Application Security Engineer

Yum! Brands

Louisville (KY)

On-site

USD 107,000 - 147,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Yum! Brands seeks an Application Security Engineer to strengthen security across web, mobile, and restaurant tech. You will identify, prioritize, and remediate vulnerabilities, guide secure SDLC practices, and help manage SAST/DAST/SCA programs.

Collaboration with engineering, product, and security teams is essential. Expect active threat monitoring and risk communication across stakeholders. This role emphasizes securing supply chains, container security, and IaC tooling, with parity to

Qualifications

  • Bachelor's degree and 4+ years in cybersecurity, software engineering, or app development.
  • Experience evaluating vulnerabilities for exploitability and business risk.
  • Ability to explain security concepts to technical and non-technical audiences.
  • Knowledge of SSDLC practices and modern software delivery methods.
  • Familiarity with PCI DSS, GDPR, and CCPA in testing/remediation.

Responsibilities

  • Provide security guidance as a SME around application security and operate Yum! security services.
  • Identify, prioritize, and remediate vulnerabilities in mobile and web apps across Yum! systems.
  • Review findings, determine root cause, and communicate remediation strategies and timelines.
  • Maintain scan profiles, policies for SAST/DAST/SCA, container security, IaC, and secrets detection.
  • Integrate security into the SDLC, including secure coding and release processes.
  • Run awareness campaigns to promote secure development practices.
  • Monitor publicly disclosed vulnerabilities and communicate risks to stakeholders.
  • Coordinate with incident response to contain and investigate application security incidents.

Skills

SSDLC knowledge
Vulnerability assessment
Effective communication
Threat modeling
Security governance

Education

Bachelor's degree in cybersecurity or related field

Tools

SAST
DAST
SCA
CI/CD tooling
Container security tooling

Job description

The Application Security Engineer will help strengthen application security across web, mobile, and restaurant technology environments by partnering closely with engineering, product, and security teams. This role will focus on identifying, assessing, prioritizing, and remediating application vulnerabilities while supporting the integration of security throughout the software development lifecycle. The engineer will also help manage application security testing and scanning practices, provide guidance on secure development, monitor emerging vulnerabilities, and communicate security risks and remediation recommendations to both technical and non-technical stakeholders.

Primary Responsibilities
  • Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
  • Aligning with a risk-based approach, collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations applications.
  • Leverage established YUM! security services to review vulnerability findings and work closely with engineering teams to communicate, prioritize, and remediate security issues. Analyze findings to determine root cause, exploitability, business impact, and appropriate remediation strategies while ensuring adherence to established remediation timelines.
  • Maintain the brand's application security scan profiles and scan policies in accordance with baseline standards across SAST, DAST, software composition analysis (SCA), container security, Infrastructure as Code (IaC), secrets detection, and crowd-sourced penetration testing platforms. Onboard new applications into security services and continuously improve scan coverage and effectiveness.
  • Partner with development teams to integrate security into the software development lifecycle (SDLC), including secure coding practices, pull request workflows, automated security testing, software supply chain security, and secure release processes.
  • Conduct awareness campaigns with engineering teams to promote secure software development practices and adherence to YUM! Global Technology Risk Management standards.
  • Continuously monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies. Assess business risk, prioritize remediation activities, validate fixes through rescanning, and communicate recommendations to stakeholders.
  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis on application security incidents.
Basic Qualifications
  • Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development. Additional years of relevant experience may be considered in lieu of a bachelor's degree.
  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
  • Experience collaborating effectively with software engineering teams and communicating technical concepts to both technical and non-technical audiences.
  • Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.
  • Familiarity with relevant compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and how they influence application security testing and remediation activities.
Technical Qualifications
  • Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management practices.
  • Knowledge of CI/CD pipelines, build automation, and deployment technologies, including how security testing integrates into modern software delivery.
  • Knowledge of application security testing methodologies including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, container security scanning, and Infrastructure as Code (IaC) security testing.
  • Knowledge of secure coding principles and common software vulnerabilities, including the OWASP Top 10, secure authentication, authorization, input validation, output encoding, session management, and common web application attack techniques.
  • Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, Content Security Policy (CSP), and common web communication protocols.
  • Knowledge of modern authentication and authorization technologies including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and role-based access control (RBAC).
  • Knowledge of package management ecosystems (e.g., npm, pip, NuGet, Maven, Gradle) and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials (SBOMs), and package integrity.
  • Knowledge of containers and container management technologies (e.g., Docker and Kubernetes), including container image security best practices and interpretation of container security findings.
  • Knowledge of Infrastructure as Code technologies (e.g., Terraform, CloudFormation) and secure configuration practices.
  • Ability to investigate security findings beyond automated scanner output by understanding underlying technologies, validating exploitability, and recommending practical remediation approaches.
Preferred Qualifications
  • Experience developing software in one or more modern programming languages (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).
  • Experience securing applications within Git-based DevSecOps environments.
  • Experience integrating application security controls into CI/CD pipelines.
  • Familiarity with AI-assisted software development tools and the security considerations associated with AI-generated code and automated code review.

Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Yum Brands • Seattle (WA)

On-site
USD 112,000 - 120,000
401(k) with 6% matching
4 weeks vacation per year
Onsite childcare
+3
Sr. Security Engineer
Sr. Security Engineer

Yum! Brands • Kansas

On-site
USD 117,000 - 148,000
Medical, dental, vision insurance
401(k) plan
Paid time off
+2
Sr. Security Engineer
Sr. Security Engineer

KFC Corporation • United States

On-site
USD 117,000 - 148,000
Insurance coverage: medical, dental, &
401(k) plan, vacation, holidays, sick/
Paid time off and volunteer days
Security Engineer, Web Application Security
Security Engineer, Web Application Security

Yum! Brands • Plano (TX)

On-site
USD 107,000 - 147,000
Market Information Security Officer
Market Information Security Officer

Taco Bell • Louisville (KY)

On-site
USD 157,000 - 203,000
Senior Application Security Specialist
Senior Application Security Specialist

A-Line Staffing Solutions • Charlotte (NC)

Hybrid
USD 56,000 - 94,000
Application Security Engineer
Application Security Engineer

Method, Inc. • Washington

On-site
USD 135,000 - 155,000
Medical Coverage
Dental Coverage
Vision Coverage
+4
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • Orlando (FL)

On-site
USD 150,000 - 210,000
Professional growth
Competitive compensation
A selection of exciting projects
+1
Security Engineer
Security Engineer

Wall Street Consulting Services LLC • New York (NY)

On-site
USD 120,000 - 180,000
Senior Application Security Engineer ID87004
Senior Application Security Engineer ID87004

AgileEngine, LLC. • New York (NY)

On-site
USD 140,000 - 190,000
Professional growth
Competitive compensation
A selection of exciting projects
+1