Full-Time

Application Security Engineer

Posted on 9/14/2026

Yum! Brands

Yum! Brands

5,001-10,000 employees

Global franchised fast-food restaurant operator

Compensation Overview

$106.6k - $146.5k/yr

+ Bonus

Louisville, KY, USA + 2 more

More locations: Plano, TX, USA | United States

In Person

Bachelor's

Category
Cybersecurity (1)
Required Skills
Kubernetes
Rust
Python
JavaScript
Incident Response
Git
Java
Gradle
Infrastructure as Code (IaC)
Docker
TypeScript
Cybersecurity
CloudFormation
Vulnerability Analysis
Role-based Access Control
C#
SAML
Go
Maven
Terraform
REST APIs
Penetration Testing
DevOps
OAuth

Get referred to Yum! Brands

See people who can refer or advise you

Requirements
  • A bachelor's degree and at least four years of experience in cybersecurity, software engineering, or application development; additional relevant experience may substitute for the bachelor's degree.
  • Experience evaluating application security vulnerabilities for exploitability, business risk, and remediation planning.
  • Experience collaborating with software engineering teams and communicating technical concepts to technical and non-technical audiences.
  • Familiarity with secure software development lifecycle practices and modern software delivery methodologies.
  • Familiarity with compliance and data privacy regulations such as PCI DSS, GDPR, and CCPA and their influence on application security testing and remediation.
  • Knowledge of Git-based development workflows, including branching strategies, pull requests, code reviews, merge approvals, and secure source code management.
  • Knowledge of CI/CD pipelines, build automation, deployment technologies, and security testing integration into software delivery.
  • Knowledge of application security testing methodologies including Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis, secrets detection, container security scanning, and Infrastructure as Code security testing.
  • Knowledge of secure coding principles and common software vulnerabilities, including the OWASP Top 10, secure authentication, authorization, input validation, output encoding, session management, and web application attack techniques.
  • Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, Content Security Policy, and common web communication protocols.
  • Knowledge of authentication and authorization technologies including OAuth 2.0, OpenID Connect, SAML, JWT, and role-based access control.
  • Knowledge of package management ecosystems such as npm, pip, NuGet, Maven, and Gradle, and software supply chain security concepts including dependency management, lock files, transitive dependencies, Software Bill of Materials, and package integrity.
  • Knowledge of containers and container management technologies such as Docker and Kubernetes, including container image security practices and interpretation of container security findings.
  • Knowledge of Infrastructure as Code technologies such as Terraform and CloudFormation and secure configuration practices.
  • Ability to investigate security findings beyond automated scanner output, validate exploitability, understand underlying technologies, and recommend practical remediation approaches.
Responsibilities
  • Partner with United States teams to provide application security guidance as a subject matter expert and operate application security services for the brand.
  • Collaborate with third-party engineers and product owners to identify, prioritize, and remediate vulnerabilities in mobile and web applications across company systems using a risk-based approach.
  • Review vulnerability findings, determine root cause, exploitability, and business impact, recommend remediation strategies, and ensure adherence to remediation timelines.
  • Maintain application security scan profiles and scan policies across Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis, container security, Infrastructure as Code, secrets detection, and crowd-sourced penetration testing platforms.
  • Onboard new applications into security services and continuously improve scan coverage and effectiveness.
  • Partner with development teams to integrate security into the software development lifecycle, including secure coding practices, pull request workflows, automated security testing, software supply chain security, and secure release processes.
  • Conduct awareness campaigns with engineering teams to promote secure software development practices and adherence to global technology risk management standards.
  • Monitor publicly disclosed vulnerabilities affecting applications, frameworks, libraries, operating systems, and third-party dependencies; assess business risk, prioritize remediation, validate fixes through rescanning, and communicate recommendations to stakeholders.
  • Coordinate with incident response teams to contain and remediate application security incidents and perform root cause analysis.
Desired Qualifications
  • Experience developing software in one or more modern programming languages, including Java, JavaScript/TypeScript, Python, C#, Go, or Rust.
  • Experience securing applications within Git-based DevSecOps environments.
  • Experience integrating application security controls into CI/CD pipelines.
  • Familiarity with AI-assisted software development tools and security considerations associated with AI-generated code and automated code review.

Yum! Brands operates a global portfolio of fast-food chains, including KFC, Taco Bell, Pizza Hut, and The Habit Burger Grill, primarily through franchising in more than 155 countries with about 61,000 restaurants. Its revenue mainly comes from franchise and license fees as well as royalties, plus some company-owned locations. The company differentiates itself by leveraging a large, multi-brand network with a franchise-heavy model that supports rapid international expansion while keeping operating costs down. Its goal is to grow its global footprint, maximize value from its brands, and continuously optimize operations and menus across markets.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

Louisville, Kentucky

Founded

1997

Get referred to Yum! Brands

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Ex-Pizza Hut system sales rose 7% in Q2 2026, excluding divested assets.
  • Yum closed Pizza Hut sales in August and September 2026, simplifying focus.
  • Digital sales excluding Pizza Hut exceeded $17 billion in first-half 2026, up 25%.

What critics are saying

  • Taco Bell's July 2026 cyclospora outbreak hit U.S. same-store sales 2%.
  • Pizza Hut sales fell for 10 straight quarters before the 2026 sale closed.
  • Tracy Skeans' retirement and COO transition in 2026 disrupt execution during portfolio reshaping.

What makes Yum! Brands unique

  • Taco Bell drives nearly half of Yum's operating profit, anchoring growth.
  • KFC added 660 restaurants across 55 markets in Q2 2026.
  • Byte by Yum! and franchise-heavy model keep capital needs structurally low.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Professional Development Budget

Mental Health Support

Growth & Insights and Company News

Headcount

6 month growth

7%

1 year growth

7%

2 year growth

7%
Kalkine Media
Sep 3rd, 2026
Thrive Tribe Technologies raises $500K through 500M share placement at $0.001 each

Thrive Tribe Technologies has raised $500,000 through a placement of 500 million new ordinary shares at $0.001 each. The Australian company announced the issuance on 3 September 2026, having received shareholder approval at an extraordinary general meeting in July. The company filed a cleansing notice under section 708A(5)(e) of the Corporations Act 2001, enabling immediate trading of the placement shares. Thrive Tribe Technologies confirmed compliance with disclosure requirements and stated no excluded information exists under the Act. The shares were issued without disclosure under Part 6D.2 of the Corporations Act. An Appendix 2A for share quotation was released to the market on the same day.

Associated Press
Aug 26th, 2026
Stonegate initiates coverage on Yum! Brands, ex-Pizza Hut sales up 7%

Stonegate Capital Partners has initiated coverage on Yum! Brands, focusing on the company's performance following its Pizza Hut operations. Excluding Pizza Hut, Yum!'s second quarter 2026 results showed system sales up 7%, units up 6%, same-store sales up 4%, and core operating profit up 8%. Taco Bell remains the primary US growth driver, though a July food safety issue is expected to pressure third-quarter sales and margins. KFC opened 660 restaurants across 55 markets in the second quarter, with units growing 7%. The Pizza Hut divestiture is expected to yield approximately $2.3 billion in net proceeds. Stonegate notes the company will increasingly concentrate on its higher-growth, predominantly franchised KFC and Taco Bell businesses.

Fortune
Jul 30th, 2026
Taco Bell sales recover with $1 Mexican pizza deal after lettuce outbreak triggers 2% drop

Taco Bell's same-store sales dropped 2% in July-September following a cyclospora outbreak linked to shredded lettuce, down from a 7% increase in the previous quarter. Parent company Yum Brands reported sales bottomed out the weekend of 18-19 July but have since recovered halfway to year-ago levels. The chain removed shredded iceberg lettuce from US restaurants on 17 July after federal health officials connected it to the outbreak affecting customers in nine states. Taylor Farms recalled iceberg lettuce from central Mexico the following day. Yum Brands chief executive Chris Turner credited quick action, clear social media communication, and daily specials like $1 Mexican pizza for winning back diners. Company shares rose 6% on Thursday. Other chains including Chipotle and Chopt also reported lower traffic due to the outbreak.

CNBC
Jul 30th, 2026
Yum Brands posts mixed Q2 results as Taco Bell traffic plunges after cyclospora outbreak

Yum Brands reported mixed second-quarter results on Wednesday but provided no update on the cyclospora outbreak linked to Taco Bell restaurants. The company posted adjusted earnings per share of $1.62, beating expectations of $1.58, whilst revenue of $2.17 billion fell short of the $2.2 billion forecast. Net income rose to $853 million from $374 million year-over-year. Net revenue climbed 12% to $2.17 billion, driven by new restaurant openings. Global same-store sales increased 3% in the quarter. Taco Bell's same-store sales jumped 7%, whilst KFC reported 2% growth and Pizza Hut declined 1%. The results cover the period ended 30 June, before the FDA linked the outbreak to Taco Bell in mid-July.

Yahoo Finance
Jun 11th, 2026
Yum! Brands leads Q1 fast food earnings as sector revenues beat estimates by 1.4%

Yum! Brands reported Q1 revenues of $2.06 billion, up 15.2% year-on-year, exceeding analysts' expectations by 0.6%. The owner of KFC, Pizza Hut, Taco Bell and The Habit Burger Grill delivered strong results, beating EBITDA and same-store sales estimates. Despite the solid performance, the stock has declined 3.7% since reporting and currently trades at $150.75, suggesting investor expectations may have been higher than Wall Street's published projections. The traditional fast food sector showed strength overall in Q1, with 12 tracked companies collectively beating revenue consensus estimates by 1.4%. El Pollo Loco emerged as the quarter's top performer, reporting revenues of $126.2 million, up 5.9% year-on-year and exceeding expectations by 3.2%. Its shares rose 12.5% following the results.