Application Security Engineer
Yum! United States · $107K–$146K/yr
Restaurants · 10,001+ employees
About the role
The Application Security Engineer will partner with engineering and product teams to identify, prioritize, and remediate vulnerabilities across web, mobile, and restaurant technology environments. They will also integrate security practices into the software development lifecycle and manage application security scanning policies.
What they look for
Requirements
Candidates must have a bachelor's degree or equivalent experience, with at least four years in cybersecurity or software engineering. Proficiency in secure software development methodologies, vulnerability assessment, and modern CI/CD security integration is required.
Benefits
Full description
The Application Security Engineer will help strengthen application security across web, mobile, and restaurant technology environments by partnering closely with engineering, product, and security teams. This role will focus on identifying, assessing, prioritizing, and remediating application vulnerabilities while supporting the integration of security throughout the software development lifecycle. The engineer will also help manage application security testing and scanning practices, provide guidance on secure development, monitor emerging vulnerabilities, and communicate security risks and remediation recommendations to both technical and non-technical stakeholders.
Responsibilities
Primary Responsibilities
- Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
- Aligning with a risk-based approach, collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations applications.
- Leverage established YUM! security services to review vulnerability findings and work closely with engineering teams to communicate, prioritize, and remediate security issues. Analyze findings to determine root cause, exploitability, business impact, and appropriate remediation strategies while ensuring adherence to established remediation timelines.
- Maintain the brand's application security scan profiles and scan policies in accordance with baseline standards across SAST, DAST, software composition analysis (SCA), container security, Infrastructure as Code (IaC), secrets detection, and crowd-sourced penetration testing platforms. Onboard new applications into security services and continuously improve scan coverage and effectiveness.
- Partner with development teams to integrate security into the software development lifecycle (SDLC), including secure coding practices, pull request workflows, automated security testing, software supply chain security, and secure release processes.
- Conduct awareness campaigns with engineering teams to promote secure software development practices and adherence to YUM! Global Technology Risk Management standards.
- Continuously monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies. Assess business risk, prioritize remediation activities, validate fixes through rescanning, and communicate recommendations to stakeholders.
- Coordinate with incident response teams to contain, remediate, and perform root cause analysis on application security incidents.
Qualifications
Basic Qualifications
- Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development. Additional years of relevant experience may be considered in lieu of a bachelor's degree.
- Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
- Experience collaborating effectively with software engineering teams and communicating technical concepts to both technical and non-technical audiences.
- Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.
- Familiarity with relevant compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and how they influence application security testing and remediation activities.
Technical Qualifications
- Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management practices.
- Knowledge of CI/CD pipelines, build automation, and deployment technologies, including how security testing integrates into modern software delivery.
- Knowledge of application security testing methodologies including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, container security scanning, and Infrastructure as Code (IaC) security testing.
- Knowledge of secure coding principles and common software vulnerabilities, including the OWASP Top 10, secure authentication, authorization, input validation, output encoding, session management, and common web application attack techniques.
- Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, Content Security Policy (CSP), and common web communication protocols.
- Knowledge of modern authentication and authorization technologies including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and role-based access control (RBAC).
- Knowledge of package management ecosystems (e.g., npm, pip, NuGet, Maven, Gradle) and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials (SBOMs), and package integrity.
- Knowledge of containers and container management technologies (e.g., Docker and Kubernetes), including container image security best practices and interpretation of container security findings.
- Knowledge of Infrastructure as Code technologies (e.g., Terraform, CloudFormation) and secure configuration practices.
- Ability to investigate security findings beyond automated scanner output by understanding underlying technologies, validating exploitability, and recommending practical remediation approaches.
Preferred Qualifications
- Experience developing software in one or more modern programming languages (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).
- Experience securing applications within Git-based DevSecOps environments.
- Experience integrating application security controls into CI/CD pipelines.
- Familiarity with AI-assisted software development tools and the security considerations associated with AI-generated code and automated code review.
Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.
Similar roles
-
Senior Cybersecurity Analyst
Tlingit Haida Tribal Business Corporation Falls Church, Virginia, United States · $91K–$124K/yr
-
Compiler Security Engineer - C/C++, Languages & Runtimes
Apple Cupertino, California, United States
-
Instructional Assistant (Cybersecurity)
Per Scholas Los Angeles, California, United States · $44K/yr
-
Security Engineer - Networking
Tapestry Mountain View, California, United States · $174K–$255K/yr
-
Cybersecurity Rotational Program - June 2027
Staples Business Framingham, Massachusetts, United States
-
Information Security Engineer
Take-Two Interactive Software, Inc. Toronto, Ontario, Canada · CA$71K–CA$106K/yr