Security Engineer, Web Application Security (5583)

your Jared

United States

Remote

USD 107,000 - 147,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Yum! Brands is seeking a Security Engineer to join its Cybersecurity Engineering organization to protect the web applications and APIs across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

The role emphasizes WAF/CDN, certificate management, and API security using Akamai technologies, with collaboration across security, IT, and product teams to ensure availability, performance, and robust security.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
  • 2–4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
  • Familiarity with OWASP Top 10 and web security threats.

Responsibilities

  • Configure, maintain, and support Web Application Firewall protections using Akamai App & API Protector.
  • Monitor and investigate web security events involving various threats and anomalies.
  • Assist with onboarding applications onto the enterprise WAF/CDN platform.
  • Support the lifecycle management of public TLS certificates and related processes.
  • Participate in incident response activities and on-call rotation.

Skills

Reverse proxies
CDN concepts
REST APIs
Web app security
Networking basics

Education

Bachelor’s degree in CS or related field

Tools

Akamai App & API Protector
Akamai CDN
Certificate Manager
Web security platforms

Job description

Building global, iconic brands people trust and champion

YUM!

Remote

Position Summary

We are seeking a Security Engineer to join Yum! Brands' Cybersecurity Engineering organization and help protect the web applications and APIs supporting our global digital ecosystem across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

This role will support the operation and continuous improvement of Web Application Firewall (WAF), Content Delivery Network (CDN), API security, and digital certificate management services. The engineer will work with technologies such as Akamai App & API Protector, Akamai CDN, Certificate Manager, and other web security platforms to help protect internet-facing applications from cyber threats while maintaining application availability and performance.

The ideal candidate has a strong technical foundation in networking, web technologies, or cybersecurity and is interested in developing deeper expertise in web application security, CDN technologies, APIs, and certificate management.

This role will work closely with senior engineers and cross-functional teams to troubleshoot issues, onboard applications, respond to security events, implement security changes, maintain certificates, and improve operational processes.

Primary Responsibilities
Web Application Security
  • Configure, maintain, and support Web Application Firewall (WAF) protections using Akamai App & API Protector and related security technologies.
  • Monitor and investigate web security events involving:
  • Other suspicious or malicious web traffic
  • Layer 7 attacks
  • DDoS attacks
  • Credential stuffing
  • Bot traffic
  • API attacks
  • OWASP Top 10 vulnerabilities
  • Assist with WAF policy tuning to reduce false positives while maintaining appropriate security protections.
  • Review application traffic and security logs to identify attack patterns, application behavior, and potential security concerns.
  • Implement approved WAF policy changes, exceptions, allowlists, and security configuration updates.
  • Support senior engineers during complex security investigations and production incidents.
CDN & Edge Security
  • Configure and maintain CDN and edge security configurations supporting internet-facing applications.
  • Work with Akamai technologies including:
  • Caching and delivery configurations
  • Origin connectivity
  • DNS integrations
  • Cloudlets
  • Edge Hostnames
  • Property Manager
  • Troubleshoot common CDN and web application issues involving:
  • Application availability
  • TLS/SSL
  • Origin connectivity
  • Routing
  • DNS
  • Cache behavior
  • HTTP response codes
  • Support the onboarding of new websites and APIs onto the enterprise WAF/CDN platform.

Perform pre-production validation, testing, and post-change verification.

Certificate Lifecycle Management
  • Support the lifecycle management of public TLS certificates, including:
  • Replacement
  • Revocation
  • Renewal
  • Deployment
  • Issuance
  • Request validation
  • Monitor certificate inventories and upcoming expiration dates.
  • Coordinate certificate changes and renewals with application owners and other technical teams.
  • Validate certificates after deployment and troubleshoot common certificate, trust chain, DNS validation, and TLS issues.
  • Maintain accurate certificate ownership and lifecycle documentation.
  • Escalate certificate risks or renewal issues before they can impact production applications.
Security Operations & Incident Response
  • Monitor and investigate WAF alerts, application issues, and security events.
  • Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other available telemetry to assist with troubleshooting and investigations.
  • Participate in incident response activities involving WAF, CDN, DDoS, certificates, and internet-facing applications.
  • Assist with troubleshooting customer-impacting production issues and determining whether issues originate from the security/CDN layer or another application component.
  • Implement approved mitigations and validate application functionality following security changes.
  • Follow established incident management, escalation, and change management processes.
  • Participate in the team's on-call rotation supporting globally distributed applications and services.
Automation & Engineering
  • Identify repetitive operational activities that could benefit from automation.
  • Develop and maintain basic scripts and tools using technologies such as Python, PowerShell, Bash, or REST APIs.
  • Assist with improving security monitoring, reporting, inventory management, and operational dashboards.
  • Contribute to automation and standardization of application onboarding, WAF configuration, and certificate management processes.
  • Learn and adopt Infrastructure-as-Code and API-driven security management practices where appropriate.
Collaboration & Continuous Improvement
  • Work closely with:
  • Security Operations
  • Compliance
  • Enterprise Architecture
  • IAM
  • Infrastructure
  • Networking
  • Cloud Engineering
  • Software Engineering
  • Partner with application teams during WAF/CDN onboarding, troubleshooting, security changes, and certificate activities.
  • Participate in technical discussions and architecture reviews alongside senior engineers.
  • Create and maintain technical documentation, troubleshooting guides, operational procedures, and runbooks.
  • Share knowledge and lessons learned with other members of the team.
  • Identify opportunities to improve existing processes and operational practices.
Governance & Compliance
  • Follow established security standards, change management procedures, and operational processes.
  • Support PCI DSS and internal audit activities by gathering technical evidence and documentation.
  • Assist with periodic security reviews and control assessments.
  • Maintain accurate documentation for WAF configurations, certificates, application ownership, exceptions, and operational processes.
  • Support remediation activities identified through audits, vulnerability assessments, penetration testing, and security reviews.
Required Qualifications
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
  • 2–4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
  • Foundational understanding of:
  • Reverse proxies and CDN concepts
  • REST APIs
  • Web applications
  • TCP/IP
  • DNS
  • TLS/SSL
  • HTTP/HTTPS
  • Familiarity with Web Application Firewall technologies or web application security concepts.
  • Familiarity with common web security threats and the OWASP Top 10.
  • Experience troubleshooting technical issues using logs and other diagnostic information.
  • Ability to analyze technical problems and follow issues through resolution.
  • Strong written and verbal communication skills.
  • Ability and willingness to learn new security technologies and platforms.
Preferred Qualifications

Experience in all of the following areas is not required. Candidates with a strong technical foundation and demonstrated ability to learn are encouraged to apply.

  • Hands-on experience with Akamai or similar WAF/CDN platforms.
  • Experience with Akamai technologies such as:
  • Bot Manager
  • Cloudlets
  • Edge DNS
  • Certificate Manager
  • Property Manager
  • App & API Protector
  • Experience with public TLS certificate management.
  • Experience working with cloud environments such as AWS, Azure, or GCP.
  • Experience with SIEM or log analysis platforms such as Splunk, Sentinel, or similar technologies.
  • Basic scripting experience with Python, PowerShell, or Bash.
  • Experience working with REST APIs.
  • Familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
  • Security certifications such as Security+, GSEC, Akamai certifications, or equivalent technical certifications.

Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.

Stay connected with Yum! Brands and be the first to know about new opportunities across KFC, Taco Bell, The Habit Burger Grill, and our corporate functions.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer, Web Application Security
Security Engineer, Web Application Security

Yum! Brands • Plano (TX)

On-site
USD 107,000 - 147,000
Sr. Security Engineer
Sr. Security Engineer

KFC Corporation • United States

On-site
USD 117,800 - 147,600
Insurance coverage: medical, dental, &
401(k) plan, vacation, holidays, sick/
Paid time off and volunteer days
Sr. Security Engineer
Sr. Security Engineer

Yum! Brands • Kansas

On-site
USD 117,800 - 147,600
Medical, dental, vision insurance
401(k) plan
Paid time off
+2
Remote Security Engineer: Web App & API Protection
Remote Security Engineer: Web App & API Protection

your Jared • United States

Remote
USD 107,000 - 147,000
Application Security Engineer
Application Security Engineer

Yum! Brands • Louisville (KY)

On-site
USD 107,000 - 147,000
Application Security Engineer
Application Security Engineer

Cybersecurity Jobs • Louisville (KY)

On-site
USD 107,000 - 147,000
Senior Security Engineer — WAF & Cloud Security Champion
Senior Security Engineer — WAF & Cloud Security Champion

Yum! Brands • Kansas

On-site
USD 117,800 - 147,600
Medical, dental, vision insurance
401(k) plan
Paid time off
+2
Security Engineer
Security Engineer

Yum Brands • Seattle (WA)

On-site
USD 112,000 - 120,000
401(k) with 6% matching
4 weeks vacation per year
Onsite childcare
+3
Senior Security Engineer
Senior Security Engineer

Akamai Technologies, Inc. • Carson City (NV)

On-site
USD 113,000 - 203,000
Senior Security Engineer
Senior Security Engineer

Akamai Technologies, Inc. • Helena (MT)

Hybrid
USD 113,000 - 203,000
Healthcare
401K savings plan
Paid time off (PTO)
+2