UNFI
Senior Application Security Engineer-Remote
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About UNFI
United Natural Foods, Inc. (UNFI) is a leading wholesale distributor of natural, organic, specialty, and conventional grocery products in North America, with net sales of $30.1 billion for fiscal 2024. Established in 1996 through the merger of Mountain People's Warehouse and Cornucopia Natural Foods, UNFI has expanded from a regional distributor to a national leader, headquartered in Providence, Rhode Island. The company operates an extensive network of distribution centers across the United States and Canada. UNFI distributes over 250,000 products, including organic produce, proteins, cheese, and baked goods, as well as conventional groceries. The company partners with thousands of suppliers, ranging from startups to major brands, and offers services such as wholesale distribution, supply chain management, and retail optimization. UNFI serves more than 30,000 retail locations, including natural chains, supermarkets, and foodservice providers, making it a vital player in the grocery supply chain.
Security at UNFI
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- The team focuses on embedding security practices into the software development lifecycle (SDLC) with a collaborative approach emphasizing developer enablement rather than gatekeeping.
- The philosophy centers on integrating security tools and best practices into CI/CD pipelines and providing security consulting and training to development teams on secure coding practices.
- Risk management prioritizes alignment with industry-standard frameworks and regulatory requirements including NIST, OWASP, PCI-DSS, and SOC 2.
Security Team
The Application Security function is integrated into the broader cybersecurity operations team. Matthew Karnas serves as VP, CISO Interim. The team size is not publicly disclosed with sufficient detail. As of March 19, 2026, there is 1 active AppSec job posting with emphasis on integrating security into CI/CD pipelines and providing consulting/training to developers. Specific reporting lines beyond the 'Cybersecurity Operations' designation are not publicly detailed.
Key Initiatives
The team actively implements 'Shift Left' practices by integrating security testing into the automated deployment process. Vulnerability management includes triage of results from multiple automated scanning types including SAST and DAST. Security-focused code reviews are part of the secure SDLC process. No public evidence exists of a formal Security Champions program or specific remediation SLAs.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.