Cybersecurity Engineer III
Company: McDonald's Corporation
Location: Chicago
Posted on: June 1, 2025
Job Description:
Job Description:Company Description:McDonald's growth strategy,
Accelerating the Arches, encompasses all aspects of our business as
the leading global omni-channel restaurant brand. As the consumer
landscape shifts we are using our competitive advantages to further
strengthen our brand. One of our core growth strategies is to
Double Down on the 3Ds (Delivery, Digital and Drive Thru).
McDonald's will accelerate technology innovation so 65M+ customers
a day will experience a fast, easy experience, whether at one of
our 25,000 and growing Drive thrus, through McDelivery, dine-in or
takeaway. McDonald's Global Technology is here to power tomorrow's
feel-good moments. That's why you'll find us at the forefront of
transformative technology, exploring new and innovative ways to
serve our millions of customers and spread happiness one delicious
Hot Fudge Sundae-dipped fry at a time. Using AI, robotics and
emerging tech, we're digitizing the Golden Arches. Combine that
with our unparalleled global scale, and we're reshaping all areas
of the business, industry and every community that is home to a
McDonald's restaurant. We face complex tech challenges every day.
But that's where our diverse and talented teams come in. They're
made up of the best and brightest from all over the globe, and they
thrive in the space where feel-good meets fast-paced. Check out the
McDonald's to learn how technology and our global team are directly
enabling the Accelerating the Arches strategy. Department
OverviewLeading the security of our business is the Global Cyber
Security (GCS) organization made up of leading practitioners who
partner with the enterprise and provide security for the next set
of groundbreaking opportunities business. We take on the highest
security challenges for McDonalds - driving security platforms,
enabling McDonalds to do business securely, and helping
continuously mature secure practices for McDonalds all while
improving operational effectiveness. GCS provides access to
compelling career paths for aspiring technologists. It's bonus
points when you get to see your family and friends use the tech you
secure at their favorite McDonald's restaurant.McDonald's is
seeking an App Sec Engineer III to support our cybersecurity team
as we protect our customers and the McDonald's brand. You will be
an integral part of an application security program that is
designed to ensure that all developed software meets exact
McDonald's standards while enabling continued innovation to meet
customers' needs.McDonald's is investing heavily in technology to
drive our growth. We're looking at how to use technology to improve
the customer experience and build new customer experiences. We're
also exploring technologies that can help us reduce or eliminate
repetitive tasks and make employees' jobs ultimately exciting. With
all the new projects and initiatives, it is a dynamic era in our
cybersecurity growth, helping to make a Safer and Better
McDonald's!The Engineer III will bring their technical expertise to
facilitate the App Sec program, including the technical
implementation and management of commercially leading Secure
Development tools across the SDLC, specifically facilitating DAST,
MDAST, SAST, and SCA capabilities. This role will also coach and
educate analysts, engineers, and developers on the findings and
their remediation. As a leading SME, the Engineer III will
collaborate with other Cyber Engineers and broaden their
understanding technical expertise. This position will work closely
with cybersecurity experts, Global Technology teams and developers,
and suppliers.Responsibilities
- Stay up to date on emerging threats and potential impact to our
cyber ecosystem
- Oversee the evaluation, implementation, and management of
application security tools and technologies throughout the
development process and pipeline (e.g., SAST, DAST, AMAST).
- Perform security evaluations of application code and design to
detect security flaws and secure code adherence in addition to
compliance with relevant security policies and standards.
- Coach analysts and engineers on the mastery of technical skills
and capabilities
- Meet developers where they are, enabling developers to develop
code securely
- Partner with our front-end digital channel development teams
(mobile, web, etc.), back-end platform development teams
(Point-of-Sale, eCommerce Platform, etc.), and security service
delivery teams to triage and develop plans for remediation of
application threats and vulnerabilities, at a global
scale.Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, or other
related fields (Master's Degree Preferred).
- 4+ years of professional experience in Application Security,
Software development, or related.
- Experience managing technical teams and leading security
projects and initiatives.
- Experience with security tools and technology (e.g., SAST,
DAST, AMAST, MDAST).
- Experience with multiple objected oriented coding programming
languages, and front-end frameworks as well.
- Experience with secure software development implementation and
integration of security into the SDLC with pipeline
integrations.
- Ability to inspect code and offer remediation techniques
- Ability to communicate complex security concepts to technical
and non-technical stakeholdersDesired skills:
- Relevant certifications (e.g., CISSP, CEH) preferred.
- Strong knowledge of application security tools (SAST, DAST,
AMAST) and secure coding practices.
- Experience with code reviews, identifying vulnerabilities, and
ensuring code compliance.
- Assess and exploit vulnerabilities utilizing tools such as Burp
Suite and Invicti alongside SAST/SCA(Snyk), and DAST(StackHawk)
tools.
- Skilled in intercepting, analyzing, and manipulating web
traffic using AMAST tool(s)
- Strong understanding of modern web technologies (e.g. Web APIs,
Authentication/ Authorization, etc.)
- Ability to coach and educate both the technical and
secure-by-design principles to developers and analysts
- Ability to build custom solutions and enabling capabilities to
facilitate improved business processes as related to secure code
capabilitiesCompensationBonus Eligible:This position is eligible
for a bonus, calculated based on individual and company
performance.Long - Term Incentive:This position is eligible for
stock or other equity grants pursuant to McDonald's long-term
incentive plan.Benefits Eligible:This position offers health and
welfare benefits, a 401(k) plan, adoption assistance program,
educational assistance program, flexible ways of working, and time
off policies (including sick leave, parental leave, and
vacation/PTO). Eligibility requirements apply to some benefits and
may depend on job classification and length of employment.Salary
RangeSalary Ranges-$129,800.00 -$165,490.00Additional
Information:Benefits eligible: This position offers health and
welfare benefits, a 401(k) plan, adoption assistance program,
educational assistance program, flexible ways of working, and time
off policies (including sick leave, parental leave, and
vacation/PTO). Eligibility requirements apply to some benefits and
may depend on job classification and length of employment. Bonus
eligible: This position is eligible for a bonus, calculated based
on individual and company performance.Long term Incentive eligible:
This position is eligible for stock or other equity grants pursuant
to McDonald's long-term incentive plan.McDonald's is an equal
opportunity employer committed to the diversity of our workforce.
We promote an inclusive work environment that creates feel-good
moments for everyone. McDonald's provides reasonable accommodations
to qualified individuals with disabilities as part of the
application or hiring process or to perform the essential functions
of their job. If you need assistance accessing or reading this job
posting or otherwise feel you need an accommodation during the
application or hiring process, please contact
mcdhrbenefits@us.mcd.com. Reasonable accommodations will be
determined on a case-by-case basis.McDonald's provides equal
employment opportunities to all employees and applicants for
employment and prohibits discrimination and harassment of any type
without regard to sex, sex stereotyping, pregnancy (including
pregnancy, childbirth, and medical conditions related to pregnancy,
childbirth, or breastfeeding), race, color, religion, ancestry or
national origin, age, disability status, medical condition, marital
status, sexual orientation, gender, gender identity, gender
expression, transgender status, protected military or veteran
status, citizenship status, genetic information, or any other
characteristic protected by federal, state or local laws. This
policy applies to all terms and conditions of employment, including
recruiting, hiring, placement, promotion, termination, layoff,
recall, transfer, leaves of absence, compensation and
training.Nothing in this job posting or description should be
construed as an offer or guarantee of employment.
#J-18808-Ljbffr
Keywords: McDonald's Corporation, Orland Park , Cybersecurity Engineer III, Engineering , Chicago, Illinois
Didn't find what you're looking for? Search again!
Loading more jobs...