Job Description
Department Overview
McDonald’s is hiring an Engineer I – Application Security to support building, configuring, and optimizing our application security ecosystem across applications. This hands-on role focuses on operating security tools, assisting with automation, and embedding security throughout the SDLC.
As McDonald’s accelerates technology-driven growth, this role helps deliver safer, more efficient experiences for customers and employees by reducing manual work and enabling new digital capabilities. In this role, you will support the implementation and tuning of application security controls for web and mobile platforms. You’ll work closely with developers, architects, and product teams to create basic automation scripts and help validate security measures.
Duties
- Assist in building, implementing, and maintaining application security processes aligned to standards and best practices.
- Help embed security controls and testing throughout the SDLC for web and mobile applications.
- Operate and tune SAST and DAST tooling; incorporate security testing, reduce false positives, and improve developer experience.
- Contribute to perform security assessments, mixing automatic and manual approach.
- Collaborate with DevSecOps to implement CI/CD security pipelines and automated checks.
Qualifications
- Bachelor’s in Computer Science, Cybersecurity, or related field (or equivalent experience).
Experience:
- 2+ years in application security or related cybersecurity roles
- Hands-on experience with application penetration testing methodologies and tools (web and/or mobile).
- Proficiency with SAST and DAST tools; familiarity with app security testing practices (e.g., OWASP ASVS).
- Solid understanding of secure coding and common vulnerabilities (OWASP Top 10).
Skills:
- Basic scripting (Python, Bash, or PowerShell) and comfort with REST APIs.
- Familiarity with source control (e.g., GitHub/GitLab) and code review practices.
- Strong problem-solving, communication, and collaboration skills.
Preferred
- Exposure to containers and cloud-native application security.
- Knowledge of mobile (iOS/Android) security topics
- Certifications such as CEH, GSEC, Security+, Pentest+, or similar.
