> Markdown version of [/jobs/ext/2293949-sr-external-web-application-api-security-engineer](https://www.wearedevelopers.com/jobs/ext/2293949-sr-external-web-application-api-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr External Web Application & API Security Engineer - **Company:** McDonald's - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $138,207.0 - $172,758.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Business Logic, Microsoft Azure, Cyber Security, Continuous Integration, Hypertext Transfer Protocols (HTTP), JSON, OAuth, Open Web Application Security, Openid Connect, Akamai, JSON Web Token, Web Application Security, Security Information and Event Management, Simple Object Access Protocol (SOAP), Web Applications, Web Platforms, Openapi, Data Logging, Scripting, Transport Layer Security, Google Cloud, Load Balancing, Cloud Platform System, Delivery Pipeline, Software Security, Core Api, Git, Information Technology, Integration Frameworks, Graphql, Api Gateway, Restful APIs, Terraform, Ddos, Grpc, Devsecops, Microservices - **Published:** August 29, 2026 - **Apply:** https://www.chicagocareersite.com/job.asp?id=3369531283&tx=FL535FFL&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience. * Five or more years of security engineering experience, including at least three years of hands-on API security across discovery, posture assessment, runtime monitoring, testing, architecture review, or control engineering. * Strong knowledge of REST, GraphQL, API gateways, microservices, HTTP, TLS, JSON, OAuth 2.0, OpenID Connect, JWT, API keys, mutual TLS, service identities, authorization, and common API abuse patterns. * Hands-on experience with enterprise API security and WAF platforms. * Experience analyzing security telemetry, investigating attacks, reducing false positives, scripting in a common language, and integrating security platforms with SIEM, SOAR, ticketing, or workflow automation tools. * Experience with at least one major cloud platform (AWS, Microsoft Azure, or Google Cloud Platform), including API gateway, identity, logging, and load-balancing services. * Strong written and verbal communication skills, with the ability to explain technical risk and remediation to both engineering and non-technical stakeholders. Preferred Qualifications * Hands-on Akamai API Security and App & API Protector experience. * OpenAPI or GraphQL schema analysis. * Terraform and Git-based deployment workflows. * Experience supporting global, high-volume digital platforms. ## Description * Lead the engineering and operationalization of API discovery, posture management, and runtime protection capabilities across cloud, on-premises, and partner environments. * Design, operate, and tune WAF and edge security controls for high-availability digital services. * Assess and reduce API risk related to authorization failures, authentication weaknesses, excessive data exposure, business logic abuse, injection, automation, and other OWASP API Security Top 10 risks. * Design and tune WAF, rate-limiting, bot management, DDoS, and edge security controls for applications and APIs, with a strong focus on accuracy, resiliency, and low false-positive rates. * Automate repeatable security workflows and embed validation into CI/CD and DevSecOps processes. This role reports into the Senior Manager, Application & API Security (E-WAAP) and will provide coaching and technical direction to Engineers and Analysts as we in-source capabilities from our managed services provider. Responsibilities & Accountabilities API Security Engineering and Architecture * Lead API discovery, inventory, classification, and ownership mapping across external, internal, partner, and cloud-hosted APIs, including identification of shadow, zombie, and unmanaged APIs. * Operate and improve enterprise API security capabilities for posture management, runtime detection, attacker behavior analysis, and risk prioritization. * Assess REST, GraphQL, SOAP, gRPC, and event-driven APIs for OWASP API Security Top 10 risks, authentication and authorization weaknesses, excessive data exposure, schema and input-validation gaps, rate-control issues, and differences between documented and observed behavior. * Partner with API owners and engineering teams to prioritize findings and implement practical remediation or compensating controls. * Develop reusable API security patterns and reference architectures for customer-facing, mobile, partner, microservice, and third-party integrations. Runtime API Protection and Security Operations * Analyze API telemetry, tune behavioral detections, and lead incident investigation and containment for credential abuse, token misuse, scraping, enumeration, account takeover, authorization bypass, data exfiltration, and business logic abuse. * Integrate API security events and findings with SIEM, SOAR, ticketing, and case-management workflows to support centralized monitoring, response, and remediation tracking. * Define and monitor API coverage, ownership, unmanaged API risk, critical findings, remediation aging, attack volume, alert fidelity, and response-time metrics. WAF and Edge Application Protection * Design, onboard, and tune WAF, rate-limiting, bot-management, DDoS, and edge controls for applications and APIs, including OWASP protections, custom rules, virtual patching, and narrowly scoped exceptions. Automation, DevSecOps, and Platform Engineering * Automate API and WAF security workflows using platform APIs, Terraform, scripting, and CI/CD pipelines, including configuration validation, policy promotion, alert routing, remediation tracking, rollback, and reporting. Governance, Collaboration, and Technical Leadership * Lead security design reviews. * Maintain API and web application security standards and runbooks. * Communicate risk and remediation priorities. * Mentor engineers and analysts. * Support high-severity incidents as required. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Exploring the Power of gRPC-Gateway for Writing RESTful Services](https://www.wearedevelopers.com/videos/2072-exploring-the-power-of-grpc-gateway-for-writing-restful-services) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Lessons learned from observing a billion API requests](https://www.wearedevelopers.com/videos/1574-lessons-learned-from-observing-a-billion-api-requests) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)