Prepin
Log in
Pizza Hut

engineering opportunity

Security Engineer, Web Application Security

The Security Engineer will manage and optimize web application security, including WAF, CDN, and API protection services. They will also handle certificate lifecycle management and participate in incident response and security operations for global digital platforms.

United StatesremoteFULL_TIME

Posted

About the role

What will you do at Pizza Hut?

Position Summary

We are seeking a Security Engineer to join Yum! Brands' Cybersecurity

Engineering organization and help protect the web applications and APIs

supporting our global digital ecosystem across KFC, Taco Bell, Pizza Hut, Habit

Burger & Grill, and Yum! corporate platforms.

This role will support the operation and continuous improvement of Web

Application Firewall (WAF), Content Delivery Network (CDN), API security, and

digital certificate management services. The engineer will work with

technologies such as Akamai App & API Protector, Akamai CDN, Certificate

Manager, and other web security platforms to help protect internet-facing

applications from cyber threats while maintaining application availability and

performance.

The ideal candidate has a strong technical foundation in networking, web

technologies, or cybersecurity and is interested in developing deeper expertise

in web application security, CDN technologies, APIs, and certificate management.

This role will work closely with senior engineers and cross-functional teams to

troubleshoot issues, onboard applications, respond to security events, implement

security changes, maintain certificates, and improve operational processes.

RESPONSIBILITIES

Primary Responsibilities

Web Application Security

* Configure, maintain, and support Web Application Firewall (WAF) protections

using Akamai App & API Protector and related security technologies.

* Monitor and investigate web security events involving:

* OWASP Top 10 vulnerabilities

* API attacks

* Bot traffic

* Credential stuffing

* DDoS attacks

* Layer 7 attacks

* Other suspicious or malicious web traffic

* Assist with WAF policy tuning to reduce false positives while maintaining

appropriate security protections.

* Review application traffic and security logs to identify attack patterns,

application behavior, and potential security concerns.

* Implement approved WAF policy changes, exceptions, allowlists, and security

configuration updates.

* Support senior engineers during complex security investigations and

production incidents.

CDN & Edge Security

* Configure and maintain CDN and edge security configurations supporting

internet-facing applications.

* Work with Akamai technologies including:

* Property Manager

* Edge Hostnames

* Cloudlets

* DNS integrations

* Origin connectivity

* Caching and delivery configurations

* Troubleshoot common CDN and web application issues involving:

* HTTP response codes

* Cache behavior

* DNS

* Routing

* Origin connectivity

* TLS/SSL

* Application availability

* Support the onboarding of new websites and APIs onto the enterprise WAF/CDN

platform.

Perform pre-production validation, testing, and post-change verification.

Certificate Lifecycle Management

* Support the lifecycle management of public TLS certificates, including:

* Request validation

* Issuance

* Deployment

* Renewal

* Revocation

* Replacement

* Monitor certificate inventories and upcoming expiration dates.

* Coordinate certificate changes and renewals with application owners and other

technical teams.

* Validate certificates after deployment and troubleshoot common certificate,

trust chain, DNS validation, and TLS issues.

* Maintain accurate certificate ownership and lifecycle documentation.

* Escalate certificate risks or renewal issues before they can impact

production applications.

Security Operations & Incident Response

* Monitor and investigate WAF alerts, application issues, and security events.

* Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other

available telemetry to assist with troubleshooting and investigations.

* Participate in incident response activities involving WAF, CDN, DDoS,

certificates, and internet-facing applications.

* Assist with troubleshooting customer-impacting production issues and

determining whether issues originate from the security/CDN layer or another

application component.

* Implement approved mitigations and validate application functionality

following security changes.

* Follow established incident management, escalation, and change management

processes.

* Participate in the team's on-call rotation supporting globally distributed

applications and services.

Automation & Engineering

* Identify repetitive operational activities that could benefit from

automation.

* Develop and maintain basic scripts and tools using technologies such as

Python, PowerShell, Bash, or REST APIs.

* Assist with improving security monitoring, reporting, inventory management,

and operational dashboards.

* Contribute to automation and standardization of application onboarding, WAF

configuration, and certificate management processes.

* Learn and adopt Infrastructure-as-Code and API-driven security management

practices where appropriate.

Collaboration & Continuous Improvement

* Work closely with:

* Software Engineering

* Cloud Engineering

* Networking

* Infrastructure

* IAM

* Enterprise Architecture

* Compliance

* Security Operations

* Partner with application teams during WAF/CDN onboarding, troubleshooting,

security changes, and certificate activities.

* Participate in technical discussions and architecture reviews alongside

senior engineers.

* Create and maintain technical documentation, troubleshooting guides,

operational procedures, and runbooks.

* Share knowledge and lessons learned with other members of the team.

* Identify opportunities to improve existing processes and operational

practices.

Governance & Compliance

* Follow established security standards, change management procedures, and

operational processes.

* Support PCI DSS and internal audit activities by gathering technical evidence

and documentation.

* Assist with periodic security reviews and control assessments.

* Maintain accurate documentation for WAF configurations, certificates,

application ownership, exceptions, and operational processes.

* Support remediation activities identified through audits, vulnerability

assessments, penetration testing, and security reviews.

QUALIFICATIONS

Required Qualifications

* Bachelor's degree in Computer Science, Cybersecurity, Information Technology,

or equivalent education and/or professional experience.

* 2–4+ years of experience in cybersecurity, networking, infrastructure, cloud

engineering, application support, or a related technical field.

* Foundational understanding of:

* HTTP/HTTPS

* TLS/SSL

* DNS

* TCP/IP

* Web applications

* REST APIs

* Reverse proxies and CDN concepts

* Familiarity with Web Application Firewall technologies or web application

security concepts.

* Familiarity with common web security threats and the OWASP Top 10.

* Experience troubleshooting technical issues using logs and other diagnostic

information.

* Ability to analyze technical problems and follow issues through resolution.

* Strong written and verbal communication skills.

* Ability and willingness to learn new security technologies and platforms.

Preferred Qualifications

  • Experience in all of the following areas is not required. Candidates with a
  • strong technical foundation and demonstrated ability to learn are encouraged to
  • apply.
  • * Hands-on experience with Akamai or similar WAF/CDN platforms.
  • * Experience with Akamai technologies such as:
  • * App & API Protector
  • * Property Manager
  • * Certificate Manager
  • * Edge DNS
  • * Cloudlets
  • * Bot Manager
  • * Experience with public TLS certificate management.
  • * Experience working with cloud environments such as AWS, Azure, or GCP.
  • * Experience with SIEM or log analysis platforms such as Splunk, Sentinel, or
  • similar technologies.
  • * Basic scripting experience with Python, PowerShell, or Bash.
  • * Experience working with REST APIs.
  • * Familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
  • * Security certifications such as Security+, GSEC, Akamai certifications, or
  • equivalent technical certifications.
  • Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the
  • expected salary range for this position. Ultimately, in determining pay, we’ll
  • consider the successful candidate’s location, experience, and other job-related
  • factors.

Which skills does this role require?

Web Application SecurityAPI SecurityTLS/SSLCybersecurityIncident ResponseNetworkingCloud EngineeringOWASP Top 10Web Application FirewallAkamai App & API ProtectorContent Delivery NetworkDDoSPCI DSSHTTPHTTPSSecurity+

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.