{"schemaVersion":"jobsearcher.job.v1","id":"3766615bc573e0ffe21e618e","url":"https://jobsearcher.com/jobs/3766615bc573e0ffe21e618e","canonicalUrl":"https://jobsearcher.com/jobs/3766615bc573e0ffe21e618e","title":"Application Security | Application Security Engineer","description":"Overview:\nPepsiCo’s Global Application Security Program integrates security into software development at enterprise scale. Our mission is to make application security risks visible, actionable, and measurable so they can be remediated efficiently.\n\nThis role is responsible for implementing and operating foundational application security controls, optimizing security tooling, and enabling security automation at scale. The ideal candidate will improve signal quality, reduce false positives, and help developers remediate the risks that matter most.\n\nResponsibilities:\nConfigure, tune, and maintain application security tools to maximize accuracy, coverage, and performance.\nEstablish and maintain security baselines, policies, and scanning rules aligned with organizational standards.\nImprove finding quality by reducing false positives and ensuring results accurately reflect business risk.\nDevelop and maintain risk-based prioritization models to focus remediation on the highest-impact vulnerabilities.\nIntegrate security tool outputs into centralized vulnerability management workflows.\nValidate findings, investigate false positives, and track remediation through closure.\nPartner with engineering teams to implement security guardrails and secure development practices.\nContinuously evaluate and optimize security tooling, processes, and platform effectiveness.\nPerform targeted security assessments of high-risk applications to identify coverage gaps and critical vulnerabilities.\nManage and optimize Web Application Firewall (WAF) and CDN security capabilities, including DDoS protection, bot mitigation, and traffic management.\nEvaluate emerging security technologies and recommend improvements to increase automation, coverage, and operational efficiency.\nDevelop and maintain technical documentation, operational runbooks, and security standards.\nSupport vulnerability response, remediation activities, and application security incident investigations.\nParticipate in Agile development, including sprint planning, backlog refinement, estimation, stand-ups, and retrospectives.\nDevelop metrics and KPIs to measure program effectiveness and drive continuous improvement.\nParticipate in a 24/7 on-call rotation, including weekends and holidays.\nCompensation and Benefits:\nThe expected compensation range for this position is between $80,200 - $134,250.\n\nLocation, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.\n\nBonus based on performance and eligibility target payout is 8% of annual salary paid out annually.\n\nPaid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.\n\nIn addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.\n\nQualifications:\nYears of Experience\nBachelor’s degree in computer science, Engineering, or a related technical field, with 3-4 years of relevant professional experiences or equivalent in job experience\nMandatory Technical Skills\nExperience with secure software development and identifying vulnerabilities within application code.\nExperience analyzing application security findings and providing actionable remediation guidance.\nHands-on experience with application security, vulnerability management, and security engineering.\nExperience securing cloud-native applications in AWS (preferred), Azure, or GCP.\nProficiency with Python and/or Go.\nExperience with SAST, SCA, Secrets, DAST, API, and Container security tools.\nExperience tuning security scanners and reducing false positives, including OWASP Top 10 findings.\nExperience deploying, configuring, and managing Web Application Firewalls (WAFs).\nKnowledge of Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or similar).\nStrong understanding of web and mobile application security, including the OWASP Top 10, SSRF, RCE, deserialization, and memory corruption vulnerabilities.\nFamiliarity with securing CI/CD pipelines and integrating security into development workflows.\nUnderstanding of API security, including OAuth, JWT, authentication, authorization, and access control.\nUnderstanding of CDN security, including DDoS protection, bot mitigation, rate limiting, and caching.\nUnderstanding of cryptographic principles, key management, and encryption best practices.\nNon-technical Skills:\nStrong written and verbal communication skills.\nHigh integrity with sound judgment and accountability.\nExcellent analytical, problem-solving, and critical thinking abilities.\nSelf-motivated, curious, and committed to continuous learning.\nStrong collaboration, relationship-building, and influencing skills.\nComfortable working in a fast-paced, global environment with changing priorities and ambiguity.\nAbility to perform effectively under pressure.\nDifferentiating Behaviors:\nDemonstrates curiosity, innovation, and a continuous improvement mindset.\nMakes sound decisions by balancing technical, business, and operational trade-offs.\nRemains calm, organized, and methodical in high-pressure situations.\nEffectively prioritizes work and manages competing commitments.\n\n>:\nOur Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.\n\nAll qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.\n\nPepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age\n\nIf you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.\n\nPlease view our Pay Transparency Statement.","company":"PepsiCo","rawCompany":"pepsico","city":"Plano","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-08-04T10:39:20.135Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Application Security | Application Security Engineer","description":"Overview:\nPepsiCo’s Global Application Security Program integrates security into software development at enterprise scale. Our mission is to make application security risks visible, actionable, and measurable so they can be remediated efficiently.\n\nThis role is responsible for implementing and operating foundational application security controls, optimizing security tooling, and enabling security automation at scale. The ideal candidate will improve signal quality, reduce false positives, and help developers remediate the risks that matter most.\n\nResponsibilities:\nConfigure, tune, and maintain application security tools to maximize accuracy, coverage, and performance.\nEstablish and maintain security baselines, policies, and scanning rules aligned with organizational standards.\nImprove finding quality by reducing false positives and ensuring results accurately reflect business risk.\nDevelop and maintain risk-based prioritization models to focus remediation on the highest-impact vulnerabilities.\nIntegrate security tool outputs into centralized vulnerability management workflows.\nValidate findings, investigate false positives, and track remediation through closure.\nPartner with engineering teams to implement security guardrails and secure development practices.\nContinuously evaluate and optimize security tooling, processes, and platform effectiveness.\nPerform targeted security assessments of high-risk applications to identify coverage gaps and critical vulnerabilities.\nManage and optimize Web Application Firewall (WAF) and CDN security capabilities, including DDoS protection, bot mitigation, and traffic management.\nEvaluate emerging security technologies and recommend improvements to increase automation, coverage, and operational efficiency.\nDevelop and maintain technical documentation, operational runbooks, and security standards.\nSupport vulnerability response, remediation activities, and application security incident investigations.\nParticipate in Agile development, including sprint planning, backlog refinement, estimation, stand-ups, and retrospectives.\nDevelop metrics and KPIs to measure program effectiveness and drive continuous improvement.\nParticipate in a 24/7 on-call rotation, including weekends and holidays.\nCompensation and Benefits:\nThe expected compensation range for this position is between $80,200 - $134,250.\n\nLocation, confirmed job-related skills, experience, and education will be considered in setting actual starting salary. Your recruiter can share more about the specific salary range during the hiring process.\n\nBonus based on performance and eligibility target payout is 8% of annual salary paid out annually.\n\nPaid time off subject to eligibility, including paid parental leave, vacation, sick, and bereavement.\n\nIn addition to salary, PepsiCo offers a comprehensive benefits package to support our employees and their families, subject to elections and eligibility: Medical, Dental, Vision, Disability, Health, and Dependent Care Reimbursement Accounts, Employee Assistance Program (EAP), Insurance (Accident, Group Legal, Life), Defined Contribution Retirement Plan.\n\nQualifications:\nYears of Experience\nBachelor’s degree in computer science, Engineering, or a related technical field, with 3-4 years of relevant professional experiences or equivalent in job experience\nMandatory Technical Skills\nExperience with secure software development and identifying vulnerabilities within application code.\nExperience analyzing application security findings and providing actionable remediation guidance.\nHands-on experience with application security, vulnerability management, and security engineering.\nExperience securing cloud-native applications in AWS (preferred), Azure, or GCP.\nProficiency with Python and/or Go.\nExperience with SAST, SCA, Secrets, DAST, API, and Container security tools.\nExperience tuning security scanners and reducing false positives, including OWASP Top 10 findings.\nExperience deploying, configuring, and managing Web Application Firewalls (WAFs).\nKnowledge of Policy-as-Code frameworks (OPA, HashiCorp Sentinel, or similar).\nStrong understanding of web and mobile application security, including the OWASP Top 10, SSRF, RCE, deserialization, and memory corruption vulnerabilities.\nFamiliarity with securing CI/CD pipelines and integrating security into development workflows.\nUnderstanding of API security, including OAuth, JWT, authentication, authorization, and access control.\nUnderstanding of CDN security, including DDoS protection, bot mitigation, rate limiting, and caching.\nUnderstanding of cryptographic principles, key management, and encryption best practices.\nNon-technical Skills:\nStrong written and verbal communication skills.\nHigh integrity with sound judgment and accountability.\nExcellent analytical, problem-solving, and critical thinking abilities.\nSelf-motivated, curious, and committed to continuous learning.\nStrong collaboration, relationship-building, and influencing skills.\nComfortable working in a fast-paced, global environment with changing priorities and ambiguity.\nAbility to perform effectively under pressure.\nDifferentiating Behaviors:\nDemonstrates curiosity, innovation, and a continuous improvement mindset.\nMakes sound decisions by balancing technical, business, and operational trade-offs.\nRemains calm, organized, and methodical in high-pressure situations.\nEffectively prioritizes work and manages competing commitments.\n\n>:\nOur Company will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the Fair Credit Reporting Act, and all other applicable laws, including but not limited to, San Francisco Police Code Sections 4901-4919, commonly referred to as the San Francisco Fair Chance Ordinance; and Chapter XVII, Article 9 of the Los Angeles Municipal Code, commonly referred to as the Fair Chance Initiative for Hiring Ordinance.\n\nAll qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.\n\nPepsiCo is an Equal Opportunity Employer: Female / Minority / Disability / Protected Veteran / Sexual Orientation / Gender Identity / Age\n\nIf you'd like more information about your EEO rights as an applicant under the law, please download the available EEO is the Law & EEO is the Law Supplement documents. View PepsiCo EEO Policy.\n\nPlease view our Pay Transparency Statement.","datePosted":"2026-08-04T10:39:20.135Z","dateModified":"2026-08-04T10:39:20.135Z","hiringOrganization":{"@type":"Organization","name":"PepsiCo","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Plano","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"3766615bc573e0ffe21e618e"},"url":"https://jobsearcher.com/jobs/3766615bc573e0ffe21e618e"}}