Job Description The External Web Application and API Protection (E-WAAP) team is responsible for securing McDonald’s external web and API surfaces across web, mobile, and partner integrations using Akamai’s edge security platform (WAF, bot management, DDoS, CDN, and API security). Department Overview The Global Technology organization designs, builds, and operates the platforms behind our global omni-channel experience. Within Global Technology, Global Cybersecurity Services (GCS) protects McDonald’s customers, crew, and brand by securing our digital ecosystem end‑to‑end. Duties Responsibilities & Accountabilities Monitoring & First‑Line Triage Monitor Akamai dashboards, alerts, and logs to identify abnormal traffic, errors, or performance issues impacting web and API properties. Perform initial triage on alerts and tickets by gathering key context (affected application, timeframe, recent changes) and escalating clear, concise summaries to Engineers. Track incidents, changes, and service requests in ServiceNow and Jira, ensuring accurate categorization, documentation, and status updates. Staging & Validation Support staging configuration reviews by validating URLs, headers, origins, and expected WAF and routing behavior. Execute standard validation playbooks (e.g., path testing, error scenarios, status codes) and document results for engineering review. Assist with post‑change and post‑deployment production validations to confirm no negative user or application impact. Data Analysis & Reporting Collect and organize metrics related to WAF activity, attack trends, false positives, performance, and security coverage to support recurring reports. Perform basic log analysis using dashboards, queries, and filters to identify spikes, notable patterns, or anomalies. Documentation & Process Improvement Maintain and update Confluence documentation, runbooks, and standard operating procedures for common tasks such as validations, intake requirements, and escalations. Help refine onboarding materials and intake templates used by application teams requesting E‑WAAP services. Participate in Agile ceremonies to stay aligned on priorities, capture action items, and keep tickets current. Qualifications Basic Qualifications Bachelor’s degree in Computer Science, Information Technology, Engineering, or equivalent practical experience. 0–2 years of experience in IT operations, technical support, security, or a related internship or apprenticeship. Basic knowledge of Linux or cloud environments, along with introductory scripting experience (e.g., Python, Bash, PowerShell, or similar). Foundational understanding of HTTP, TLS, DNS, CDN, and SDK concepts, as well as basic web development technologies such as HTML, JavaScript, and APIs. Basic knowledge of web technologies, including HTTP behavior, browsers, and simple web application functionality, with a demonstrated interest in security. Comfort working with dashboards, log data, alerting systems, and ticketing tools such as ServiceNow and Jira. Strong attention to detail, curiosity, and a willingness to learn while following structured processes and documentation. Preferred Qualifications Exposure to any Web Application Firewall (WAF) or Content Delivery Network (CDN) platform (e.g., Akamai, Cloudflare, F5) through coursework, labs, internships, or self‑directed learning. Experience using collaboration and documentation tools such as Confluence, Jira, and Microsoft Teams in a team‑based environment. We do not tolerate inequality, injustice, or discrimination of any kind. #J-18808-Ljbffr
Analyst, Application Security
MCDONALD'S
distrito federal, distrito federal
Publicado hace 22 días
Denunciar empleo