
Security Engineer, Web Application Security
Yum! Brands, Inc.1 day ago
Remote, United StatesMid Level
Base Salary
$107k - $147k/yr
Responsibilities
- Configure, maintain, and support Web Application Firewall protections using Akamai App & API Protector and related security technologies.
- Monitor and investigate WAF alerts, web security events, API attacks, bot traffic, credential stuffing, DDoS attacks, Layer 7 attacks, and other suspicious traffic.
- Tune WAF policies, implement approved policy changes and exceptions, review traffic and logs, and support complex security investigations and production incidents.
- Configure and maintain CDN and edge security settings, including Property Manager, Edge Hostnames, Cloudlets, DNS integrations, origin connectivity, caching, and delivery configurations.
- Troubleshoot HTTP response codes, cache behavior, DNS routing, origin connectivity, TLS/SSL, and application availability issues.
- Onboard websites and APIs to the enterprise WAF/CDN platform and perform pre-production validation, testing, and post-change verification.
- Support public TLS certificate validation, issuance, deployment, renewal, revocation, replacement, inventory tracking, and post-deployment troubleshooting.
- Participate in incident response, production troubleshooting, approved mitigations, change management, escalation, and the global on-call rotation.
- Develop and maintain basic scripts and tools using Python, PowerShell, Bash, or REST APIs and improve monitoring, reporting, inventory, dashboards, and onboarding automation.
- Create technical documentation, troubleshooting guides, operational procedures, runbooks, and certificate, WAF, application ownership, and exception records.
- Support PCI DSS, internal audits, security reviews, control assessments, and remediation activities related to audits, vulnerability assessments, penetration testing, and security reviews.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
- 2–4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
- Foundational understanding of HTTP/HTTPS, TLS/SSL, DNS, TCP/IP, web applications, REST APIs, reverse proxies, and CDN concepts.
- Familiarity with Web Application Firewall technologies, web application security concepts, common web threats, and the OWASP Top 10.
- Experience troubleshooting technical issues using logs and diagnostic information and following issues through resolution.
- Strong written and verbal communication skills and the ability to learn new security technologies and platforms.
- Preferred hands-on experience with Akamai or similar WAF/CDN platforms, including App & API Protector, Property Manager, Certificate Manager, Edge DNS, Cloudlets, or Bot Manager.
- Preferred experience managing public TLS certificates; working with AWS, Azure, or GCP; using SIEM or log analysis platforms such as Splunk or Sentinel; and working with REST APIs.
- Preferred basic scripting experience with Python, PowerShell, or Bash and familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
- Security certifications such as Security+, GSEC, Akamai certifications, or equivalent technical certifications are preferred.
Benefits
- Annual salary range of $106,600 to $146,500 with bonus eligibility.
- Pay may vary based on location, experience, and other job-related factors.
- Participation in a global on-call rotation is required.
About Yum! Brands, Inc.
Yum! Brands is a publicly traded restaurant company that operates and franchises KFC, Taco Bell, Pizza Hut, and The Habit Burger Grill for consumers worldwide. Its model centers on franchising, digital ordering, and delivery platforms, with corporate teams supporting marketing, supply chain, and enterprise technology. The company was formed in 1997 and is headquartered in Louisville, Kentucky, with thousands of restaurants across more than 150 countries.