
McDonald's Corporation, doing business as McDonald's, is an American multinational fast food restaurant chain
Cyber Engineer III - API Security
Required skills
Python
TypeScript
Terraform
The Senior Engineer, Application & API Security is a key member of the E-WAAP team and serves as a technical lead for our Akamai-based web and API security platform. You will:
- Lead onboarding of new applications and APIs onto Akamai (WAF, CDN, bot, and API security capabilities).
- Design and tune security policies to protect against OWASP Top 10, API abuse, bots, and DDoS while preserving performance and user experience.
- Partner with product teams, developers, and cloud teams to embed E-WAAP into CI/CD and Dev Sec Ops workflows.
This role reports into the G5 Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to G3 Engineers and G2/G3 Analysts as we in-source capabilities from our managed services provider.
Responsibilities & Accountabilities:
-
Platform engineering & design- Lead the onboarding of new web and API workloads to Akamai, from discovery and architecture review to staging, validation, and production cutover.
-
Design and implement WAF, bot management, DDoS, and rate-limiting policies tailored to application risk profiles and business requirements.
-
Build reusable configuration patterns, templates, and reference architectures for common Mc Donald’s application types (e.g., marketing sites, e-commerce, APIs, partner integrations).
-
Use Akamai APIs, automation frameworks, and infrastructure-as-code (e.g., Terraform, Python, CI/CD pipelines) to manage configurations at scale.
-
Security operations & tuning- Lead incident triage and investigations for WAF, API, and bot-related events; coordinate containment, tuning, and long-term fixes.
-
Analyze WAF and CDN logs to identify attacks, false positives, and evasion attempts; refine policies, exception sets, and custom rules.
-
Collaborate with Security Operations, Threat Intelligence, and product security teams to map emerging threats into new or updated rulesets.
-
Drive continuous improvement in detection quality, block rates, and false-positive reduction while maintaining performance SLAs.
-
Dev & automation focus- Partner with developers to integrate Akamai security checks into CI/CD (e.g., automated policy promotions, pre-prod validation jobs, automated regression checks).
-
Develop internal tools and scripts (Python, Bash, TypeScript, etc.) to streamline common workflows (policy cloning, bulk updates, configuration linting).
-
Provide technical requirements and guidance into product roadmaps for observability, logging, and security analytics.
-
Governance, metrics, and leadership- Own platform health and risk metrics (coverage, rule adoption, false positives, incident volume, MTTR) and present them regularly to leadership and stakeholders.
-
Lead operational governance forums with product teams to review posture, tuning backlog, and upcoming changes.
-
Mentor and coach G3 Engineers and Analysts; provide guidance on investigations, change reviews, and documentation.
-
Contribute to and lead updates of SOPs, intake processes, runbooks, and standards for Akamai and E-WAAP.
Qualifications
- Bachelor’s degree in computer science, Engineering, Information Technology, or equivalent experience.
- Knowledge of Agile software development process including application of Agile techniques and delivery practices and promoting adoption of Agile methodologies to secure outcome-driven mindset in product teams.
- Experience working with large-scale, global, high-availability platforms (CDN, edge, or cloud) where performance and latency are critical.
- Prior experience with Akamai APIs, Terraform, or other infrastructure-as-code tools for managing Akamai configurations at scale.
- Familiarity with SIEM/SOAR tools and log analysis for WAF and CDN events.
- Industry certifications in security or cloud (e.g., CISSP, CCSP, GIAC, cloud provider security certifications).
Additional Information
Mc Donald’s is committed to providing qualified individuals with reasonable accommodations to perform the essential functions of their jobs. Additionally, if you (or another applicant of whom you are aware) require assistance accessing or reading this job posting or otherwise seek assistance in the application process, please contact recruiting.supportteam@us.mcd.com
Mc Donald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
Nothing in this job posting or description should be construed as an offer or guarantee of employment.
Total Views
0
Total Apply Clicks
0
Total Mock Apply
0
Total Bookmarks
0
Similar jobs

Business Development and Partnerships Lead, LATAM
Duolingo · Remote - Mexico City

Senior Developer - Manufacturing Process
HCL Technologies · Juarez, Mexico

Senior UW Assistant
AIG · Mexico City

Senior Project Engineer
ABB · Apodaca, Nuevo León, Mexico

Principal Statistical Programmer (Clinical Trials)
IQVIA · Mexico City, Mexico
About McDonald's

McDonald's
PublicMcDonald's Corporation, doing business as McDonald's, is an American multinational fast food restaurant chain. As of 2024, it is the largest by revenue and second-largest by number of locations in the world, behind the Chinese chain Mixue Ice Cream & Tea.
10,001+
Employees
Chicago
Headquarters
$200B
Valuation
Reviews
10 reviews
3.1
10 reviews
Work-life balance
3.2
Compensation
2.1
Culture
3.8
Career
2.3
Management
2.5
45%
Recommend to a friend
Pros
Flexible hours/schedule
Friendly coworkers/staff
Good learning/training opportunities
Cons
Low pay/compensation
Limited career advancement/growth
Stressful environment/rush hours
Salary Ranges
24,181 data points
Junior/L3
Mid/L4
Senior/L5
Junior/L3 · Analyst, Cybersecurity Operations
1 reports
$140,400
total per year
Base
$108,000
Stock
-
Bonus
-
$140,400
$140,400
Interview experience
3 interviews
Difficulty
3.3
/ 5
Duration
14-28 weeks
Experience
Positive 0%
Neutral 33%
Negative 67%
Interview process
1
Application Review
2
HR Screen
3
Hiring Manager Interview
4
Panel Interview
5
Offer
Common questions
Behavioral/STAR
Past Experience
Culture Fit
Customer Service Scenarios
Availability/Scheduling
Latest updates
No, McDonald’s AI bot didn’t go rogue, but ‘prompt injection’ is still a risk for companies - Fast Company
Fast Company
News
·
1w ago
McDonald’s franchisee reveals secret science behind why their Coke tastes better than anyone else’s - Yahoo
Yahoo
News
·
1w ago
McDonald's unveils 'Stranger Things'-inspired Happy Meal. See the toys - USA Today
USA Today
News
·
1w ago
CEO: Pricy Beef Moving McDonald’s Toward More Chicken, ‘Elevated’ Burgers - Meatingplace
Meatingplace
News
·
1w ago