AppSec Jobs
← Back to all jobs

Ryder System, Inc.

Information Security Architect

Little Rock, Arkansas, United StatesWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Ryder System, Inc.

Ryder System, Inc. is a prominent logistics and transportation company based in Coral Gables, Florida. Founded in 1933, Ryder has grown into a leader in supply chain management, generating approximately $12.6 billion in annual revenue. The company operates through three main segments: Supply Chain Solutions, Dedicated Transportation Solutions, and Fleet Management Solutions, providing comprehensive services across the United States, Canada, Mexico, Europe, and Asia. Ryder's Fleet Management Solutions include full-service leasing and short-term rentals of trucks and trailers, along with preventive maintenance services. The Dedicated Transportation Solutions segment offers customized contract carriage, while Supply Chain Solutions encompasses warehouse management, transportation management, and e-commerce fulfillment. With a strong focus on innovation and technology, Ryder supports a diverse range of industries, including automotive and food and beverage, serving many well-known brands.

Industry

logistics & supply chain

Employees

51,000

546 engineers

Revenue

$13B

Website

Visit →

Security at Ryder System, Inc.

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Stated AppSec Mission: "ensures that every step of the software development lifecycle (SDLC) follows security best practices."Developer Enablement vs. Gatekeeping: "collaborate with software development teams to integrate security into the development life cycle."Risk Philosophy: "We utilize the National Institute of Standards and Technology's Cybersecurity Framework (NIST CSF)". Stated Pain Points or Goals: "stay current with security threats, trends, and technologies". Gaps & Contradictions: No verbatim public statements located that define "security as an enabler"vs. strict gating language. Information not publicly available.

Security Team

Org Structure & Reporting Line: "The Chief Information Officer supervises our cybersecurity program". "and our Chief Information Security Officer (CISO) manages its daily operation.". Key Public-Facing Leaders: Joe Ellis, Chief Information Security Officer. LinkedIn: https://www.linkedin.com/in/joe-ellis-45655110. Key Quote: "manages the transportation and logistics company's information security initiatives.". Team Size Estimate: Information not publicly available. Active AppSec Job Postings: Count: 3 (identified AppSec-focused postings) - Application Security Engineer (Boston) – https://jobs.ryder.com/boston-ma/application-security-engineer/046EB45B812B44E6B0D0BD130E570DF3/job/ - Application Security Engineer (Atlanta) – https://jobs.ryder.com/atlanta-ga/application-security-engineer/D3F1772CF76948EC907FE47CFF921C68/job/ - Web Application Security Engineer (Tallahassee) – https://jobs.ryder.com/tallahassee-fl/web-application-security-engineer/EBD6D80AAFFE423298914A66F5030CB1/job/ . Common Skill/Tool Patterns: "Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies.""SCA""WAFs deployed on-premises, in the cloud, or in hybrid environments""Akamai Kona, Azure App Gateway, Cloudflare""Burp Suite and enterprise scanning platforms such as InsightAppSec.""CI/CD experience with Azure Devops, Terraform or other automation""Proficiency in at least one programming language (e.g. Python.NET, Javascript)". Gaps & Contradictions: No public org chart or published AppSec headcount found. Information not publicly available.

Key Initiatives

Security Champions Program: No Evidence Found. (Search of Ryder corporate pages, leadership bios, and job postings produced no verbatim references to a "security champions"program.). Shift Left in Practice: "integrate security into the development life cycle.""integrating security in CI/CD, DevOps". Vulnerability Management Process: Intake: "Conduct security assessments... using both Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) methodologies."Triage/Remediation: "collaborate with development, infrastructure, and SOC/IR teams to ensure findings are triaged, addressed, and documented."Information not publicly available. Secure SDLC Artifacts: "threat modeling, secure coding standards, and code review.""Design and implement secure software development practices". Recent Initiatives (Last 6 Months): No verbatim public statements dated within the last six months describing new AppSec programs, tool rollouts, or policy changes. Information not publicly available. Gaps & Contradictions: No public description of vulnerability prioritization SLAs, security champions, or formalized shift-left program artifacts beyond job responsibilities. Information not publicly available.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.