Application Security Engineer: Automate and Harden Apps

PepsiCo

Plano (TX)

On-site

USD 80,000 - 134,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical benefits
Dental benefits
Vision benefits
Disability insurance
401(k) retirement plan
Employee Assistance Program

Job summary

PepsiCo is seeking an experienced application security professional to implement and operate foundational controls, optimize tooling, and enable automation at scale. You will improve signal quality, reduce false positives, and guide developers in remediating critical risks across cloud-native apps in AWS/Azure/GCP.

You will tune scanners, manage WAF/CDN security, and participate in Agile delivery. The role requires knowledge of SAST/DAST/SCA, policy-as-code, and secure DevOps practices to

Qualifications

  • Bachelor’s degree in computer science, Engineering, or a related technical field, with 3-4 years of relevant professional experiences or equivalent in job experience.
  • Experience with secure software development and identifying vulnerabilities within application code.
  • Experience analyzing application security findings and providing actionable remediation guidance.
  • Hands-on experience with application security, vulnerability management, and security engineering.
  • Experience securing cloud-native applications in AWS (preferred), Azure, or GCP.

Responsibilities

  • Configure, tune, and maintain application security tools to maximize accuracy, coverage, and performance.
  • Establish and maintain security baselines, policies, and scanning rules aligned with organizational standards.
  • Improve finding quality by reducing false positives and ensuring results accurately reflect business risk.
  • Develop and maintain risk-based prioritization models to focus remediation on the highest-impact vulnerabilities.
  • Integrate security tool outputs into centralized vulnerability management workflows.
  • Validate findings, investigate false positives, and track remediation through closure.
  • Partner with engineering teams to implement security guardrails and secure development practices.
  • Continuously evaluate and optimize security tooling, processes, and platform effectiveness.
  • Perform targeted security assessments of high-risk applications to identify coverage gaps and critical vulnerabilities.
  • Manage and optimize Web Application Firewall (WAF) and CDN security capabilities, including DDoS protection, bot mitigation, and traffic management.
  • Evaluate emerging security technologies and recommend improvements to increase automation, coverage, and operational efficiency.
  • Develop and maintain technical documentation, operational runbooks, and security standards.
  • Support vulnerability response, remediation activities, and application security incident investigations.
  • Participate in Agile development, including sprint planning, backlog refinement, estimation, stand-ups, and retrospectives.
  • Develop metrics and KPIs to measure program effectiveness and drive continuous improvement.
  • Participate in a 24/7 on-call rotation, including weekends and holidays.

Skills

Secure software development
Vulnerability remediation guidance
Cloud security (AWS/Azure/GCP)
Python or Go
CI/CD security integration
API security (OAuth, JWT)
WAF security
Policy-as-Code (OPA, Sentinel)
CDN and DDoS basics
Cryptography fundamentals

Education

Bachelor’s degree in CS, Engineering, or related field

Tools

SAST tools
SCA tools
DAST tools
WAF configuration
CI/CD tooling

Job description

PepsiCo is seeking an experienced application security professional to implement and operate foundational controls, optimize tooling, and enable automation at scale. You will improve signal quality, reduce false positives, and guide developers in remediating critical risks across cloud-native apps in AWS/Azure/GCP.

You will tune scanners, manage WAF/CDN security, and participate in Agile delivery. The role requires knowledge of SAST/DAST/SCA, policy-as-code, and secure DevOps practices to

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer — Cloud-Native & Automation
Application Security Engineer — Cloud-Native & Automation

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 80,000 - 134,000
Senior Security Automation & Vulnerability Lead (Emerging Tech)
Senior Security Automation & Vulnerability Lead (Emerging Tech)

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 94,000 - 156,000
Medical benefits
Dental benefits
Vision benefits
+3
Senior InfoSec Automation & Data Security Lead
Senior InfoSec Automation & Data Security Lead

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 94,000 - 156,000
Bonus payout 10% of annual salary
Comprehensive benefits package
Application Security | Application Security Engineer
Application Security | Application Security Engineer

PepsiCo Deutschland GmbH • Plano (TX)

On-site
USD 80,000 - 134,000
Threat Response & Vulnerability Automation Lead
Threat Response & Vulnerability Automation Lead

PepsiCo • Plano (TX)

On-site
USD 94,000 - 156,000
Medical, Dental, Vision
Paid time off
Retirement plan
Application Security | Application Security Engineer
Application Security | Application Security Engineer

PepsiCo • Plano (TX)

On-site
USD 80,000 - 134,000
Medical benefits
Dental benefits
Vision benefits
+3
Senior Information Security Principal - Automation & Data Security
Senior Information Security Principal - Automation & Data Security

PepsiCo • Plano (TX)

On-site
USD 94,000 - 156,000
Medical
Dental insurance
Vision insurance
+1
Senior Vulnerability & Security Automation Engineer
Senior Vulnerability & Security Automation Engineer

PepsiCo • Plano (TX)

On-site
USD 80,200 - 134,250
Medical, Dental, Vision
Disability Insurance
Employee Assistance Program (EAP)
+2
Application Security Engineer — Shift Left & Automate
Application Security Engineer — Shift Left & Automate

Teradata Group • San Diego (CA)

On-site
USD 130,000 - 190,000
Senior Application Security Engineer (Secure DevOps)
Senior Application Security Engineer (Secure DevOps)

Relha LLC • Northern (KY)

Hybrid
USD 172,000 - 240,000