×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Security Engineer, Web Application Security

Job in Washington, District of Columbia, 20022, USA
Listing for: your Jared
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 107000 - 147000 USD Yearly USD 107000.00 147000.00 YEAR
Job Description & How to Apply Below
Position: Security Engineer, Web Application Security (5583)

Building global, iconic brands people trust and champion

YUM!

Remote

Position Summary

We are seeking a Security Engineer to join Yum! Brands' Cybersecurity Engineering organization and help protect the web applications and APIs supporting our global digital ecosystem across KFC, Taco Bell, Pizza Hut, Habit Burger & Grill, and Yum! corporate platforms.

This role will support the operation and continuous improvement of Web Application Firewall (WAF), Content Delivery Network (CDN), API security, and digital certificate management services. The engineer will work with technologies such as Akamai App & API Protector, Akamai CDN, Certificate Manager, and other web security platforms to help protect internet-facing applications from cyber threats while maintaining application availability and performance.

The ideal candidate has a strong technical foundation in networking, web technologies, or cybersecurity and is interested in developing deeper expertise in web application security, CDN technologies, APIs, and certificate management.

This role will work closely with senior engineers and cross-functional teams to troubleshoot issues, onboard applications, respond to security events, implement security changes, maintain certificates, and improve operational processes.

Primary Responsibilities Web Application Security
  • Configure, maintain, and support Web Application Firewall (WAF) protections using Akamai App & API Protector and related security technologies.
  • Monitor and investigate web security events involving:
  • Other suspicious or malicious web traffic
  • Layer 7 attacks
  • DDoS attacks
  • Credential stuffing
  • Bot traffic
  • API attacks
  • OWASP Top 10 vulnerabilities
  • Assist with WAF policy tuning to reduce false positives while maintaining appropriate security protections.
  • Review application traffic and security logs to identify attack patterns, application behavior, and potential security concerns.
  • Implement approved WAF policy changes, exceptions, allow lists, and security configuration updates.
  • Support senior engineers during complex security investigations and production incidents.
CDN & Edge Security
  • Configure and maintain CDN and edge security configurations supporting internet-facing applications.
  • Work with Akamai technologies including:
  • Caching and delivery configurations
  • Origin connectivity
  • DNS integrations
  • Cloudlets
  • Edge Hostnames
  • Property Manager
  • Troubleshoot common CDN and web application issues involving:
  • Application availability
  • TLS/SSL
  • Origin connectivity
  • Routing
  • DNS
  • Cache behavior
  • HTTP response codes
  • Support the onboarding of new websites and APIs onto the enterprise WAF/CDN platform.

Perform pre-production validation, testing, and post-change verification.

Certificate Lifecycle Management
  • Support the lifecycle management of public TLS certificates, including:
  • Replacement
  • Revocation
  • Renewal
  • Deployment
  • Issuance
  • Request validation
  • Monitor certificate inventories and upcoming expiration dates.
  • Coordinate certificate changes and renewals with application owners and other technical teams.
  • Validate certificates after deployment and troubleshoot common certificate, trust chain, DNS validation, and TLS issues.
  • Maintain accurate certificate ownership and lifecycle documentation.
  • Escalate certificate risks or renewal issues before they can impact production applications.
Security Operations & Incident Response
  • Monitor and investigate WAF alerts, application issues, and security events.
  • Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other available telemetry to assist with troubleshooting and investigations.
  • Participate in incident response activities involving WAF, CDN, DDoS, certificates, and internet-facing applications.
  • Assist with troubleshooting customer-impacting production issues and determining whether issues originate…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary