CybersecurityJobs.io
← Back to all jobs

Job Description

Yum! Brands is seeking an Application Security Engineer to strengthen security across web, mobile, and restaurant technology environments. In this onsite role in Louisville, KY, you will help identify, assess, prioritize, and remediate application vulnerabilities while integrating security into the software development lifecycle.

This position focuses on application security testing and scanning, continuous monitoring of emerging vulnerabilities, and clear risk communication to technical and non-technical stakeholders. You will also work across engineering and incident response to support containment, remediation, and root cause analysis when application security incidents occur.

What you’ll do

  • Act as a subject matter expert on application security for US teams and operate YUM! application security services for the brand.
  • Use a risk-based approach to work with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems, including e-commerce websites, e-commerce mobile apps, and restaurant operations applications.
  • Review vulnerability findings using established YUM! security services, coordinate with engineering teams to communicate and remediate issues, and analyze findings for root cause, exploitability, business impact, and remediation strategies aligned to established timelines.
  • Maintain application security scan profiles and scan policies across baseline standards for SAST, DAST, Software Composition Analysis (SCA), container security, Infrastructure as Code (IaC), secrets detection, and crowd-sourced penetration testing platforms; onboard new applications and improve scan coverage and effectiveness.
  • Partner with development teams to integrate security into the SDLC, including secure coding practices, pull request workflows, automated security testing, software supply chain security, and secure release processes.
  • Support engineering awareness campaigns promoting secure software development practices and adherence to YUM! Global Technology Risk Management standards.
  • Continuously monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies; assess business risk, prioritize remediation, validate fixes through rescanning, and communicate recommendations to stakeholders.
  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis for application security incidents.

Minimum qualifications

  • Bachelor’s degree and at least 4 years of experience in cybersecurity, software engineering, or application development.
  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
  • Experience collaborating with software engineering teams and communicating technical topics to both technical and non-technical audiences.
  • Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.
  • Familiarity with relevant compliance and data privacy regulations, such as PCI DSS, GDPR, and CCPA, and how they influence application security testing and remediation.

Core technical focus

  • Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management.
  • CI/CD pipelines and build automation, including how security testing integrates into modern software delivery.
  • Application security testing methodologies: SAST, DAST, SCA, secrets detection, container security scanning, and IaC security testing.
  • Secure coding principles and common vulnerabilities aligned to OWASP Top 10, including secure authentication, authorization, input validation, output encoding, and session management.
  • Web communication fundamentals such as HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, and Content Security Policy (CSP).
  • Modern authentication and authorization technologies including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and RBAC.
  • Package management ecosystems (npm, pip, NuGet, Maven, Gradle) and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials (SBOMs), and package integrity.
  • Container and orchestration technologies, including Docker and Kubernetes, and the ability to interpret container security findings.
  • Infrastructure as Code technologies such as Terraform and CloudFormation, including secure configuration practices.
  • Ability to investigate beyond automated scanner output by validating exploitability and recommending practical remediation approaches.

Salary: USD 106,600 to 146,500 per year. Location: Louisville, KY (onsite).

Similar Jobs