×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity Engineer III T500-23510

Job in 500001, Hyderabad, Telangana, India
Listing for: McDonald's Global Office in India
Full Time, Part Time position
Listed on 2026-02-23
Job specializations:
  • IT/Tech
    Cybersecurity, Cloud Computing
Job Description & How to Apply Below
Position: Cybersecurity Engineer III [T500-23510]
About McDonald’s:

One of the world’s largest employers with locations in more than 100 countries, McDonald’s Corporation has corporate opportunities in Hyderabad. Our global offices serve as dynamic innovation and operations hubs, designed to expand McDonald's global talent base and in-house expertise. Our new office in Hyderabad will bring together knowledge across business, technology, analytics, and AI, accelerating our ability to deliver impactful solutions for the business and our customers across the globe.

Senior Engineer, External Application & API Security – E-WAAP

- Global Grade: G4
- Office

Location:

India
- Part Time / Full-Time:
Full Time

Company

Description:

McDonald’s new growth strategy, Accelerating the Arches, is built on our ambition to Double Down on the 3

Ds:
Delivery, Digital, and Drive-Thru. Technology is at the center of this strategy, enabling 65M+ customers each day to enjoy fast, easy, and secure experiences across web, mobile, and restaurant channels.

The Global Technology organization designs, builds, and operates the platforms behind our global omni-channel experience. Within Global Technology, Global Cybersecurity Services (GCS) protects McDonald’s customers, crew, and brand by securing our digital ecosystem end-to-end.

The External Web Application and API Protection (E-WAAP) team is responsible for securing McDonald’s external web and API surfaces across web, mobile, and partner integrations using Akamai’s edge security platform (WAF, bot management, DDoS, CDN, and API security).

Job Description:

The Senior Engineer, Application & API Security is a key member of the E-WAAP team and serves as a technical lead for our Akamai-based web and API security platform. You will:

- Lead onboarding of new applications and APIs onto Akamai (WAF, CDN, bot, and API security capabilities).
- Design and tune security policies to protect against OWASP Top 10, API abuse, bots, and DDoS while preserving performance and user experience.
- Partner with product teams, developers, and cloud teams to embed E-WAAP into CI/CD and Dev Sec Ops  workflows.

This role reports into the G5 Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to G3 Engineers and G2 / G3 Analysts as we in-source capabilities from our managed services provider.

Responsibilities & Accountabilities:

Platform engineering & design:

- Lead the onboarding of new web and API workloads to Akamai, from discovery and architecture review to staging, validation, and production cutover.
- Design and implement WAF, bot management, DDoS, and rate-limiting policies tailored to application risk profiles and business requirements.
- Build reusable configuration patterns, templates, and reference architectures for common McDonald’s application types (e.g., marketing sites, e-commerce, APIs, partner integrations).
- Use Akamai APIs, automation frameworks, and infrastructure-as-code (e.g., Terraform, Python, CI/CD pipelines) to manage configurations at scale.

Security operations & tuning:

- Lead incident triage and investigations for WAF, API, and bot-related events; coordinate containment, tuning, and long-term fixes.
- Analyze WAF and CDN logs to identify attacks, false positives, and evasion attempts; refine policies, exception sets, and custom rules.
- Collaborate with Security Operations, Threat Intelligence, and product security teams to map emerging threats into new or updated rulesets.
- Drive continuous improvement in detection quality, block rates, and false-positive reduction while maintaining performance SLAs.

Dev & automation focus:

- Partner with developers to integrate Akamai security checks into CI/CD (e.g., automated policy promotions, pre-prod validation jobs, automated regression checks).
- Develop internal tools and scripts (Python, Bash, Type Script, etc.) to streamline common workflows (policy cloning, bulk updates, configuration linting).
- Provide technical requirements and guidance into product roadmaps for observability, logging, and security analytics.

Governance, metrics, and leadership:

- Own platform health and risk metrics (coverage, rule adoption, false positives, incident volume, MTTR) and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary