
Leading company in the technology industry
Security Engineer III
Responsibilities
-
Partner with US teams to provide security guidance as a subject matter expert around application security and operate YUM! application security services for the brand.
-
Aligning with a risk-based approach, collaborate with third-party engineers, and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across YUM! systems. These include e-commerce websites, e-commerce mobile apps, and restaurant operations apps.
-
Leveraging established YUM! security services, review vulnerability scanner reports/results and work with application and/or engineering teams to communicate and address/remediate issues. This includes ensuring adherence to established remediation timelines, including recommending and monitoring remediation activities.
-
Maintain the brand’s application security scan profiles and scan policies as per baseline standards across scanning tools for containers, SAST, DAST, and crowd sourced pen testing. This will include reviewing findings of security scans and onboarding new applications into scanning tools or services.
-
Conduct awareness campaigns with engineering teams to ensure application development adheres to YUM! Global Technology Risk Management development standards.
-
Continuously monitor published vulnerabilities for various applications, operating systems, and databases. Based on the publicly disclosed vulnerabilities determine the remediation priority and engage the stakeholders. Review the solution by re-scanning the disclosed vulnerabilities. (Familiar with OWASP Top 10, etc.)
-
Conduct threat modeling exercises to identify potential risks at the design and architecture stages and provide guidance to development teams in secure design and best practices.
-
Coordinate with incident response teams to contain, remediate, and perform root cause analysis on security incidents affecting applications.
Minimum Requirements:
- Bachelor's degree and at least 6-8 years of experience in cybersecurity and/or software development. Additional years of relevant cybersecurity or development experience may be considered in lieu of bachelor's degree.
- Experience with reviewing application cybersecurity vulnerabilities for risk and relevance as well as in vulnerability mitigations/remediation planning, for identified vulnerabilities
- Able to successfully communicate with technical personnel and third parties.
- Knowledge of continuous integration and continuous delivery platforms
- Familiarity with relevant compliance and data privacy regulations (e.g. PCI DSS, GDPR, CCPA) and how they impact application security with the ability to incorporate compliance requirements into security testing and remediation processes.
- Knowledge of common programming languages and paradigms ( OOP, functional, concurrent, etc)
- Knowledge of cloud environment topics including secrets management, infrastructure as code, and serverless technologies
- Knowledge of CI/CD techniques and build/deployment pipeline technologies
- Knowledge of application scanning tools using both dynamic and static techniques
- Knowledge of containers and container management tools (e.g. Docker, Kubernetes) including how to interpret and remediate security findings and best practices for securing container images and deployments.
- Knowledge of HTTP communication
- Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)
Preferred Requirements
- Knowledge of cloud environment topics including secrets management, infrastructure as code, and serverless technologies
- Knowledge of CI/CD techniques and build/deployment pipeline technologies
- Knowledge of application scanning tools using both dynamic and static techniques
- Knowledge of containers and container management tools (e.g. Docker, Kubernetes) including how to interpret and remediate security findings and best practices for securing container images and deployments.
- Knowledge of HTTP communication
Knowledge of package management tools for languages and operating systems (e.g. npm, pip, apt, yum)
BTECH - Computer Since / Information Technology:
Security Engineer III:
Level 7
전체 조회수
0
전체 지원 클릭
0
전체 Mock Apply
0
전체 스크랩
0
비슷한 채용공고

Senior Cyber Security Engineer – IAM
Maersk · India, Bengaluru, 560064

Senior Security Architect
Nokia · India, IN

Senior Cyber Manager - Threat Exposure Management
Maersk · India, Bengaluru, 560064

Senior Product Security Engineer
Thomson Reuters · India

Senior Security Researcher
Microsoft · India, Telangana, Hyderabad; India, Karnataka, Bangalore
Yum! Brands 소개

Yum! Brands
PublicYum! Brands, Inc. is an American multinational fast food corporation. Based in Louisville, Kentucky, the company operates KFC, Pizza Hut, Taco Bell, Habit Burger & Grill, and several technology companies. Yum! is one of the world's largest fast food restaurant companies in terms of system units.
10,001+
직원 수
Louisville
본사 위치
$40B
기업 가치
리뷰
10개 리뷰
3.7
10개 리뷰
워라밸
3.2
보상
3.5
문화
4.1
커리어
2.8
경영진
2.9
68%
지인 추천률
장점
Flexible schedule/hours
Supportive management and colleagues
Good team environment and culture
단점
Limited career advancement opportunities
Management communication issues
Pay could be better
연봉 정보
117개 데이터
Junior/L3
Junior/L3 · Cybersecurity Analyst
0개 리포트
$123,000
총 연봉
기본급
-
주식
-
보너스
-
$105,000
$142,000
면접 후기
후기 47개
난이도
3.7
/ 5
소요 기간
14-28주
합격률
38%
경험
긍정 65%
보통 25%
부정 10%
면접 과정
1
Phone Screen
2
Technical Interview
3
System Design
4
Behavioral
5
Team Fit
자주 나오는 질문
Tell me about a challenging project
System design question
Coding problem
Why this company
최근 소식
On Verge of Potential Sale, Pizza Hut Remains a Brand in Transition - QSR Magazine
QSR Magazine
News
·
1w ago
Yummy No More! Yum! Brands Stock (YUM) Rises on Plan to Sell Pizza Hut - TipRanks
TipRanks
News
·
2w ago
Yum! Brands explores Pizza Hut sale amid turnaround push - MSN
MSN
News
·
2w ago
Pizza Hut needs a bold change, and a sale of the business is on the table - Yahoo Finance
Yahoo Finance
News
·
2w ago