Security Engineer III
Yum! Brands · India ·
- Work mode
- Hybrid
- Category
- Security
- Experience
- 6+ years
Yum! Brands · India ·
xai · Palo Alto, CA; Austin, TX; New York, NY; Washington, DC
Clarity Innovations · Fort Meade, MD
snapchat · Los Angeles, California
Grayscale Investments Sponsors, LLC · Stamford, Connecticut, United States
Security Engineer III at Yum! Brands partners with US teams to secure YUM! applications (e-commerce, mobile apps, restaurant ops) by reviewing vulnerabilities, enforcing security policies, and guiding remediation using SAST/DAST, containers, and CI/CD.
Responsibilities
Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
Aligning with a risk-based approach, collaborate with third-party engineers, and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations apps.
Leveraging established YUM! security services, review vulnerability scanner reports/results and work with application and/or engineering teams to communicate and address/remediate issues. This includes ensuring adherence to established remediation timelines, including recommending and monitoring remediation activities.
Maintain the brand’s application security scan profiles and scan policies as per baseline standards across scanning tools for containers, SAST, DAST, and crowd sourced pen testing. This will include reviewing findings of security scans and onboarding new applications into scanning tools or services.
Conduct awareness campaigns with engineering teams to ensure application development adheres to YUM! Global Technology Risk Management development standards.
Continuously monitor published vulnerabilities for various applications, operating systems, and databases. Based on the publicly disclosed vulnerabilities determine the remediation priority and engage the stakeholders. Review the solution by re-scanning the disclosed vulnerabilities. (Familiar with OWASP Top 10, etc.)
Conduct threat modeling exercises to identify potential risks at the design and architecture stages and provide guidance to development teams in secure design and best practices.
Coordinate with incident response teams to contain, remediate, and perform root cause analysis on security incidents affecting applications.
Minimum Requirements:
Preferred Requirements
Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)
Security Engineer III
Level 7
BTECH - Computer Since / Information Technology
Five9 · Portugal (Remote)