For Employers

Yum!

Application Security Engineer

Posted 3 days ago
$106K - $146K per year
2-5 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

The Application Security Engineer will partner with engineering and product teams to identify, prioritize, and remediate vulnerabilities across web, mobile, and restaurant technology environments. They will also integrate security practices into the software development lifecycle and manage application security scanning policies.

The Application Security Engineer will help strengthen application security across web, mobile, and restaurant technology environments by partnering closely with engineering, product, and security teams. This role will focus on identifying, assessing, prioritizing, and remediating application vulnerabilities while supporting the integration of security throughout the software development lifecycle. The engineer will also help manage application security testing and scanning practices, provide guidance on secure development, monitor emerging vulnerabilities, and communicate security risks and remediation recommendations to both technical and non-technical stakeholders.

Responsibilities

Primary Responsibilities

  • Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.

  • Aligning with a risk-based approach, collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations applications.

  • Leverage established YUM! security services to review vulnerability findings and work closely with engineering teams to communicate, prioritize, and remediate security issues. Analyze findings to determine root cause, exploitability, business impact, and appropriate remediation strategies while ensuring adherence to established remediation timelines.

  • Maintain the brand's application security scan profiles and scan policies in accordance with baseline standards across SAST, DAST, software composition analysis (SCA), container security, Infrastructure as Code (IaC), secrets detection, and crowd-sourced penetration testing platforms. Onboard new applications into security services and continuously improve scan coverage and effectiveness.

  • Partner with development teams to integrate security into the software development lifecycle (SDLC), including secure coding practices, pull request workflows, automated security testing, software supply chain security, and secure release processes.

  • Conduct awareness campaigns with engineering teams to promote secure software development practices and adherence to YUM! Global Technology Risk Management standards.

  • Continuously monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies. Assess business risk, prioritize remediation activities, validate fixes through rescanning, and communicate recommendations to stakeholders.

  • Coordinate with incident response teams to contain, remediate, and perform root cause analysis on application security incidents.

Qualifications

Basic Qualifications

  • Bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development. Additional years of relevant experience may be considered in lieu of a bachelor's degree.

  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.

  • Experience collaborating effectively with software engineering teams and communicating technical concepts to both technical and non-technical audiences.

  • Familiarity with secure software development lifecycle (SSDLC) practices and modern software delivery methodologies.

  • Familiarity with relevant compliance and data privacy regulations (e.g., PCI DSS, GDPR, CCPA) and how they influence application security testing and remediation activities.

Technical Qualifications

  • Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management practices.

  • Knowledge of CI/CD pipelines, build automation, and deployment technologies, including how security testing integrates into modern software delivery.

  • Knowledge of application security testing methodologies including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), secrets detection, container security scanning, and Infrastructure as Code (IaC) security testing.

  • Knowledge of secure coding principles and common software vulnerabilities, including the OWASP Top 10, secure authentication, authorization, input validation, output encoding, session management, and common web application attack techniques.

  • Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, Content Security Policy (CSP), and common web communication protocols.

  • Knowledge of modern authentication and authorization technologies including OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and role-based access control (RBAC).

  • Knowledge of package management ecosystems (e.g., npm, pip, NuGet, Maven, Gradle) and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials (SBOMs), and package integrity.

  • Knowledge of containers and container management technologies (e.g., Docker and Kubernetes), including container image security best practices and interpretation of container security findings.

  • Knowledge of Infrastructure as Code technologies (e.g., Terraform, CloudFormation) and secure configuration practices.

  • Ability to investigate security findings beyond automated scanner output by understanding underlying technologies, validating exploitability, and recommending practical remediation approaches.

 

Preferred Qualifications

  • Experience developing software in one or more modern programming languages (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).

  • Experience securing applications within Git-based DevSecOps environments.

  • Experience integrating application security controls into CI/CD pipelines.

  • Familiarity with AI-assisted software development tools and the security considerations associated with AI-generated code and automated code review.

Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we'll consider the successful candidate’s location, experience, and other job-related factors.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Senior Oracle Forms & APEX Engineer

Full Time Hungary, United Kingdom Software Development

Senior Software Engineer

Full Time Hungary Software Development

Senior Full Stack Developer for CubiCasa Tour

Full Time Finland Software Development

Director of Analytics and Data Science

Full Time United States Software Development

UPS Field Engineer- GA

Full Time United States $75000 - $110K per year Software Development

Java Engineer

Full Time Italy Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 222,178+ Jobs in Application Security Engineer

Answer easy questions

Answer easy questions

222,178+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified