McLane Company, Inc.
Cyber Defense Platform Security Engineer (Microsoft)
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About McLane Company, Inc.
McLane Company, Inc. is a leading distributor in the United States, founded in 1894. The company serves convenience stores, mass merchants, and chain restaurants, employing over 26,000 people. With a national distribution network that spans more than 18 million square feet, McLane provides comprehensive supply chain solutions, including procurement, warehousing, and transportation services through one of the largest private fleets in the country. The company has a significant presence in various industries, holding a notable market share in confectionery wholesaling and cigarette and tobacco product wholesaling. McLane emphasizes competitive pricing, product selection, and expert support for its customers. It offers flexible ordering terms and technology solutions for real-time inventory tracking and streamlined operations. Led by CEO Tony Frankenberger, McLane aims to deliver a superior customer experience while positively impacting its teammates and communities.
Security at McLane Company, Inc.
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- McLane's Application Security philosophy centers on embedding security directly into the application build, test, and deployment phases through automation and developer collaboration.
- Their stated mission is to 'embed security directly into how applications are built, tested, and deployed' .
- They follow an automation-first approach, aiming to 'automate security testing (SAST, DAST), vulnerability scanning, and compliance checks' .
- The team prioritizes developer enablement by 'integrating security into build and deployment workflows' and providing 'remediation guidance' .
- Their risk philosophy involves leading 'vulnerability management, penetration testing' and designing 'secure CI/CD pipelines' .
Security Team
- The cybersecurity function is led by Juan Gomez-Sanchez, Vice President of Cybersecurity, who is described as a 'Cybersecurity Executive, Advisor and Servant Leader' .
- The broader IT and digital strategy is overseen by Murat Genc, Chief Information & Digital Officer, who aims to 'build an intelligent, scalable digital foundation' .
- While the exact reporting line for AppSec is not explicitly detailed, the team operates within a 'modern, automation-first security environment' .
- As of March 2026, there is at least one active 'Senior Security Engineer' posting focused on application security.
- Common skill patterns include expertise in SAST/DAST automation, CI/CD integration, and SCA tools like Snyk and Sonatype.
Key Initiatives
McLane's primary AppSec initiative is the integration of security into the DevOps lifecycle, often referred to as 'Shift Left.' They focus on 'designing and maintaining secure CI/CD pipelines' and 'integrating security into build and deployment workflows' . Their vulnerability management process includes leading 'penetration testing and remediation guidance' . They emphasize 'automating security at scale across cloud-native platforms' . There is no public evidence of a formal Security Champions program or specific remediation SLAs (MTTR).
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.