More jobs:
Sr External Web Application & API Security Engineer
Job in
Chicago, Cook County, Illinois, 60684, USA
Listed on 2026-08-30
Listing for:
McDonald's
Full Time
position Listed on 2026-08-30
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
Company
Description:
McDonald's growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3
Ds (Delivery, Digital and Drive Thru). McDonald's will accelerate technology innovation so 65M+ customers a day will experience a fast, easy experience, whether at one of our 25,000 and growing Drive thrus, through McDelivery, dine-in or takeaway.
McDonald's Global Technology is here to power tomorrow's feel-good moments.
That's why you'll find us at the forefront of transformative technology, exploring new and innovative ways to serve our millions of customers and spread happiness one delicious Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and emerging tech, we're digitizing the Golden Arches. Combine that with our unparalleled global scale, and we're reshaping all areas of the business, industry and every community that is home to a McDonald's restaurant. We
face complex tech challenges every day. But that's where our diverse and talented teams come in. They're made up of the best and brightest from all over the globe, and they thrive in the space where feel-good meets fast-paced.
Check out the McDonald's Global Technology Technical Blog () to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.
Department Overview
The Senior Engineer, External Web Application & API Security is a hands-on technical lead responsible for enterprise API security and web application protection.
You will:
+ Lead the engineering and operationalization of API discovery, posture management, and runtime protection capabilities across cloud, on-premises, and partner environments.
+ Design, operate, and tune WAF and edge security controls for high-availability digital services.
+ Assess and reduce API risk related to authorization failures, authentication weaknesses, excessive data exposure, business logic abuse, injection, automation, and other OWASP API Security Top 10 risks.
+ Design and tune WAF, rate-limiting, bot management, DDoS, and edge security controls for applications and APIs, with a strong focus on accuracy, resiliency, and low false-positive rates.
+ Automate repeatable security workflows and embed validation into CI/CD and Dev Sec Ops processes.
This role reports into the Senior Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to Engineers and Analysts as we in-source capabilities from our managed services provider.
Responsibilities & Accountabilities
API Security Engineering and Architecture
+ Lead API discovery, inventory, classification, and ownership mapping across external, internal, partner, and cloud-hosted APIs, including identification of shadow, zombie, and unmanaged APIs.
+ Operate and improve enterprise API security capabilities for posture management, runtime detection, attacker behavior analysis, and risk prioritization.
+ Assess REST, GraphQL, SOAP, gRPC, and event-driven APIs for OWASP API Security Top 10 risks, authentication and authorization weaknesses, excessive data exposure, schema and input-validation gaps, rate-control issues, and differences between documented and observed behavior.
+ Partner with API owners and engineering teams to prioritize findings and implement practical remediation or compensating controls.
+ Develop reusable API security patterns and reference architectures for customer-facing, mobile, partner, microservice, and third-party integrations.
Runtime API Protection and Security Operations
+ Analyze API telemetry, tune behavioral detections, and lead incident investigation and containment for credential abuse, token misuse, scraping, enumeration, account takeover, authorization bypass, data exfiltration, and business logic abuse.
+ Integrate API security events and findings with SIEM, SOAR, ticketing, and case-management workflows to support centralized monitoring, response, and remediation tracking.
+ Define and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×