Sr External Web Application & API Security Engineer

McDonald's Corporation

Chicago, Northern (IL, KY)

Hybrid

USD 138,000 - 173,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus Eligible
Long‑Term Incentive
Health insurance

Job summary

McDonald's Corporation is seeking a Senior Engineer for External Web Application & API Security. You will lead API discovery, posture management, and runtime protection across cloud and on‑prem environments.

You will design, operate, and tune WAF and edge security controls while reducing API risk and enabling secure, scalable digital services.

Qualifications

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field is required or equivalent experience.
  • Five+ years of security engineering experience, including at least three years in API security across discovery, posture assessment, runtime monitoring, testing, architecture review, or control engineering.
  • Strong knowledge of REST, GraphQL, API gateways, microservices, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, API keys, mutual TLS, service identities, authorization, and common API abuse patterns.
  • Hands-on experience with enterprise API security and WAF platforms.
  • Experience integrating security platforms with SIEM, SOAR, ticketing, or automation tools.

Responsibilities

  • Lead API discovery, inventory, classification, and ownership mapping across external, internal, partner, and cloud-hosted APIs.
  • Operate and improve API security capabilities for posture management, runtime detection, attacker behavior analysis, and risk prioritization.
  • Assess REST, GraphQL, SOAP, gRPC, and event-driven APIs for OWASP API Security Top 10 risks and related weaknesses.
  • Design and tune WAF, rate-limiting, bot management, DDoS, and edge security controls for apps and APIs.
  • Automate security workflows and embed validation into CI/CD and DevSecOps processes.
  • Provide coaching and technical direction to Engineers and Analysts during in-source transition.

Skills

REST
GraphQL
API gateways
OAuth 2.0
OpenID Connect
JWT
Security tooling
Cloud platforms (AWS/Azure/GCP)
CI/CD
SIEM/SOAR

Education

Bachelor's degree in CS/Engineering/IT/Cybersecurity

Tools

Akamai API Security
Terraform
Git-based deployments

Job description

Job Description:

Company Description:

McDonald’s growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald’s will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway.

McDonald’s Global Technology is here to power tomorrow’s feel-good moments.

That’s why you’ll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time.Using AI, robotics and emerging tech, we’re digitizing the Golden Arches. Combine that with our unparalleled global scale, and we’re reshaping all areas of the business, industry and every community that is home to a McDonald’s restaurant.We face complex tech challenges every day. But that’s where our diverse and talented teams come in. They’re made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.

Check out the McDonald’s Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.

Department Overview

The Senior Engineer, External Web Application & API Security is a hands-on technical lead responsible for enterprise API security and web application protection.

You will:

  • Lead the engineering and operationalization of API discovery, posture management, and runtime protection capabilities across cloud, on-premises, and partner environments.
  • Design, operate, and tune WAF and edge security controls for high-availability digital services.
  • Assess and reduce API risk related to authorization failures, authentication weaknesses, excessive data exposure, business logic abuse, injection, automation, and other OWASP API Security Top 10 risks.
  • Design and tune WAF, rate-limiting, bot management, DDoS, and edge security controls for applications and APIs, with a strong focus on accuracy, resiliency, and low false-positive rates.
  • Automate repeatable security workflows and embed validation into CI/CD and DevSecOps processes.

This role reports into the Senior Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to Engineers and Analysts as we in-source capabilities from our managed services provider.

Responsibilities & Accountabilities
API Security Engineering and Architecture
  • Lead API discovery, inventory, classification, and ownership mapping across external, internal, partner, and cloud-hosted APIs, including identification of shadow, zombie, and unmanaged APIs.
  • Operate and improve enterprise API security capabilities for posture management, runtime detection, attacker behavior analysis, and risk prioritization.
  • Assess REST, GraphQL, SOAP, gRPC, and event-driven APIs for OWASP API Security Top 10 risks, authentication and authorization weaknesses, excessive data exposure, schema and input-validation gaps, rate-control issues, and differences between documented and observed behavior.
  • Partner with API owners and engineering teams to prioritize findings and implement practical remediation or compensating controls.
  • Develop reusable API security patterns and reference architectures for customer-facing, mobile, partner, microservice, and third-party integrations.
Runtime API Protection and Security Operations
  • Analyze API telemetry, tune behavioral detections, and lead incident investigation and containment for credential abuse, token misuse, scraping, enumeration, account takeover, authorization bypass, data exfiltration, and business logic abuse.
  • Integrate API security events and findings with SIEM, SOAR, ticketing, and case-management workflows to support centralized monitoring, response, and remediation tracking.
  • Define and monitor API coverage, ownership, unmanaged API risk, critical findings, remediation aging, attack volume, alert fidelity, and response-time metrics.
WAF and Edge Application Protection
  • Design, onboard, and tune WAF, rate-limiting, bot-management, DDoS, and edge controls for applications and APIs, including OWASP protections, custom rules, virtual patching, and narrowly scoped exceptions.
Automation, DevSecOps, and Platform Engineering
  • Automate API and WAF security workflows using platform APIs, Terraform, scripting, and CI/CD pipelines, including configuration validation, policy promotion, alert routing, remediation tracking, rollback, and reporting.
Governance, Collaboration, and Technical Leadership
  • Lead security design reviews.
  • Maintain API and web application security standards and runbooks.
  • Communicate risk and remediation priorities.
  • Mentor engineers and analysts.
  • Support high‑severity incidents as required.
Qualifications
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
  • Five or more years of security engineering experience, including at least three years of hands‑on API security across discovery, posture assessment, runtime monitoring, testing, architecture review, or control engineering.
  • Strong knowledge of REST, GraphQL, API gateways, microservices, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, API keys, mutual TLS, service identities, authorization, and common API abuse patterns.
  • Hands‑on experience with enterprise API security and WAF platforms.
  • Experience analyzing security telemetry, investigating attacks, reducing false positives, scripting in a common language, and integrating security platforms with SIEM, SOAR, ticketing, or workflow automation tools.
  • Experience with at least one major cloud platform (AWS, Microsoft Azure, or Google Cloud Platform), including API gateway, identity, logging, and load‑balancing services.
  • Strong written and verbal communication skills, with the ability to explain technical risk and remediation to both engineering and non‑technical stakeholders.
Preferred Qualifications
  • Hands‑on Akamai API Security and App & API Protector experience.
  • OpenAPI or GraphQL schema analysis.
  • Terraform and Git‑based deployment workflows.
  • Experience supporting global, high‑volume digital platforms.
Compensation

Bonus Eligible:YES

Long - Term Incentive:YES

Benefits Eligible: YES

Salary Range

The expected salary range for this role is$138,207.00 -$172,758.00per year
The above represents the expectedsalaryrange for this job requisition. Ultimately, in determining yourpay, we may also consider your experience, and other job-related factors.

Benefits eligible: This position offers health and welfare benefits, including but not limited to comprehensive health insurance, which includes medical, prescription drug, mental health, dental and vision coverage, as well as, life insurance.

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance.

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan.

McDonald’s is an equal opportunity employer committed to the diversity of our workforce. We promote an inclusive work environment that creates feel‑good moments for everyone. McDonald’s provides reasonable accommodations to qualified individuals with disabilities as part of the application or hiring process or to perform the essential functions of their job. If you need assistance accessing or reading this job posting or otherwise feel you need an accommodation during the application or hiring process, please contact mcdhrbenefits@us.mcd.com. Reasonable accommodations will be determined on a case‑by‑case basis.

McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Nothing in this job posting or description should be construed as an offer or guarantee of employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Penetration Testing Lead Analyst
Penetration Testing Lead Analyst

McDonald's Corporation • Chicago (IL)

On-site
USD 167,000 - 209,000
Bonus Eligible
Long Term Incentive
Benefits Eligible
Director, Software Engineering
Director, Software Engineering

McDonald's Corporation • Chicago (IL)

On-site
USD 195,000 - 244,000
Bonus Eligible
Long Term Incentive
Benefits Eligible
Senior Manager - Edge Reliability Engineering
Senior Manager - Edge Reliability Engineering

McDonald's Corporation • Chicago (IL)

On-site
USD 152,000 - 191,000
Bonus Eligible
LT Incentive
Benefits Eligible
Sr Manager, Data Engineering
Sr Manager, Data Engineering

McDonald's Corporation • Chicago (IL), Northern (KY)

Hybrid
USD 167,000 - 209,000
Bonus eligible
Long term incentive
Benefits eligible
Manager, Technology Testing
Manager, Technology Testing

McDonald's Corporation • Chicago (IL), Northern (KY)

Hybrid
USD 127,000 - 159,000
Sr Director, Cyber Third-Party Risk Management
Sr Director, Cyber Third-Party Risk Management

McDonald's Corporation • Chicago (IL), Northern (KY)

Hybrid
USD 237,000 - 296,000
Bonus eligible
Long-term Incentive
Health benefits
+1
Platform Architect, Cloud Security
Platform Architect, Cloud Security

McDonald's Corporation • Chicago (IL), Northern (KY)

Hybrid
USD 127,000 - 159,000
Health insurance
401(k)
Adoption assistance
+2
Sr Manager, Network Product Management
Sr Manager, Network Product Management

McDonald's Corporation • Chicago (IL)

On-site
USD 152,678 - 190,847
Health insurance
Stock options
Bonus eligible
+2
Sr Analyst, Technical Product Management
Sr Analyst, Technical Product Management

McDonald's • Chicago (IL)

On-site
USD 112,000 - 144,000
Health and welfare benefits
401(k) plan
Educational assistance program
+2
Sr Director, Enterprise Architecture
Sr Director, Enterprise Architecture

McDonald's Corporation • Chicago (IL)

On-site
USD 220,000 - 274,000
Health insurance
Long-term incentive