About the role
What will you do at Pizza Hut?
The Application Security Engineer will help strengthen application security
across web, mobile, and restaurant technology environments by partnering closely
with engineering, product, and security teams. This role will focus on
identifying, assessing, prioritizing, and remediating application
vulnerabilities while supporting the integration of security throughout the
software development lifecycle. The engineer will also help manage application
security testing and scanning practices, provide guidance on secure development,
monitor emerging vulnerabilities, and communicate security risks and remediation
recommendations to both technical and non-technical stakeholders.
RESPONSIBILITIES
PRIMARY RESPONSIBILITIES
* Partner with US teams to provide security guidance as a subject matter expert
around application security and operate YUM! application security services
for the brand.
* Aligning with a risk-based approach, collaborate with third-party engineers
and product owners to identify, prioritize, and remediate vulnerabilities in
mobile and web applications across YUM! systems. These include e-commerce
websites, e-commerce mobile apps, and restaurant operations applications.
* Leverage established YUM! security services to review vulnerability findings
and work closely with engineering teams to communicate, prioritize, and
remediate security issues. Analyze findings to determine root cause,
exploitability, business impact, and appropriate remediation strategies while
ensuring adherence to established remediation timelines.
* Maintain the brand's application security scan profiles and scan policies in
accordance with baseline standards across SAST, DAST, software composition
analysis (SCA), container security, Infrastructure as Code (IaC), secrets
detection, and crowd-sourced penetration testing platforms. Onboard new
applications into security services and continuously improve scan coverage
and effectiveness.
* Partner with development teams to integrate security into the software
development lifecycle (SDLC), including secure coding practices, pull request
workflows, automated security testing, software supply chain security, and
secure release processes.
* Conduct awareness campaigns with engineering teams to promote secure software
development practices and adherence to YUM! Global Technology Risk Management
standards.
* Continuously monitor publicly disclosed vulnerabilities affecting
applications, frameworks, libraries, operating systems, and third-party
dependencies. Assess business risk, prioritize remediation activities,
validate fixes through rescanning, and communicate recommendations to
stakeholders.
* Coordinate with incident response teams to contain, remediate, and perform
root cause analysis on application security incidents.
QUALIFICATIONS
BASIC QUALIFICATIONS
* Bachelor's degree and at least four years of experience in cybersecurity,
software engineering, or application development. Additional years of
relevant experience may be considered in lieu of a bachelor's degree.
* Experience evaluating application security vulnerabilities for
exploitability, business risk, and remediation planning.
* Experience collaborating effectively with software engineering teams and
communicating technical concepts to both technical and non-technical
audiences.
* Familiarity with secure software development lifecycle (SSDLC) practices and
modern software delivery methodologies.
* Familiarity with relevant compliance and data privacy regulations (e.g., PCI
DSS, GDPR, CCPA) and how they influence application security testing and
remediation activities.
TECHNICAL QUALIFICATIONS
* Knowledge of Git-based development workflows, including branching strategies,
pull requests, code reviews, merge approvals, and secure source code
management practices.
* Knowledge of CI/CD pipelines, build automation, and deployment technologies,
including how security testing integrates into modern software delivery.
* Knowledge of application security testing methodologies including Static
Application Security Testing (SAST), Dynamic Application Security Testing
(DAST), Software Composition Analysis (SCA), secrets detection, container
security scanning, and Infrastructure as Code (IaC) security testing.
* Knowledge of secure coding principles and common software vulnerabilities,
including the OWASP Top 10, secure authentication, authorization, input
validation, output encoding, session management, and common web application
attack techniques.
* Knowledge of HTTP/HTTPS, TLS, RESTful APIs, cookies, headers, CORS, Content
Security Policy (CSP), and common web communication protocols.
* Knowledge of modern authentication and authorization technologies including
OAuth 2.0, OpenID Connect (OIDC), SAML, JWT, and role-based access control
(RBAC).
* Knowledge of package management ecosystems (e.g., npm, pip, NuGet, Maven,
Gradle) and software supply chain security concepts including dependency
management, lock files, transitive dependencies, Software Bill of Materials
(SBOMs), and package integrity.
* Knowledge of containers and container management technologies (e.g., Docker
and Kubernetes), including container image security best practices and
interpretation of container security findings.
* Knowledge of Infrastructure as Code technologies (e.g., Terraform,
CloudFormation) and secure configuration practices.
* Ability to investigate security findings beyond automated scanner output by
understanding underlying technologies, validating exploitability, and
recommending practical remediation approaches.
Preferred Qualifications
- * Experience developing software in one or more modern programming languages
- (e.g., Java, JavaScript/TypeScript, Python, C#, Go, Rust).
- * Experience securing applications within Git-based DevSecOps environments.
- * Experience integrating application security controls into CI/CD pipelines.
- * Familiarity with AI-assisted software development tools and the security
- considerations associated with AI-generated code and automated code review.
- Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the
- expected salary range for this position. Ultimately, in determining pay, we'll
- consider the successful candidate’s location, experience, and other job-related
- factors.
Which skills does this role require?
Make your next move
Build a shortlist and prepare
Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.
- Build a focused shortlist before you applyCompare role requirements with your experience and give each application a clear reason.
- Practice explaining your experience in an interviewRehearse your answers before meeting the hiring team.
Other roles to compare
Review the responsibilities and requirements before adding an opening to your shortlist.
Security Engineer, Web Application Security
Pizza Hut · United States
Cybersecurity Assessment Data Analyst
CACI International Inc · United States
Lead Engineer, Information Security (Application Security)
RXO, Inc. · United States
Application & AI Security Engineer
MissionSquare · District of Columbia, United States
Senior Security Engineer
Credit Sesame · Mountain View, California, United States
Network Security Engineer Master
GovCIO · United States
Role information can change. Confirm current details on the original application page.
