Security Engineer III

Yum! Brands

Gurugram District

On-site

INR 1,800,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Yum! Brands is seeking an experienced Security Engineer III to guide application security for the Yum! ecosystem. You will collaborate with US teams, review vulnerability reports, and lead remediation across mobile, web, and restaurant operations apps.

The role emphasizes threat modeling, secure design guidance, and collaboration with incident response to mitigate incidents affecting applications.

Qualifications

  • Bachelor's degree and 6-8 years of cybersecurity/software development experience.
  • Strong knowledge of application security, vulnerability remediation, and risk assessment.
  • Experience communicating with technical teams and third parties.
  • Familiarity with CI/CD platforms and secure development practices.
  • Knowledge of PCI DSS, GDPR, CCPA and data privacy considerations.

Responsibilities

  • Partner with US teams to provide security guidance as a subject matter expert around application security.
  • Identify, prioritize, and remediate vulnerabilities in mobile and web applications across Yum! systems.
  • Review vulnerability scanner reports and monitor remediation timelines with engineering teams.
  • Maintain security scan profiles and policies across containers, SAST, DAST, and crowdsourced pen testing.
  • Conduct awareness campaigns to ensure secure development practices.
  • Monitor published vulnerabilities and determine remediation priority; re-scan after fixes.
  • Perform threat modeling at design/architecture stages and advise secure design practices.
  • Coordinate with incident response to contain and analyze security incidents affecting applications.

Skills

Security engineering
Application security
Vulnerability management
Threat modeling
CI/CD
OWASP Top 10
Cloud security
Container security
Secure SDLC
Communication

Education

Bachelor's degree in cybersecurity or related field

Tools

Docker
Kubernetes
SAST/DAST tools
CI/CD pipelines
NPM / PIP / APT / YUM

Job description

Responsibilities
  • Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
  • Aligning with a risk-based approach, collaborate with third-party engineers, and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations apps.
  • Leveraging established YUM! security services, review vulnerability scanner reports/results and work with application and/or engineering teams to communicate and address/remediate issues. This includes ensuring adherence to established remediation timelines, including recommending and monitoring remediation activities.
  • Maintain the brand’s application security scan profiles and scan policies as per baseline standards across scanning tools for containers, SAST, DAST, and crowd sourced pen testing. This will include reviewing findings of security scans and onboarding new applications into scanning tools or services.
  • Conduct awareness campaigns with engineering teams to ensure application development adheres to YUM! Global Technology Risk Management development standards.
  • Continuously monitor published vulnerabilities for various applications, operating systems, and databases. Based on the publicly disclosed vulnerabilities determine the remediation priority and engage the stakeholders. Review the solution by re-scanning the disclosed vulnerabilities. (Familiar with OWASP Top 10, etc.)
  • Conduct threat modeling exercises to identify potential risks at the design and architecture stages and provide guidance to development teams in secure design and best practices.
  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis on security incidents affecting applications.
  • Bachelor's degree and at least 6-8 years of experience in cybersecurity and/or software development. Additional years of relevant cybersecurity or development experience may be considered in lieu of bachelor's degree.
  • Experience with reviewing application cybersecurity vulnerabilities for risk and relevance as well as in vulnerability mitigations/remediation planning, for identified vulnerabilities
  • Able to successfully communicate with technical personnel and third parties.
  • Knowledge of continuous integration and continuous delivery platforms
  • Familiarity with relevant compliance and data privacy regulations (e.g. PCI DSS, GDPR, CCPA) and how they impact application security with the ability to incorporate compliance requirements into security testing and remediation processes.
  • Knowledge of common programming languages and paradigms ( OOP, functional, concurrent, etc)
  • Knowledge of cloud environment topics including secrets management, infrastructure as code, and serverless technologies
  • Knowledge of CI/CD techniques and build/deployment pipeline technologies
  • Knowledge of application scanning tools using both dynamic and static techniques
  • Knowledge of containers and container management tools (e.g. Docker, Kubernetes) including how to interpret and remediate security findings and best practices for securing container images and deployments.
  • Knowledge of HTTP communication
  • Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)
Minimum Requirements
  • Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
  • Aligning with a risk-based approach, collaborate with third-party engineers, and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations apps.
  • Leveraging established YUM! security services, review vulnerability scanner reports/results and work with application and/or engineering teams to communicate and address/remediate issues. This includes ensuring adherence to established remediation timelines, including recommending and monitoring remediation activities.
  • Maintain the brand’s application security scan profiles and scan policies as per baseline standards across scanning tools for containers, SAST, DAST, and crowd sourced pen testing. This will include reviewing findings of security scans and onboarding new applications into scanning tools or services.
  • Conduct awareness campaigns with engineering teams to ensure application development adheres to YUM! Global Technology Risk Management development standards.
  • Continuously monitor published vulnerabilities for various applications, operating systems, and databases. Based on the publicly disclosed vulnerabilities determine the remediation priority and engage the stakeholders. Review the solution by re-scanning the disclosed vulnerabilities. (Familiar with OWASP Top 10, etc.)
  • Conduct threat modeling exercises to identify potential risks at the design and architecture stages and provide guidance to development teams in secure design and best practices.
  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis on security incidents affecting applications.
  • Bachelor's degree and at least 6-8 years of experience in cybersecurity and/or software development. Additional years of relevant cybersecurity or development experience may be considered in lieu of bachelor's degree.
  • Experience with reviewing application cybersecurity vulnerabilities for risk and relevance as well as in vulnerability mitigations/remediation planning, for identified vulnerabilities
  • Able to successfully communicate with technical personnel and third parties.
  • Knowledge of continuous integration and continuous delivery platforms
  • Familiarity with relevant compliance and data privacy regulations (e.g. PCI DSS, GDPR, CCPA) and how they impact application security with the ability to incorporate compliance requirements into security testing and remediation processes.
  • Knowledge of common programming languages and paradigms ( OOP, functional, concurrent, etc)
  • Knowledge of cloud environment topics including secrets management, infrastructure as code, and serverless technologies
  • Knowledge of CI/CD techniques and build/deployment pipeline technologies
  • Knowledge of application scanning tools using both dynamic and static techniques
  • Knowledge of containers and container management tools (e.g. Docker, Kubernetes) including how to interpret and remediate security findings and best practices for securing container images and deployments.
  • Knowledge of HTTP communication
  • Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)
Preferred Requirements
  • Knowledge of cloud environment topics including secrets management, infrastructure as code, and serverless technologies
  • Knowledge of CI/CD techniques and build/deployment pipeline technologies
  • Knowledge of application scanning tools using both dynamic and static techniques
  • Knowledge of containers and container management tools (e.g. Docker, Kubernetes) including how to interpret and remediate security findings and best practices for securing container images and deployments.
  • Knowledge of HTTP communication

Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)

Security Engineer III

Level 7

BTECH - Computer Since / Information Technology

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

Yum! Brands • Gurugram District

On-site
INR 1,200,000 - 2,000,000
Security Engineer II
Security Engineer II

KFC Corporation • Gurgaon

Hybrid
INR 1,500,000 - 2,300,000
Application Security Engineer
Application Security Engineer

DigiCert • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Generous time off policies
Top shelf benefits
Education, wellness, and lifestyle support
Application Security Engineer II
Application Security Engineer II

Phenom • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Cyber Security Engineer
Cyber Security Engineer

Vaisesika Consulting • Bengaluru

Hybrid
INR 1,500,000 - 2,100,000
Application Security Engineer - Red Team
Application Security Engineer - Red Team

Air India • Gurugram District

On-site
INR 2,500,000 - 4,000,000
Security Engineer
Security Engineer

Recro • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Application Security Engineer II
Application Security Engineer II

Phenom People • Hyderabad

On-site
INR 1,500,000 - 2,100,000
Application Security Engineer
Application Security Engineer

Ola • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Appsec Specialist - Lead
Appsec Specialist - Lead

Adani Group • Ahmedabad District

On-site
INR 2,800,000 - 4,200,000