Senior External Web Application & API Security Engineer

McDonald’s Corporation

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Chicago, IL
Salary
$138,207–$172,758 / yr
Posted
1 day ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $155k
$122k most similar roles pay here $226k

This role pays less than 67% of similar roles. Most pay $149,625–$214,000 — the shaded band above. At the midpoint, this role pays about $155k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About McDonald’s Corporation

McDonald’s Corporation is the world's largest fast-food chain by revenue, operating over 40,000 locations in more than 100 countries.

McDonald’s Corporation currently has 43 open roles on FindRole.

Listed pay typically runs $138,207–$172,758 across 26 roles with salary data.

Most-posted roles

View all roles at McDonald’s Corporation

At a glance

TL;DR · Senior External Web Application & API Security Engineer

Sr External Web Application & API Security Engineer serves as a hands-on technical lead responsible for enterprise API security and web application protection. You will lead the engineering and operationalization of API discovery, posture management, and runtime protection across cloud, on-premises, and partner environments. Key responsibilities include designing and tuning WAF, rate-limiting, bot management, and DDoS controls while mitigating OWASP API Security Top 10 risks like authentication weaknesses and business logic abuse. You will automate security workflows using Terraform, scripting, and CI/CD pipelines to integrate with SIEM and SOAR tools. The role requires expertise in REST, GraphQL, SOAP, gRPC, OAuth 2.0, OpenID Connect, and JWT. This position addresses the critical challenge of securing high-availability digital services and complex integrations for customer-facing, mobile, and third-party platforms within a large-scale technical ecosystem.

What you'll do

  • Lead the discovery, inventory, and classification of internal and external APIs to identify unmanaged risks.
  • Design and tune WAF, rate-limiting, bot management, and DDoS protections for high-availability digital services.
  • Assess and mitigate OWASP API Security Top 10 risks including authentication failures and data exposure.
  • Analyze security telemetry to investigate and contain incidents like credential abuse and account takeovers.
  • Automate security workflows using Terraform, scripting, and CI/CD pipelines to integrate into DevSecOps processes.
  • Develop reusable security patterns and reference architectures for mobile, partner, and microservice integrations.
  • Provide technical leadership by mentoring engineers and conducting security design reviews.
  • Maintain security standards, runbooks, and communicate risk remediation priorities to stakeholders.

What we're looking for

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
  • Five or more years of security engineering experience.
  • At least three years of hands-on API security across discovery, posture assessment, runtime monitoring, testing, architecture review, or control engineering.
  • Strong knowledge of REST, GraphQL, API gateways, microservices, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, and common API abuse patterns.
  • Hands-on experience with enterprise API security and WAF platforms.
  • Experience analyzing security telemetry, investigating attacks, scripting in a common language, and integrating security tools with SIEM or SOAR.
  • Experience with at least one major cloud platform (AWS, Microsoft Azure, or Google Cloud Platform).
  • Strong written and verbal communication skills to explain technical risk to both engineering and non-technical stakeholders.
  • Hands-on Akamai API Security and App & API Protector experience (preferred).
  • OpenAPI or GraphQL schema analysis (preferred).
  • Terraform and Git-based deployment workflows (preferred).
  • Experience supporting global, high-volume digital platforms (preferred).

More like this

Similar roles

API Security Engineer

Fiserv

Berkeley Heights, NJ +2 3 days ago $110,000$186,000
API Security OAuth2 OIDC JWT mTLS Open API JSON Schema CI/CD DevSecOps SAST DAST WAF WAAP Service Mesh Policy-as-Code NIST ISO 27001 PCI DSS FAPI OWASP API Security Top 10 Traceable Salt Security NoName
5+ yrs exp

API Security Engineer

Fiserv

Berkeley Heights, NJ +2 4 days ago $128,000$216,000
API Security OAuth2 OIDC JWT mTLS OpenAPI JSON Schema CI/CD DevSecOps SAST DAST Policy-as-Code WAF WAAP Service Mesh NIST ISO 27001 PCI DSS FAPI OWASP API Security Top 10 Traceable Salt Security NoName
5+ yrs exp

Application Security Engineer

State Street

Quincy, MA +4 21 days ago $120,000$202,500
AppSec DevSecOps SAST DAST SCA CI/CD Python Java .Net Node.js AWS Azure Kubernetes Terraform Ansible Infrastructure as Code Agile SDLC API Security Container Scanning
6+ yrs exp

Senior Application Security Engineer

LPL Financial

Fort Mill, NC +5 40 days ago $100,631$167,787
Application Security OWASP Top 10 DevSecOps CI/CD IAST Burpsuite Postman Synopsys BlackDuck J-Frog PrismaCloud C# Java HTML CSS React Angular
5+ yrs exp Hybrid

Senior Application Security Engineer

SentinelOne

11 days ago $132,000$160,000
C C++ Rust Java Python Node.js SAST OWASP Top 10 CWE Top 25 SAML OAuth OIDC JWT Git CI/CD Threat Modeling IDA Pro Binary Ninja Ghidra
5+ yrs exp