AppSec Engineer: Secure SDLC & Vulnerability Remediation

Yum! Brands

Louisville (KY)

On-site

USD 107,000 - 147,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Yum! Brands seeks an Application Security Engineer to strengthen security across web, mobile, and restaurant tech. You will identify, prioritize, and remediate vulnerabilities, guide secure SDLC practices, and help manage SAST/DAST/SCA programs.

Collaboration with engineering, product, and security teams is essential. Expect active threat monitoring and risk communication across stakeholders. This role emphasizes securing supply chains, container security, and IaC tooling, with parity to

Qualifications

  • Bachelor's degree and 4+ years in cybersecurity, software engineering, or app development.
  • Experience evaluating vulnerabilities for exploitability and business risk.
  • Ability to explain security concepts to technical and non-technical audiences.
  • Knowledge of SSDLC practices and modern software delivery methods.
  • Familiarity with PCI DSS, GDPR, and CCPA in testing/remediation.

Responsibilities

  • Provide security guidance as a SME around application security and operate Yum! security services.
  • Identify, prioritize, and remediate vulnerabilities in mobile and web apps across Yum! systems.
  • Review findings, determine root cause, and communicate remediation strategies and timelines.
  • Maintain scan profiles, policies for SAST/DAST/SCA, container security, IaC, and secrets detection.
  • Integrate security into the SDLC, including secure coding and release processes.
  • Run awareness campaigns to promote secure development practices.
  • Monitor publicly disclosed vulnerabilities and communicate risks to stakeholders.
  • Coordinate with incident response to contain and investigate application security incidents.

Skills

SSDLC knowledge
Vulnerability assessment
Effective communication
Threat modeling
Security governance

Education

Bachelor's degree in cybersecurity or related field

Tools

SAST
DAST
SCA
CI/CD tooling
Container security tooling

Job description

Yum! Brands seeks an Application Security Engineer to strengthen security across web, mobile, and restaurant tech. You will identify, prioritize, and remediate vulnerabilities, guide secure SDLC practices, and help manage SAST/DAST/SCA programs.

Collaboration with engineering, product, and security teams is essential. Expect active threat monitoring and risk communication across stakeholders. This role emphasizes securing supply chains, container security, and IaC tooling, with parity to

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer III — Vulnerability & Penetration Management
Security Engineer III — Vulnerability & Penetration Management

Yum! Brands • Louisville (KY)

On-site
USD 118,000 - 148,000
Application Security Engineer — Secure SDLC Champion
Application Security Engineer — Secure SDLC Champion

Conagra Brands • Omaha (NE)

Hybrid
USD 74,000 - 109,000
Health insurance
401(k) match
Stock purchase plan
+6
Application Security Engineer
Application Security Engineer

Yum! Brands • Louisville (KY)

On-site
USD 107,000 - 147,000
Application Security Analyst I: Secure SDLC & CI/CD
Application Security Analyst I: Secure SDLC & CI/CD

Transaction Network Services (TNS) • Kentucky

On-site
USD 75,000 - 83,000
Medical & dental coverage
Life insurance
Paid holidays and vacations
+1
Staff Application Security Engineer: Scale Secure SDLC
Staff Application Security Engineer: Scale Secure SDLC

BetterCloud • Buffalo (NY)

On-site
USD 110,000 - 170,000
Senior Security Engineer — WAF & Cloud Security Champion
Senior Security Engineer — WAF & Cloud Security Champion

Yum! Brands • Kansas

On-site
USD 117,000 - 148,000
Medical, dental, vision insurance
401(k) plan
Paid time off
+2
Senior Web Security Engineer — WAF & Cloud
Senior Web Security Engineer — WAF & Cloud

KFC Corporation • United States

On-site
USD 117,000 - 148,000
Insurance coverage: medical, dental, &
401(k) plan, vacation, holidays, sick/
Paid time off and volunteer days
AppSec Analyst I: Shape Secure SDLC & Remediation
AppSec Analyst I: Shape Secure SDLC & Remediation

Transaction Network Services (TNS) • Virginia (MN)

On-site
USD 75,000 - 83,000
Medical and dental coverage
Life insurance
Paid holidays and vacations
+1
Emerging Application Security Analyst - Secure SDLC
Emerging Application Security Analyst - Secure SDLC

TNS Inc. • Virginia (MN)

Hybrid
USD 75,000 - 83,000
Medical and dental coverage
Life insurance
Paid holidays and vacations
+1
Senior Remote AppSec Engineer: Secure SDLC & API
Senior Remote AppSec Engineer: Secure SDLC & API

Miteksystems 2 • United States

On-site
USD 120,000 - 150,000
Home office setup allowance
Stock plan participation
Paid time off