skills
Preferred Qualifications
- Bachelor's Degree
- 4–6 years, with direct application security assessment experience
- Professional certification such as Security+, Network+, CISA, CEH, CCNA, or GSEC (application-security-focused certifications such as GWAPT or OSCP a plus)
- Experience with cloud security architectures (PaaS, SaaS, IaaS) and virtualization
- Experience with mobile device management and mobile security architecture
- Familiarity with MITRE ATT&CK Framework and advanced persistent threats (APTs) TTPs
- Demonstrated experience embedding automated security scanning into DevOps/CI/CD workflows
EEO Statement
Performance Food Group and/or its subsidiaries (individually or collectively, the "Company") provides equal employment opportunity (EEO) to all applicants and employees, regardless of race, color, national origin, sex, marital status, pregnancy, sexual orientation, gender identity, religion, age, disability, genetic information, veteran status, and any other characteristic protected by applicable local, state and federal laws and regulations. Please click on the following links to review: (1) our EEO Policy; (2) the "EEO is the Law" poster and supplement; and (3) the Pay Transparency Policy Statement.
Similar roles
-
Emerging Technologies & Cybersecurity Manager
BC High Boston, Massachusetts, United States · $90K–$110K/yr
-
Enterprise Cybersecurity BigID Engineer
Booz Allen Hamilton McLean, Virginia, United States · $99K–$225K/yr
- Principal OT Cybersecurity Consultant
-
Senior Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. Hanscom AFB, Massachusetts, United States · $175K–$185K/yr
-
OT Cybersecurity Specialist
INTECH Process Automation Basrah, Al-Basrah, Iraq
-
Senior Consultant - Cybersecurity Compliance Specialist
Adservio Luxembourg Luxembourg, Luxembourg