Base Career helps you apply smarter for this job.
Key skills for this role
The Principal Security Engineer is a senior technical leader who sets the vision, architecture, and standards for enterprise security across infrastructure, applications, data, and cloud platforms. This role defines security patterns, embeds security as code in delivery pipelines, and guides teams to design, build, test, deploy, and support secure solutions that are resilient, performant, user centric, and compliant.
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which also includes five leading omnichannel grocery brands – Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Ahold Delhaize USA associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more.
The Principal Security Engineer is a senior technical leader who sets the vision, architecture, and standards for enterprise security across infrastructure, applications, data, and cloud platforms. This role defines security patterns, embeds security as code in delivery pipelines, and guides teams to design, build, test, deploy, and support secure solutions that are resilient, performant, user centric, and compliant.
Applicants must be currently authorized to work in the United States on a full-time basis.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Salisbury, USA
Carlisle, USA
Salisbury, USA
Quincy, USA
Salisbury, USA
Quincy, USA
Salisbury, USA
Kenansville, USA
Set enterprise security architecture, reference patterns, and guardrails for cloud, network, platform, and application domains, including hybrid and on‑premises infrastructure. Drive security as code practices, integrating automated controls into CI/CD pipelines and cloud native workflows.
Standardize vulnerability management across infrastructure and software layers, prioritizing remediation based on risk and business impact. Integrate identity, access, and secrets management into platform and application architectures, aligning to least privilege and zero trust principles.
Lead threat modeling, risk assessments, and security design reviews for complex initiatives and critical systems. Mentor engineers at all levels; elevate secure coding, testing, automation, and operational excellence across teams.
Support governance of Azure services, subscriptions, connectivity, and administrative models. May be called upon to support critical escalations and must be available during urgent IT incidents as needed.
Guide performance monitoring, logging, and detection engineering to improve signal quality and reduce mean time to detect/respond.
Collaborate with teams supporting enterprise networks, on‑prem data centers, and distributed operational environments to ensure secure connectivity, segmentation, and baseline enforcement.
Influence roadmap priorities using data, metrics, and risk quantification to support informed trade off decisions.
Design scalable controls and "secure by default" blueprints that teams reuse to accelerate delivery and reduce technical debt.
Partner with Technology, Compliance, and business leaders to embed security into evaluation, selection, installation, and configuration of products.
Evangelize modern engineering practices (Agile/Kanban/Lean), ensuring security enhances-not hinders-developer and customer experience.
Orchestrate incident response for high severity events, ensuring rapid triage, root cause analysis, and durable remediation.
Help define and maintain security baselines for servers, platforms, and cloud services, including hardening standards for hybrid infrastructure.
Set enterprise security architecture, reference patterns, and guardrails for cloud, network, platform, and application domains, including hybrid and on‑premises infrastructure.
Drive security as code practices, integrating automated controls into CI/CD pipelines and cloud native workflows.
Lead threat modeling, risk assessments, and security design reviews for complex initiatives and critical systems. Orchestrate incident response for high severity events, ensuring rapid triage, root cause analysis, and durable remediation.
Standardize vulnerability management across infrastructure and software layers, prioritizing remediation based on risk and business impact.
Integrate identity, access, and secrets management into platform and application architectures, aligning to least privilege and zero trust principles.
Support governance of Azure services, subscriptions, connectivity, and administrative models.
Mentor engineers at all levels; elevate secure coding, testing, automation, and operational excellence across teams.
May be called upon to support critical escalations and must be available during urgent IT incidents as needed.
10+ years in progressive experience in cybersecurity, with significant experience in security engineering and architecture roles. Experience working in distributed or multi‑site operational environments is a plus. Experience building platform security capabilities (e.g., cloud security posture management, workload protection, container security). Experience with segmentation design, network architecture, or securing retail or regulated operational environments.
Expertise in security information and event management (SIEM), endpoint detection and response, and detection engineering. Hands on knowledge of application security (secure SDLC, dependency scanning, and runtime protections). Familiarity with PCI DSS, SOX, HIPAA, or similar frameworks; practical experience operationalizing compliance.
Demonstrated leadership in enterprise security architecture for cloud platforms (e.g., Azure, AWS, or GCP), networks, and platforms, including hybrid and on‑premises environments.
Bachelor's degree or equivalent years of work experience.
Excellent communication and executive influencing skills; able to translate risk and complexity into clear, actionable decisions.
Strong proficiency with infrastructure as code (e.g., Terraform or Bicep), configuration management, and policy as code.
Industry certifications (e.g., CISSP, CCSP, GIAC, OSCP) or equivalent portfolio of work.
10+ years in progressive experience in cybersecurity, with significant experience in security engineering and architecture roles.
Proven depth in identity and access management, key and secrets management, and zero trust concepts.
Expertise in security information and event management (SIEM), endpoint detection and response, and detection engineering.
Advanced skills in scripting/automation (e.g., Python or PowerShell) to codify controls, tests, and runbooks.
Experience working in distributed or multi‑site operational environments is a plus.
Experience building platform security capabilities (e.g., cloud security posture management, workload protection, container security).
Hands on knowledge of application security (secure SDLC, dependency scanning, and runtime protections).
Familiarity with PCI DSS, SOX, HIPAA, or similar frameworks; practical experience operationalizing compliance.
Industry certifications (e.g., CISSP, CCSP, GIAC, OSCP) or equivalent portfolio of work
Experience with segmentation design, network architecture, or securing retail or regulated operational environments.
Ahold Delhaize USA, a division of global food retailer Ahold Delhaize, is part of the U.S. family of brands, which also includes five leading omnichannel grocery brands – Food Lion, Giant Food, The GIANT Company, Hannaford and Stop & Shop. Ahold Delhaize USA associates support the brands with a wide range of services, including Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more. Join our Talent Community to stay updated on opportunities with Ahold Delhaize USA. You’ll be the first to know about new positions that match your career aspirations. To join, click here: Talent Community - Ahold Delhaize USA (careerswithus.com) .
At Ahold Delhaize USA, we provide services to one of the largest portfolios of grocery companies in the nation, and we're actively seeking top talent.
Our team shares a common motivation to drive change, take ownership and enable our brands to better care for their customers. We thrive on supporting great local grocery brands and their strategies. Our associates are the heartbeat of our organization. We are committed to offering a welcoming work environment where all associates can succeed and thrive. Guided by our values of courage, care, teamwork, integrity (and even a little humor), we are dedicated to being a great place to work. We believe in collaboration, curiosity, and continuous learning in all that we think, create and do. While building a culture where personal and professional growth are just as important as business growth, we invest in our people, empowering them to learn, grow and deliver at all levels of the business. Learn More About Our Benefits - Click Here
Ahold Delhaize USA is an equal opportunity employer.
Under the Federal Transparency in Coverage rule, group health plans are required to make publicly available machine-readable files that include in-network rates and out-of-network allowed amounts and billed charges. Click here to view the in-network rates and out-of-network allowed amounts and billed charges for health benefits offered by Ahold Delhaize USA.
Our employees and prospective employees are treated with respect and dignity. As an equal opportunity employer, we comply with all applicable federal, state and local laws. Qualified applicants are considered without regard to sex, race, color, ancestry, national origin, citizenship status, religion, age, marital status (including civil unions), military service, veteran status, pregnancy (including childbirth and related medical conditions), genetic information, sexual orientation, gender identity, legally recognized disability, domestic violence victim status or any other characteristic protected by law.
We provide reasonable accommodations to applicants and employees with disabilities. If you have a disability and require assistance in the application process, please contact our Talent Acquisition Department at tad@adusa.com.
The U.S. service division for a global grocery retailer.
Visit company websiteJobs and hiring trendsUSD 108880-187800 yearly / year
Full-time
Senior · 10+ years experience
Hybrid
Apply faster on company sites with our extension.