Senior Application Security Engineer - Wyoming, MI
2 days ago

Job description
Welcome to Gordon Food Service We are excited that you are thinking about opportunities with us, and we have an amazing story to share. See below for a quick glance of who we are and the impact you could have on the food service industry. There's a seat at our table for you...
Position Summary:
The Senior Application Security Engineer develops and maintains the application security environment for all Gordon Food Service Information Technology.
What you will do:
- Establish strategic direction for software security standards, practices, tools, and lifecycle processes at Gordon Food Service.
- Oversee design-time threat modeling and risk assessment activities for deployed software solutions; mentor project teams in the practice of threat modeling.
- Conduct initial high-level risk assessments of SaaS (cloud) and COTS (commercial package) software solutions.
- Maintain secure coding standards and best practices for custom software development at Gordon Food Service.
- Work closely with Application Services teams and with the Gordon Food Service quality architect and QA/QC team to ensure that security controls are in place for Gordon Food Service custom software and it is security tested.
- Provide secure software development mentoring and guidance to Gordon Food Service software engineers.
- Perform internal penetration testing against new or modified software solutions.
- Coordinate external security assessments (e.g., "grey-box" web application penetration tests).
- Serve as the Enterprise Information Security (EIS) team resource to represent EIS concerns on the Gordon Food Service Application Engineering Council (AEC) and Application Architecture Council (AAC).
- Research and keep abreast of the dynamic threat landscape associated with software security, adapting Gordon Food Service protection strategies to proactively cope with emerging threats.
- Other duties and responsibilities as assigned.
When you will work:
- Monday to Friday, 8am to 5pm
- Hybrid schedule, 4 days in office in Wyoming, MI with 1 day remote
What you'll bring to the table:
- Bachelor's Degree in Computer Science, Information Technology or a related field preferred.
- Five or more years previous related experience or an equivalent combination of education, training, and experience.
- Solid grasp of standard web application development technologies such as: Java, Python, JavaScript, Maven, HTML5, frontend tools (NPM, Grunt, Gulp, etc.), current frameworks (Angular, Backbone, Ember, ReactJS, Kotlin, Spring etc.).
- Experience in DevOps and containerized cloud environments a plus, including Docker, Google Cloud Platform (GCP) and Kubernetes.
- Familiarity with automated analysis / security testing technologies such as: Static Application Security (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST) and Runtime Application Self-Protection (RASP).
- Thorough understanding of web application security and vulnerability / attack patterns such as those enumerated in the OWASP Top 10.
- Thorough understanding of the software development lifecycle and the ways in which security disciplines are incorporated into it and throughout its stages.
- Proficiency with web application penetration testing tools such as Burp Suite or OWASP ZAP.
- Familiarity with software security maturity models such as OSAMM or BSIMM.
- Familiarity with threat modeling and security risk analysis tools and processes.
- Familiarity with secure software design and coding practices.
- Thorough knowledge of security testing practices and supporting methodologies such as OWASP ASVS (Application Security Verification Standard).
- Ability to mentor less-experienced development staff and clearly communicate the goals of software security, the risks of insufficient security controls to the organization, the nature of common vulnerabilities, and the best practices for mitigating them.
- Ability to advocate for security, identity, and compliance imperatives in council discussions with senior domain engineers and application architects.
- Ability to assess security risks within the context of real-world software solutions and develop common-sense, pragmatic mitigation strategies in collaboration with project teams and business stakeholders
BE PART OF AN AMAZING CULTURE WHERE WHAT MATTERS TO YOU, MATTERS TO US
Gordon Food Service values our customers and understands that their success is largely dependent upon their workforce. To demonstrate our commitment to our partnership, we will require any candidate who works for a Gordon Food Service customer to provide a letter of support from their management if they are selected for the interview process.
Equal Employment Opportunity is a matter of policy at Gordon Food Service, Inc. and we are committed to a work environment in which all individuals are treated with respect and dignity.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, status as a protected veteran, or status as a qualified individual with disability. If you require reasonable accommodation for any part of the application or hiring process due to a disability, please submit your request to and use the words "Accommodation Request" in your subject line.
All Gordon Food Service locations are tobacco-free.
Gordon Food Service is a drug-free workplace and conducts pre-employment drug tests.
Similar jobs
We're looking to hire a Senior Security Engineer (Privacy + Compliance) To Join Our Team. You'll work with our incredible clients in one of two ways: Team Augmentation or Design & Build. · ...
1 month ago
Senior Security Engineer Privacy Job Summary Shape the future of blockchain bringing business on-chain We re offering a unique opportunity to join Launch Legends as part of time Equity Cofounder Founded nearly four years ago Launch Legends is at the forefront of bridging Web3 blo ...
1 week ago
We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder. · Architect penetration tests for cryptographic operations validating resilience at 1B+ TPS. · Implement vulnerability scans for DAG-based interpreters ensuring secure topolog ...
1 week ago
We are seeking a skilled Cloud Network Security Engineer to join our team in Bellevue, WA. · In this role, you will play a pivotal part in enhancing our security posture through various initiatives. · Our team is dedicated to leveraging cutting-edge technologies to meet our secur ...
2 weeks ago
This internship role involves designingimplementingand optimizing data pipelinesarchitecture. · Strong proficiency in data engineering technologiesincluding SQL ETL processesdata warehousing concepts. · Experience with programming languages such as Pythonor Javafamiliarity with d ...
1 week ago
+We're offering a unique opportunity to join Launch Legends (and Autheo) as part-time Equity Cofounder.We're building a world-class QA team to ensure excellence in our blockchain Layer-1/2 solutions... · +Demonstrate expertise with best-in-class scanning and monitoring tools · De ...
1 month ago
We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder.We have already completed an initial financing round to support infrastructure and marketing, and are currently in discussions with VCs and crypto investors to fund expansion a ...
1 month ago
We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder. · ...
1 week ago
As a CO+I Critical Environment Mechanical Engineer at Microsoft's Cloud Operations & Innovation (CO+I), you will perform a key role in delivering the core infrastructure and foundational technologies for Microsoft's online services including Bing, Office 365, Xbox, OneDrive, and ...
4 weeks ago
+Decentralized infrastructure for blockchain and AI computing +High availability system with 99.999% uptime +Real-time monitoring of blockchain anomalies and DePIN performance +Automated provisioning and scaling of Kubernetes clusters ...
1 week ago
We are committed to cultivating an inclusive work environment for all employees. · In alignment with our Microsoft values, · we need you as a Critical Environment Electrical Engineer. · ...
1 month ago
We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder. · ...
1 week ago
Lead the architecture and evolution of mission-critical software systems that power global aviation communications. As a Principal Software Engineer, you will serve as a technical authority and thought leader, shaping system architecture, guiding engineering teams, and owning com ...
1 month ago
We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder. Founded nearly four years ago, Launch Legends is at the forefront of bridging Web3 blockchain technology with the next evolution of Web2 integration—bringing businesses on-cha ...
1 month ago
The position of Critical Facility Technician is responsible for ensuring that all electrical, mechanical, and fire/life safety equipment within the data center is operating at peak efficiency.This involves both planned preventative maintenance of equipment, daily corrective work, ...
2 weeks ago
We are seeking an Electronics Technician 3 to join our Security and Electronic Systems (SES) business Unit. · M.C. Dean is Building Intelligence. We design, build, operate and maintain cyber-physical solutions for the nation’s most mission-critical facilities. · ...
1 month ago
We currently have an Installation Technician opening for team-oriented individuals possessing vocational training in electronics or electromechanical engineering. · In this role, you will be responsible for providing service on ST products at customer sites,The position provides ...
1 month ago
We design, build, operate, and maintain cyber-physical solutions for the nation's most recognizable mission critical facilities... · ...
1 month ago
We design, build, operate and maintain cyber-physical solutions for the nation's most mission-critical facilities. With over 7 thousand employees our capabilities span electrical electronic security telecommunications life safety automation and controls audiovisual and IT systems ...
2 weeks ago
Shape the Future of Blockchain—Bringing Business On-Chain We're offering a unique opportunity to join Launch Legends (and Autheo) as a part-time Equity Cofounder. This is a part time equity / token-based cofounder opportunity. You will receive equity in Launch Legends, Autheo, an ...
1 week ago
The Enterprise Architect – Solution Architecture role at Pearson VUE is a strategic, high-impact position responsible for defining technical solutions that drive new customer acquisition, · support entry into emerging markets, and expand capabilities for existing customers.This r ...
1 month ago