Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cybersecurity Engineer III - Application  Security image - Rise Careers
Job details

Cybersecurity Engineer III - Application Security

Company Description

McDonald’s new growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts, we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 4Ds (Delivery, Digital, Drive Thru, and Development). Our growth pillars emphasize the critical role technology plays as the best-in-class, global omni-channel restaurant brand. Technology enables the organization through digital technologies, and improving the customer, crew, and employee experience each and every day.

Leading the security of our business is the Global Cyber Security (GCS) organization made up of leading practitioners who partner with the enterprise and provide security for the next set of groundbreaking opportunities business. We take on the highest security challenges for McDonalds – driving security platforms, enabling McDonalds to do business securely, and helping continuously mature secure practices for McDonalds all while improving operational effectiveness. GCS provides access to compelling career paths for aspiring technologists. It’s bonus points when you get to see your family and friends use the tech you secure at their favorite McDonald’s restaurant.

Job Description

McDonald’s is seeking an App Sec Engineer III to support our cybersecurity team as we protect our customers and the McDonald’s brand. You will be an integral part of an application security program that is designed to ensure that all developed software meets exact McDonald’s standards while enabling continued innovation to meet customers’ needs.

McDonald’s is investing heavily in technology to drive our growth. We’re looking at how to use technology to improve the customer experience and build new customer experiences. We’re also exploring technologies that can help us reduce or eliminate repetitive tasks and make employees’ jobs ultimately exciting. With all the new projects and initiatives, it is a dynamic era in our cybersecurity growth, helping to make a Safer and Better McDonald's!

The Engineer III will bring their technical expertise to facilitate the App Sec program, including the technical implementation and management of commercially leading Secure Development tools across the SDLC, specifically facilitating DAST, MDAST, SAST, and SCA capabilities. This role will also coach and educate analysts, engineers, and developers on the findings and their remediation.  As a leading SME, the Engineer III will collaborate with other Cyber Engineers and broaden their understanding technical expertise.  This position will work closely with cybersecurity experts, Global Technology teams and developers, and suppliers. 

 

Responsibilities

  • Stay up to date on emerging threats and potential impact to our cyber ecosystem
  • Oversee the evaluation, implementation, and management of application security tools and technologies throughout the development process and pipeline (e.g., SAST, DAST, AMAST).
  • Perform security evaluations of application code and design to detect security flaws and secure code adherence in addition to compliance with relevant security policies and standards.
  • Coach analysts and engineers on the mastery of technical skills and capabilities
  • Meet developers where they are, enabling developers to develop code securely
  • Partner with our front-end digital channel development teams (mobile, web, etc.), back-end platform development teams (Point-of-Sale, eCommerce Platform, etc.), and security service delivery teams to triage and develop plans for remediation of application threats and vulnerabilities, at a global scale.

Benefits eligible: Yes

Bonus eligible: Yes

Long term incentive eligible: Yes

The expected salary range for this role is $129,800 - $165,490

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we may also consider your experience, and other job-related factors.

Qualifications

Minimum Requirements

  • Bachelor's degree in Computer Science, Cybersecurity, or other related fields (Master’s Degree Preferred).
  • 4+ years of professional experience in Application Security, Software development, or related.
  • Experience managing technical teams and leading security projects and initiatives.
  • Experience with security tools and technology (e.g., SAST, DAST, AMAST, MDAST).
  • Experience with multiple objected oriented coding programming languages, and front-end frameworks as well.
  • Experience with secure software development implementation and integration of security into the SDLC with pipeline integrations.
  • Ability to inspect code and offer remediation techniques
  • Ability to communicate complex security concepts to technical and non-technical stakeholders

 

Desired skills:

  • Relevant certifications (e.g., CISSP, CEH) preferred.
  • Strong knowledge of application security tools (SAST, DAST, AMAST) and secure coding practices.
  • Experience with code reviews, identifying vulnerabilities, and ensuring code compliance.
  • Assess and exploit vulnerabilities utilizing tools such as Burp Suite and Invicti alongside SAST/SCA(Snyk), and DAST(StackHawk) tools.
  • Skilled in intercepting, analyzing, and manipulating web traffic using AMAST tool(s)
  • Strong understanding of modern web technologies (e.g. Web APIs, Authentication/ Authorization, etc.)
  • Ability to coach and educate both the technical and secure-by-design principles to developers and analysts
  • Ability to build custom solutions and enabling capabilities to facilitate improved business processes as related to secure code capabilities

Additional Information

Benefits eligible: This position offers health and welfare benefits, a 401(k) plan, adoption assistance program, educational assistance program, flexible ways of working, and time off policies (including sick leave, parental leave, and vacation/PTO). Eligibility requirements apply to some benefits and may depend on job classification and length of employment. 

Bonus eligible: This position is eligible for a bonus, calculated based on individual and company performance.

Long term Incentive eligible: This position is eligible for stock or other equity grants pursuant to McDonald’s long-term incentive plan.

McDonald’s is committed to providing qualified individuals with reasonable accommodations to perform the essential functions of their jobs. Additionally, if you (or another applicant of whom you are aware) require assistance accessing or reading this job posting or otherwise seek assistance in the application process, please contact [email protected]

McDonald’s provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Nothing in this job posting or description should be construed as an offer or guarantee of employment.

Average salary estimate

$147645 / YEARLY (est.)
min
max
$129800K
$165490K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Engineer III - Application Security, McDonald's Corporation

McDonald's is on the lookout for a Cybersecurity Engineer III - Application Security to join our dynamic cybersecurity team! Located at our Chicago headquarters, you'll play a vital role in ensuring that all software developed meets our strict security standards while still fostering innovation and enhancing the customer experience. In this role, you'll dive into our application security program to help safeguard our customers and the McDonald's brand. We're investing heavily in technology, looking for creative ways to not only improve customer interactions but also simplify tasks for employees. As part of your day-to-day, you'll leverage your expertise with Secure Development tools like DAST, MDAST, SAST, and SCA throughout the software development lifecycle while mentoring fellow engineers and analysts. This isn't just about addressing vulnerabilities; it's about empowering developers to code securely right from the get-go. You'll collaborate closely with teams across the Global Technology spectrum—working with mobile and web developers as well as management teams—to enhance our application security strategies and remediate potential threats on a global scale. If you're curious about diving into emerging cyber threats and have a knack for coaching others, this role will allow you to shape the future of cybersecurity at McDonald's. Plus, you'll find satisfaction in knowing the tech you secure plays a pivotal role in the daily experiences of customers worldwide!

Frequently Asked Questions (FAQs) for Cybersecurity Engineer III - Application Security Role at McDonald's Corporation
What are the responsibilities of a Cybersecurity Engineer III - Application Security at McDonald's?

The Cybersecurity Engineer III - Application Security at McDonald's is responsible for overseeing and managing application security tools throughout the software development process, conducting security evaluations, coaching team members, and collaborating with developers to mitigate application threats. This role focuses on secure coding practices and ensuring that security standards are adhered to in the software development lifecycle.

Join Rise to see the full answer
What qualifications are needed for the Cybersecurity Engineer III - Application Security role at McDonald's?

To qualify for the Cybersecurity Engineer III - Application Security position at McDonald's, candidates should possess a Bachelor's degree in Computer Science, Cybersecurity, or a related field—preferably a Master's. Additionally, at least four years of experience in application security or software development, coupled with experience in managing technical teams and utilizing security tools such as SAST and DAST, is expected.

Join Rise to see the full answer
What tools and technologies should a Cybersecurity Engineer III be familiar with at McDonald's?

A Cybersecurity Engineer III at McDonald's should be proficient in using secure development tools including SAST, DAST, AMAST, and MDAST. Familiarity with multiple object-oriented programming languages and front-end frameworks is crucial, as well as the ability to assess vulnerabilities using tools like Burp Suite and Invicti.

Join Rise to see the full answer
How does the Cybersecurity Engineer III - Application Security contribute to McDonald's overall growth strategy?

The Cybersecurity Engineer III - Application Security plays a key role in McDonald's growth strategy by ensuring that all technology initiatives are secure, thereby protecting the brand and enhancing customer experience. By implementing robust security practices across development processes, they help facilitate innovation while safeguarding both customer data and company assets.

Join Rise to see the full answer
What kind of team collaboration can a Cybersecurity Engineer III - Application Security expect at McDonald's?

In the role of Cybersecurity Engineer III - Application Security at McDonald's, you can expect to collaborate closely with various teams, including front-end and back-end development groups, cybersecurity experts, and Global Technology teams. This interdisciplinary approach allows for a thorough understanding of security challenges and ensures a unified response to secure application development.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Engineer III - Application Security
Can you describe your experience with application security tools like SAST and DAST?

When responding to this question, outline your hands-on experience with SAST and DAST tools, giving specific examples of how you implemented these tools in your previous roles. Mention the types of vulnerabilities you've identified and how you remediated them, emphasizing any collaboration with development teams.

Join Rise to see the full answer
How do you stay updated on emerging cybersecurity threats?

Discuss your methods for staying informed, such as following cybersecurity blogs, attending conferences, participating in online forums, or engaging with industry groups. Mention any specific sources or communities that you rely on to keep your skills and knowledge up to date.

Join Rise to see the full answer
How would you approach training developers in secure coding practices?

Highlight your strategy for educating developers on secure coding by discussing workshops, one-on-one mentoring sessions, or the creation of shared resources. Emphasize practical examples from your experience and how you ensure developers understand both technical concepts and the importance of security in their work.

Join Rise to see the full answer
Can you give an example of a major security vulnerability you identified and resolved?

Prepare to narrate a specific incident where you identified a significant security vulnerability. Discuss the tools you used, the steps taken to address the issue, and the collaborative efforts necessary to ensure a successful resolution, allowing you to demonstrate both technical and teamwork skills.

Join Rise to see the full answer
What is your process for evaluating the security of application code?

Describe your detailed evaluation process, including steps like static code analysis, dynamic testing, and code reviews. Focus on the importance of both automated and manual assessments to ensure thorough coverage of potential vulnerabilities.

Join Rise to see the full answer
How do you prioritize security issues that arise during development?

Talk about your criteria for prioritizing vulnerabilities, such as prevalence, exploitability, and impact on business operations. Provide examples of how you have effectively communicated these priorities to development teams.

Join Rise to see the full answer
What role does documentation play in application security from your perspective?

Emphasize the importance of thorough documentation, including tracking security incidents, outlining remediation processes, and capturing lessons learned. Discuss any tools you have used to enhance documentation practices and how this benefits the security program overall.

Join Rise to see the full answer
How would you integrate security into the software development lifecycle?

Discuss specific strategies for integrating security at each stage of the SDLC, such as conducting threat modeling, security assessments during coding phases, and implementing security gates. This demonstrates your understanding of embedding security from the ground up.

Join Rise to see the full answer
What challenges have you faced in application security, and how did you overcome them?

Be honest about specific challenges, such as resistance from developers or resource limitations. Describe the strategies you implemented to address these challenges while ensuring that security remained a priority.

Join Rise to see the full answer
What measures do you suggest for maintaining application security in a cloud environment?

Talk about the unique security challenges cloud environments present, such as data protection and third-party integrations. Discuss strategies like network segmentation, continuous monitoring, and compliance checks that can help safeguard cloud applications.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted yesterday
Photo of the Rise User
McDonald's Corporation Hybrid Chicago, Illinois, United States
Posted yesterday
Posted 11 days ago
Photo of the Rise User
Varonis Hybrid No location specified
Posted 7 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
LINEAR Remote No location specified
Posted 13 days ago
Photo of the Rise User
Devoteam Remote Českobratrská, Moravská Ostrava a Přívoz, Czechia
Posted 10 days ago
Posted 6 days ago

McDonald's Corporation is a chain of fast food restaurants. Headquartered in Oak Brook, Illinois, the company's famous menu items include the Big Mac, Chicken McNuggets and Egg McMuffin. McDonald's is a publicly owned company and operates a Canadi...

264 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!