
Sr External Web Application & API Security Engineer
McDonald's7 days ago
Base Salary
$138k - $173k/yr
Responsibilities
- Lead API discovery, inventory, classification, ownership mapping, posture management, runtime detection, attacker-behavior analysis, and risk prioritization.
- Assess APIs for authentication, authorization, data exposure, schema, input-validation, rate-control, and other OWASP API Security Top 10 risks, then partner with owners on remediation.
- Design, onboard, operate, and tune WAF, rate-limiting, bot-management, DDoS, and edge security controls for high-availability applications and APIs.
- Analyze API telemetry and lead investigation and containment of credential abuse, token misuse, scraping, enumeration, account takeover, authorization bypass, data exfiltration, and business-logic abuse.
- Integrate API security events with SIEM, SOAR, ticketing, and case-management workflows and define coverage, risk, remediation, alert-fidelity, and response-time metrics.
- Automate API and WAF workflows, including validation, policy promotion, alert routing, remediation tracking, rollback, and reporting.
- Lead security design reviews, maintain standards and runbooks, communicate remediation priorities, mentor engineers and analysts, and support high-severity incidents.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
- Five or more years of security engineering experience, including at least three years of hands-on API security experience.
- Strong knowledge of REST, GraphQL, API gateways, microservices, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, API keys, mutual TLS, service identities, authorization, and common API abuse patterns.
- Hands-on experience with enterprise API security and WAF platforms, security telemetry analysis, attack investigation, false-positive reduction, scripting, and security-platform integrations.
- Experience with at least one major cloud platform—AWS, Microsoft Azure, or Google Cloud Platform—including API gateway, identity, logging, and load-balancing services.
- Strong written and verbal communication skills for explaining technical risk and remediation to technical and non-technical stakeholders.
- Preferred qualifications include Akamai API Security and App & API Protector experience, OpenAPI or GraphQL schema analysis, Terraform and Git-based deployment workflows, and experience supporting global, high-volume digital platforms.
Benefits
- Health and welfare benefits including medical, prescription drug, mental health, dental, vision, and life insurance coverage.
- Eligible for a performance-based bonus.
- Eligible for stock or other equity grants under McDonald’s long-term incentive plan.
- Equal opportunity employer with reasonable workplace accommodations available for qualified individuals with disabilities.
About McDonald's
McDonald’s is the world’s leading global foodservice retailer with over 37,000 locations in over 100 countries. More than 90% of McDonald’s restaurants worldwide are owned and operated by independent local business men and women. McDonald's & our franchisees employ 1.9 million people worldwide. We serve the world some of its favorite foods - World Famous Fries, Big Mac, Quarter Pounder, Chicken McNuggets and Egg McMuffin. To learn more about the company, please visit www.aboutmcdonalds.com.