EngineerJobs.io
← Back to all jobs

Job Description

Help strengthen application security across web, mobile, and restaurant technology environments for Yum! Brands in Louisville, KY.

Responsibilities

  • Act as a subject matter expert for application security, partnering with US teams and operating YUM! application security services.
  • Use a risk-based approach to collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities across mobile and web applications.
  • Support security reviews across YUM! systems, including e-commerce websites, e-commerce mobile apps, and restaurant operations applications.
  • Review vulnerability findings using established YUM! security services and work with engineering teams to communicate, prioritize, and remediate issues.
  • Analyze findings to determine root cause, exploitability, business impact, and remediation strategy, while adhering to established remediation timelines.
  • Maintain application security scan profiles and scan policies in line with baseline standards across:
    • SAST
    • DAST
    • Software Composition Analysis (SCA)
    • Container security
    • Infrastructure as Code (IaC)
    • Secrets detection
    • Crowd-sourced penetration testing platforms
  • Onboard new applications into security services and continuously improve scan coverage and effectiveness.
  • Partner with development teams to integrate security into the software development lifecycle (SDLC), including:
    • Secure coding practices
    • Pull request workflows
    • Automated security testing
    • Software supply chain security
    • Secure release processes
  • Run engineering awareness campaigns to promote secure software development practices and alignment with YUM! Global Technology Risk Management standards.
  • Continuously monitor publicly disclosed vulnerabilities impacting applications, frameworks, libraries, operating systems, and third-party dependencies; assess business risk, prioritize remediation, validate fixes via rescanning, and communicate recommendations.
  • Coordinate with incident response teams to support containment, remediation, and root cause analysis for application security incidents.

Requirements

  • Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development.
  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
  • Proven ability to collaborate with software engineering teams and communicate technical concepts to both technical and non-technical audiences.
  • Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.
  • Familiarity with relevant compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and how they influence application security testing and remediation.

Technical Qualifications

  • Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management practices.
  • Knowledge of CI/CD pipelines and build automation, including how security testing is integrated into software delivery.
  • Knowledge of application security testing methodologies including:
    • SAST
    • DAST
    • SCA
    • Secrets detection
    • Container security scanning
    • IaC security testing
  • Knowledge of secure coding principles and common software vulnerabilities, including OWASP Top 10, secure authentication, authorization, input validation, output encoding, and session management.
  • Knowledge of web and application communication fundamentals: HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, and Content Security Policy (CSP).
  • Knowledge of authentication and authorization technologies: OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and RBAC.
  • Knowledge of package management ecosystems and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials (SBOMs), and package integrity (e.g., npm, pip, NuGet, Maven, Gradle).
  • Knowledge of containers and container management (e.g., Docker and Kubernetes), including image security best practices and interpreting container security findings.
  • Knowledge of Infrastructure as Code technologies (e.g., Terraform, CloudFormation) and secure configuration practices.
  • Ability to investigate security findings beyond automated scanner output, including understanding underlying technologies, validating exploitability, and recommending practical remediation approaches.

Preferred Qualifications

  • Experience developing software in one or more modern programming languages (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).
  • Experience securing applications within Git-based DevSecOps environments.
  • Experience integrating application security controls into CI/CD pipelines.
  • Familiarity with AI-assisted software development tools and the security considerations associated with AI-generated code and automated code review.

Location & Compensation

  • Location: Louisville, KY (onsite)
  • Salary: USD 106,600 - 146,500 per year

Similar Jobs