Application Security Engineer @Yum!
Software Development
Salary usd 106,600 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4d ago

[Hiring] Application Security Engineer @Yum!

4d ago - Yum! is hiring a remote Application Security Engineer. πŸ’Έ Salary: usd 106,600 - 146,500 per year πŸ“Location: USA

Role Description

The Application Security Engineer will help strengthen application security across web, mobile, and restaurant technology environments by partnering closely with engineering, product, and security teams. This role will focus on identifying, assessing, prioritizing, and remediating application vulnerabilities while supporting the integration of security throughout the software development lifecycle. The engineer will also help manage application security testing and scanning practices, provide guidance on secure development, monitor emerging vulnerabilities, and communicate security risks and remediation recommendations to both technical and non-technical stakeholders.

Responsibilities

  • Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
  • Aligning with a risk-based approach, collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems.
  • Leverage established YUM! security services to review vulnerability findings and work closely with engineering teams to communicate, prioritize, and remediate security issues.
  • Maintain the brand's application security scan profiles and scan policies in accordance with baseline standards.
  • Partner with development teams to integrate security into the software development lifecycle (SDLC).
  • Conduct awareness campaigns with engineering teams to promote secure software development practices.
  • Continuously monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies.
  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis on application security incidents.

Qualifications

  • Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development.
  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
  • Experience collaborating effectively with software engineering teams and communicating technical concepts to both technical and non-technical audiences.
  • Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.
  • Familiarity with relevant compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA).

Technical Qualifications

  • Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management practices.
  • Knowledge of CI/CD pipelines, build automation, and deployment technologies.
  • Knowledge of application security testing methodologies including SAST, DAST, SCA, secrets detection, container security scanning, and IaC security testing.
  • Knowledge of secure coding principles and common software vulnerabilities, including the OWASP Top 10.
  • Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, CSP, and common web communication protocols.
  • Knowledge of modern authentication and authorization technologies including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and RBAC.
  • Knowledge of package management ecosystems (e.g., npm, pip, NuGet, Maven, Gradle) and software supply chain security concepts.
  • Knowledge of containers and container management technologies (e.g., Docker and Kubernetes).
  • Knowledge of Infrastructure as Code technologies (e.g., Terraform, CloudFormation) and secure configuration practices.
  • Ability to investigate security findings beyond automated scanner output.

Preferred Qualifications

  • Experience developing software in one or more modern programming languages (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).
  • Experience securing applications within Git-based DevSecOps environments.
  • Experience integrating application security controls into CI/CD pipelines.
  • Familiarity with AI-assisted software development tools and the security considerations associated with AI-generated code.

Salary Range

$106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Application Security Engineer @Yum!
Software Development
Salary usd 106,600 - 1..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4d ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,323+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later