Cyber Engineer III

hace 2 semanas


Ciudad de México, Ciudad de México McDonald's A tiempo completo

McDonald's new growth strategy,
Accelerating the Arches
, is built on our ambition to Double Down on the 3Ds:
Delivery, Digital, and Drive-Thru
. Technology is at the center of this strategy, enabling 65M+ customers each day to enjoy fast, easy, and secure experiences across web, mobile, and restaurant channels.

The
Global Technology
organization designs, builds, and operates the platforms behind our global omni-channel experience. Within Global Technology,
Global Cybersecurity Services (GCS)
protects McDonald's customers, crew, and brand by securing our digital ecosystem end-to-end.

The
External Web Application and API Protection (E-WAAP)
team is responsible for securing McDonald's external web and API surfaces across web, mobile, and partner integrations using Akamai's edge security platform (WAF, bot management, DDoS, CDN, and API security).

Check out the McDonald's  Global Technology Technical Blog to learn how technology and our global team are directly enabling the Accelerating the Arches strategy.

Job Description

The
Senior Engineer, Application & API Security
is a key member of the E-WAAP team and serves as a technical lead for our Akamai-based web and API security platform. You will:

  • Lead onboarding of new applications and APIs onto Akamai (WAF, CDN, bot, and API security capabilities).
  • Design and tune security policies to protect against OWASP Top 10, API abuse, bots, and DDoS while preserving performance and user experience.
  • Partner with product teams, developers, and cloud teams to embed E-WAAP into CI/CD and DevSecOps workflows.

This role reports into the
G5 Manager, Application & API Security (E-WAAP)
and will provide coaching and technical direction to G3 Engineers and G2/G3 Analysts as we in-source capabilities from our managed services provider.

Responsibilities & Accountabilities:

  • Platform engineering & design
  • Lead the onboarding of new web and API workloads to Akamai, from discovery and architecture review to staging, validation, and production cutover.
  • Design and implement WAF, bot management, DDoS, and rate-limiting policies tailored to application risk profiles and business requirements.
  • Build reusable configuration patterns, templates, and reference architectures for common McDonald's application types (e.g., marketing sites, e-commerce, APIs, partner integrations).
  • Use Akamai APIs, automation frameworks, and infrastructure-as-code (e.g., Terraform, Python, CI/CD pipelines) to manage configurations at scale.

  • Security operations & tuning

  • Lead incident triage and investigations for WAF, API, and bot-related events; coordinate containment, tuning, and long-term fixes.
  • Analyze WAF and CDN logs to identify attacks, false positives, and evasion attempts; refine policies, exception sets, and custom rules.
  • Collaborate with Security Operations, Threat Intelligence, and product security teams to map emerging threats into new or updated rulesets.
  • Drive continuous improvement in detection quality, block rates, and false-positive reduction while maintaining performance SLAs.

  • Dev & automation focus

  • Partner with developers to integrate Akamai security checks into CI/CD (e.g., automated policy promotions, pre-prod validation jobs, automated regression checks).
  • Develop internal tools and scripts (Python, Bash, TypeScript, etc.) to streamline common workflows (policy cloning, bulk updates, configuration linting).
  • Provide technical requirements and guidance into product roadmaps for observability, logging, and security analytics.

  • Governance, metrics, and leadership

  • Own platform health and risk metrics (coverage, rule adoption, false positives, incident volume, MTTR) and present them regularly to leadership and stakeholders.
  • Lead operational governance forums with product teams to review posture, tuning backlog, and upcoming changes.
  • Mentor and coach G3 Engineers and Analysts; provide guidance on investigations, change reviews, and documentation.
  • Contribute to and lead updates of SOPs, intake processes, runbooks, and standards for Akamai and E-WAAP.

Qualifications

  • Bachelor's degree in computer science, Engineering, Information Technology, or equivalent experience.
  • Knowledge of Agile software development process including application of Agile techniques and delivery practices and promoting adoption of Agile methodologies to secure outcome-driven mindset in product teams.
  • Experience working with
    large-scale, global, high-availability
    platforms (CDN, edge, or cloud) where performance and latency are critical.
  • Prior experience with
    Akamai APIs
    , Terraform, or other infrastructure-as-code tools for managing Akamai configurations at scale.
  • Familiarity with SIEM/SOAR tools and log analysis for WAF and CDN events.
  • Industry certifications in security or cloud (e.g., CISSP, CCSP, GIAC, cloud provider security certifications).

Additional Information

McDonald's is committed to providing qualified individuals with reasonable accommodations to perform the essential functions of their jobs. Additionally, if you (or another applicant of whom you are aware) require assistance accessing or reading this job posting or otherwise seek assistance in the application process, please contact

McDonald's provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to sex, sex stereotyping, pregnancy (including pregnancy, childbirth, and medical conditions related to pregnancy, childbirth, or breastfeeding), race, color, religion, ancestry or national origin, age, disability status, medical condition, marital status, sexual orientation, gender, gender identity, gender expression, transgender status, protected military or veteran status, citizenship status, genetic information, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Nothing in this job posting or description should be construed as an offer or guarantee of employment.



  • Ciudad de México, Ciudad de México Near Shore Cyber A tiempo completo

     About the OpportunityOur US-based global BPO client is seeking an Application Security Engineer to protect mission-critical systems and applications serving millions of customers worldwide. This award-winning employer has operated for over 40 years and maintains a strong commitment to employee development, diversity, and work-life balance.You will lead...

  • Fullstack Engineer III

    hace 8 minutos


    Ciudad de México, Ciudad de México Uber Freight A tiempo completo

    Schedule: Full-time Job Type: Hybrid Salary Type: SalaryReq #918Fullstack Engineer IIIAbout the RoleAs a Fullstack Engineer at Uber Freight, you'll develop and maintain features that connect backend systems with intuitive user interfaces, helping shippers and carriers move freight efficiently. You'll work closely with designers, backend specialists, and...

  • Cloud Engineer III

    hace 44 minutos


    Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and...

  • Cyber Security Engineer

    hace 1 semana


    Ciudad de México, Ciudad de México Mercado Libre A tiempo completo

    Como Software Engineer Backend en Mercado Libre, diseñarás y escalarás sistemas innovadores y seguros que resuelven problemas reales y de alto impacto. Trabajarás en un entorno dinámico con tecnología de vanguardia, aplicando buenas prácticas de ingeniería, modelos de IA propios y aprendizaje continuo, con el propósito de democratizar el comercio...

  • Software Engineer III

    hace 2 semanas


    Ciudad de México, Ciudad de México McDonald's A tiempo completo

    McDonald's growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru)....

  • Software Engineer III

    hace 21 minutos


    Ciudad de México, Ciudad de México McDonald's Corporation A tiempo completo

    Company Description McDonald's growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and...

  • Release Engineer III

    hace 1 hora


    Ciudad de México, Ciudad de México Solera A tiempo completo

    Release Engineer IIIWHO WE ARESolera is a global leader in data and software services that strives to transform every touchpoint of the vehicle lifecycle into a connected digital experience. In addition, we provide products and services to protect life's other most important assets: our homes and digital identities. Today, Solera processes over 300 million...


  • Ciudad de México, Ciudad de México Crunchyroll, LLC A tiempo completo

    About CrunchyrollFounded by fans, Crunchyroll delivers the art and culture of anime to a passionate community. We super-serve over 100 million anime and manga fans across 200+ countries and territories, and help them connect with the stories and characters they crave. Whether that experience is online or in-person, streaming video, theatrical, games,...

  • Cloud Platform Engineer III

    hace 33 minutos


    Ciudad de México, Ciudad de México McDonald's A tiempo completo

    McDonald's growth strategy, Accelerating the Arches, encompasses all aspects of our business as the leading global omni-channel restaurant brand. As the consumer landscape shifts we are using our competitive advantages to further strengthen our brand. One of our core growth strategies is to Double Down on the 3Ds (Delivery, Digital and Drive Thru)....


  • Ciudad de México, Ciudad de México Valce Talent Solutions A tiempo completo

    Software Engineer III .NETROLE SNAPSHOT This position is responsible for enhancing and maintaining existing software products as well as developing new products. The ideal candidate has a strong desire for excellence, regularly takes initiative, works with minimal supervision, confidence in their expertise, collaborative team player and is a creative problem...