Security Engineer, Web Application Security

Yum! Brands

Plano (TX)

On-site

USD 107,000 - 147,000

Full time

12 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Yum! Brands is seeking a Security Engineer to join its Cybersecurity Engineering org. You will protect web apps and APIs across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

Responsibilities include configuring WAF/CDN protections with Akamai, monitoring security events, and assisting with incident response. Bachelor’s degree and 2–4+ years in security fields are expected.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent.
  • 2–4+ years in cybersecurity, networking, cloud engineering, or related field.
  • Foundational understanding of web security concepts and REST APIs.
  • Experience with Akamai or similar WAF/CDN platforms is a plus.

Responsibilities

  • Configure and maintain WAF protections using Akamai App & API Protector.
  • Monitor web security events and investigate suspicious or malicious traffic.
  • Configure CDN/edge security configurations and manage TLS certificates.
  • Support incident response and security investigations across web apps and APIs.
  • Develop automation scripts to improve monitoring and onboarding processes.
  • Collaborate with Security Operations, Compliance, and Infra teams to improve practices.

Skills

Web security concepts
REST APIs
Networking basics
OWASP Top 10
Incident response coordination

Education

Bachelor's degree in CS/IT/C cybersecurity

Tools

Akamai App & API Protector
WAF/CDN platforms
Edge DNS
Cloudlets
Bot Manager
TLS/Certificate management

Job description

Position Summary

We are seeking a Security Engineer to join Yum! Brands' Cybersecurity Engineering organization and help protect the web applications and APIs supporting our global digital ecosystem across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

Position Summary

We are seeking a Security Engineer to join Yum! Brands' Cybersecurity Engineering organization and help protect the web applications and APIs supporting our global digital ecosystem across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

Primary Responsibilities
Web Application Security
  • Configure, maintain, and support Web Application Firewall (WAF) protections using Akamai App & API Protector and related security technologies.
  • Monitor and investigate web security events involving:
  • Other suspicious or malicious web traffic
  • Layer 7 attacks
  • DDoS attacks
  • Credential stuffing
  • Bot traffic
  • API attacks
  • OWASP Top 10 vulnerabilities
  • Assist with WAF policy tuning to reduce false positives while maintaining appropriate security protections.
  • Review application traffic and security logs to identify attack patterns, application behavior, and potential security concerns.
  • Implement approved WAF policy changes, exceptions, allowlists, and security configuration updates.
  • Support senior engineers during complex security investigations and production incidents.
CDN & Edge Security
  • Configure and maintain CDN and edge security configurations supporting internet-facing applications.
  • Work with Akamai technologies including:
  • Caching and delivery configurations
  • Origin connectivity
  • DNS integrations
  • Cloudlets
  • Edge Hostnames
  • Property Manager
  • Troubleshoot common CDN and web application issues involving:
  • Application availability
  • TLS/SSL
  • Origin connectivity
  • Routing
  • DNS
  • Cache behavior
  • HTTP response codes
  • Support the onboarding of new websites and APIs onto the enterprise WAF/CDN platform.
Certificate Lifecycle Management
  • Support the lifecycle management of public TLS certificates, including:
  • Replacement
  • Revocation
  • Renewal
  • Deployment
  • Issuance
  • Request validation
  • Monitor certificate inventories and upcoming expiration dates.
  • Coordinate certificate changes and renewals with application owners and other technical teams.
  • Validate certificates after deployment and troubleshoot common certificate, trust chain, DNS validation, and TLS issues.
  • Maintain accurate certificate ownership and lifecycle documentation.
  • Escalate certificate risks or renewal issues before they can impact production applications.
Security Operations & Incident Response
  • Monitor and investigate WAF alerts, application issues, and security events.
  • Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other available telemetry to assist with troubleshooting and investigations.
  • Participate in incident response activities involving WAF, CDN, DDoS, certificates, and internet-facing applications.
  • Assist with troubleshooting customer-impacting production issues and determining whether issues originate from the security/CDN layer or another application component.
  • Implement approved mitigations and validate application functionality following security changes.
  • Follow established incident management, escalation, and change management processes.
  • Participate in the team's on-call rotation supporting globally distributed applications and services.
Automation & Engineering
  • Identify repetitive operational activities that could benefit from automation.
  • Develop and maintain basic scripts and tools using technologies such as Python, PowerShell, Bash, or REST APIs.
  • Assist with improving security monitoring, reporting, inventory management, and operational dashboards.
  • Contribute to automation and standardization of application onboarding, WAF configuration, and certificate management processes.
  • Learn and adopt Infrastructure-as-Code and API-driven security management practices where appropriate.
Collaboration & Continuous Improvement
  • Work closely with:
  • Security Operations
  • Compliance
  • Enterprise Architecture
  • IAM
  • Infrastructure
  • Networking
  • Cloud Engineering
  • Software Engineering
  • Partner with application teams during WAF/CDN onboarding, troubleshooting, security changes, and certificate activities.
  • Participate in technical discussions and architecture reviews alongside senior engineers.
  • Create and maintain technical documentation, troubleshooting guides, operational procedures, and runbooks.
  • Share knowledge and lessons learned with other members of the team.
  • Identify opportunities to improve existing processes and operational practices.
Governance & Compliance
  • Follow established security standards, change management procedures, and operational processes.
  • Support PCI DSS and internal audit activities by gathering technical evidence and documentation.
  • Assist with periodic security reviews and control assessments.
  • Maintain accurate documentation for WAF configurations, certificates, application ownership, exceptions, and operational processes.
  • Support remediation activities identified through audits, vulnerability assessments, penetration testing, and security reviews.
Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
  • 2-4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
  • Foundational understanding of:
  • Reverse proxies and CDN concepts
  • REST APIs
  • Web applications
  • TCP/IP
  • DNS
  • TLS/SSL
  • HTTP/HTTPS
  • Familiarity with Web Application Firewall technologies or web application security concepts.
  • Familiarity with common web security threats and the OWASP Top 10.
  • Experience troubleshooting technical issues using logs and other diagnostic information.
  • Ability to analyze technical problems and follow issues through resolution.
  • Strong written and verbal communication skills.
  • Ability and willingness to learn new security technologies and platforms.
Preferred Qualifications
  • Hands-on experience with Akamai or similar WAF/CDN platforms.
  • Experience with Akamai technologies such as:
  • Bot Manager
  • Cloudlets
  • Edge DNS
  • Certificate Manager
  • Property Manager
  • App & API Protector
  • Experience with public TLS certificate management.
  • Experience working with cloud environments such as AWS, Azure, or GCP.
  • Experience with SIEM or log analysis platforms such as Splunk, Sentinel, or similar technologies.
  • Basic scripting experience with Python, PowerShell, or Bash.
  • Experience working with REST APIs.
  • Familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
  • Security certifications such as Security+, GSEC, Akamai certifications, or equivalent technical certifications.

Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Cloud Software Engineer – Edge, CDN & WAF
Staff Cloud Software Engineer – Edge, CDN & WAF

Intuit • San Diego (CA)

On-site
USD 189,000 - 255,000
Sr. Security Engineer
Sr. Security Engineer

KFC Corporation • United States

On-site
USD 117,000 - 148,000
Insurance coverage: medical, dental, &
401(k) plan, vacation, holidays, sick/
Paid time off and volunteer days
Staff Cloud Software Engineer – Edge, CDN & WAF
Staff Cloud Software Engineer – Edge, CDN & WAF

Intuit Inc. • San Diego (CA)

On-site
USD 189,000 - 255,000
Digital and IT Technical Specialist – Lead AI Platform Enablement Engineer
Digital and IT Technical Specialist – Lead AI Platform Enablement Engineer

Parker Hannifin • Cleveland (OH)

On-site
USD 90,000 - 120,000
Web Application Firewall Engineer (Akamai/F5)
Web Application Firewall Engineer (Akamai/F5)

Tata Consultancy Services • Charlotte (NC)

On-site
USD 65,000 - 125,000
Director, Field Technology- Federal Defense & Intelligence
Director, Field Technology- Federal Defense & Intelligence

Akamai Career Site • United States

On-site
USD 168,000 - 302,000
Health benefits
401K
PTO
+2
Director, Field Technology- Federal Defense & Intelligence
Director, Field Technology- Federal Defense & Intelligence

Akamai Technologies GmbH • Cambridge (MA)

On-site
USD 168,000 - 302,000
FlexBase program
Healthcare benefits
Director, Field Technology- Federal Defense & Intelligence
Director, Field Technology- Federal Defense & Intelligence

Akamai Technologies • Cambridge (MA)

Hybrid
USD 168,000 - 302,000
Healthcare
401K
PTO
+2
Senior II Security Architect
Senior II Security Architect

Akamai Career Site • United States

On-site
USD 139,000 - 251,000
Health insurance
FlexBase program
Flexible work options
Senior II Security Architect
Senior II Security Architect

Akamai Technologies • Cambridge (MA)

On-site
USD 139,000 - 251,000
Healthcare
401K savings plan
Paid time off (PTO)
+3