
Application Security Engineer
Yum! Brands, Inc.1 day ago
Remote, United StatesMid Level
Base Salary
$107k - $147k/yr
Responsibilities
- Provide application security guidance to US teams, engineering groups, product owners, and third-party engineers.
- Identify, assess, prioritize, and remediate vulnerabilities in web and mobile applications.
- Manage application security scan profiles, policies, coverage, and onboarding across SAST, DAST, SCA, container security, IaC, secrets detection, and penetration testing platforms.
- Integrate secure coding, automated security testing, software supply chain security, and secure release practices into the SDLC.
- Analyze exploitability, root cause, business impact, remediation options, and compliance with remediation timelines.
- Monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies.
- Validate fixes through rescanning, communicate security risks and recommendations, and coordinate application security incident response and root cause analysis.
- Conduct secure software development awareness campaigns and promote adherence to technology risk management standards.
Requirements
- Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development; additional relevant experience may substitute for the degree.
- Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
- Experience collaborating with software engineering teams and communicating technical concepts to technical and non-technical audiences.
- Familiarity with secure software development lifecycle practices, software delivery methodologies, compliance and data privacy regulations including PCI DSS, GDPR, and CCPA.
- Knowledge of Git-based workflows, source code management, CI/CD integration, build automation, deployment technologies, and application security testing methodologies.
- Knowledge of secure coding principles, OWASP Top 10 vulnerabilities, web application attack techniques, HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, and Content Security Policy.
- Knowledge of OAuth 2.0, OpenID Connect, SAML, JWT, role-based access control, package management ecosystems, software supply chain security, SBOMs, containers, and Infrastructure as Code.
- Preferred experience includes software development in Java, JavaScript/TypeScript, Python, C#, Go, or Rust; securing Git-based DevSecOps environments; integrating security controls into CI/CD pipelines; and understanding AI-assisted development security considerations.
Tech Stack
Categories
About Yum! Brands, Inc.
Yum! Brands is a publicly traded restaurant company that operates and franchises KFC, Taco Bell, Pizza Hut, and The Habit Burger Grill for consumers worldwide. Its model centers on franchising, digital ordering, and delivery platforms, with corporate teams supporting marketing, supply chain, and enterprise technology. The company was formed in 1997 and is headquartered in Louisville, Kentucky, with thousands of restaurants across more than 150 countries.