Web Application Firewall (WAF) Engineer

Posted Yesterday
Be an Early Applicant
Winston-Salem, NC
Mid level
Fintech • Information Technology • Analytics
The Role
As a Web Application Firewall Engineer, you will design, implement, configure, and maintain WAF solutions to protect web applications. You will monitor performance, collaborate with security teams, ensure compliance with policies, document configurations, assist in incident response, and stay informed on WAF technologies and threats. You will also support and train junior engineers.
Summary Generated by Built In

We are seeking a highly motivated and experienced Web Application Firewall (WAF) Engineer (Akamai preferred) to join our established security team. In this role, you will be responsible for all aspects of our WAF deployment, including design, implementation, configuration, optimization, and ongoing maintenance. You will work closely with other security and engineering teams to ensure the protection of our web applications from evolving cyber threats. You will be leaned on to liaise with other engineering teams to integrate the WAF solution seamlessly on premise and in the cloud.

Primary Accountabilities

Technical (80%)

  • Monitoring: Monitor the usage, performance and availability of the web application firewall (WAF) infrastructure and services.

  • Design:  Maintain a comprehensive understanding of WAF design concepts, including managed rules, shared objects, exclusions and routing rules

  • Configure: You will be primarily responsible for the configuration, deployment and maintenance of web application firewall (WAF) deployments  

  • Administration: Monitor and troubleshoot for security impact on performance and connectivity issues.

  • Compliance: Ensure compliance with security best practices and organizational policies.

  • Collaborate: Develop relationships and collaborate with cross-functional teams to deliver scalable and efficient security solutions.

  • Documentation: Document WAF configurations, deployments, standards and best practices

  • Policy Contribution: Collaborate with policy stakeholders to develop and enforce WAF protection

  • Continuous Improvement: Stay current with industry trends and advancements in WAF technologies and continuously integrate learnings into our standards and practices 

  • Incident Response: Collaborate with the incident response team as part of the CSIRT (cyber security incident response team) to support DFIR operations, e.g. applying virtual patches and rules to address emerging threats

  • Education: Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience)

  • Certifications: One or more of the following: CCNA, CCNP, CCIE, Azure Security Engineer Associate, AWS Certified Security Specialty, Google Cloud Security Professional, GWEB, GWAPT

  • Experience: 

    • Design, deploy, configure, and maintain WAF solutions to protect our web applications from various attacks, including OWASP Top 10 and Zero-Day vulnerabilities

    • Collaborate with application development teams to transition their apps behind the WAF. Then provide ongoing support as application design changes necessitate

    • Stay up to date on the latest WAF technologies, threats, and best practices

    • Participate in security assessments and penetration testing activities

    • Document WAF configurations, policies, and procedures and also create and maintain technical documentation

    • Assist with onboarding and training junior security engineers

    • 3-5 years of experience in information security and 2-3 years in Web Application Security

    • In-depth knowledge of WAF technologies and solutions (e.g., Akamai, AWS WAF, F5 BIG-IP WAF, Imperva Secure Sphere, Cloud flare WAF)

    • Strong understanding of web application security concepts (OWASP Top 10, Structured Query Language (SQL) Injection, XSS, etc.)

    • High level understanding of web application technologies, e.g. HTTP, HTML, common web programming languages, Caching and Content Delivery Networks (CDNs)

    • Experience with network security concepts (firewalls, intrusion detection/prevention systems)

    • Experience using threat intelligence (CTI) and attacker tactics, techniques and protocols (TTP) (like MITRE ATT&CK and/or D3FEND) to inform architecture, design and configurations

    • Ability to write code in common programming languages, e.g. Python

    • Strong analytical and problem-solving skills with an ability to assimilate, analyze, and correlate large amounts of forensic data from various network and security devices, logs, and alerts

    • Experience in handling web application protection for a large enterprise network or service provider network

    • Experience in industry standards that are relevant to our line of business, such as NIST CSF, ISO 27001, Health Insurance Portability and Accountability Act (HIPAA), HITRUST, Payment Card Industry Data Security Standard (PCI DSS)

    • Infrastructure as Code (IaC) experience with terraform, ansible, AWS CloudFormation or similar.

    • Strong understanding of DNS, DHCP, routing, and IP addressing in cloud environments.

Project Management (20%)

  • Work with IT shared services, DevOps and application development teams to ensure secure network architecture and configuration

  • Educate and train engineering and IT teams.

  • Evaluate client needs, coordinate design for a solution, and clearly communicate the value proposition of complex and highly technical cyber security subjects.

Individual Competencies:

  • Integrity: Gains the trust of others through a strong commitment to security, compliance, taking responsibility for your own actions and telling the truth. 

  • Teamwork: Builds relationships and works cooperatively with others, inside and outside the organization, to accomplish objectives to build and maintain mutually-beneficial partnerships, leverage information and achieve results.

  • Adaptable: Responds to change with a willingness to learn new ways to accomplish work objectives with a positive attitude.

  • Innovative: Ability to develop, sponsor, or support the introduction of new and improved methods, products, procedures or technologies.

  • Curious: A desire to inquire and learn, to seek new knowledge and wisdom, and to listen to the contributions of others with a genuine interest to better self, the team, and the organization.

  • Analytical and Critical Thinking:  Ability to tackle a problem by using a logical, systematic, sequential approach.

  • Problem Solving: Gathers and analyzes information to generate and evaluate potential solutions to problems, issues and challenges while weighing the accuracy and relevance of the facts, data and information.

We are an Equal Opportunity Employer, including disability/vets.

Top Skills

Python
The Company
HQ: Winston-Salem, NC
2,044 Employees
On-site Workplace
Year Founded: 1980

What We Do

We reimagine everyday business challenges through advanced analytics, technology-enabled and market-driven solutions built to solve some of industries’ biggest obstacles to growth. Inmar Intelligence’s customer-centric approach is evident through our success helping companies dynamically engage audiences, build brand loyalty, create efficiencies and drive profitable growth.

We help leading Fortune 500 companies and emerging brands stay relevant and propel growth while providing their consumers with personalized and precision-driven tools to save money, improve health and safety, and more conveniently go about their lives.

For more than 35 years, we have served retailers, manufacturers, healthcare providers, government and employers as their trusted intermediary and helped them redefine innovation.

Similar Jobs

ServiceNow Logo ServiceNow

Staff Security Contracts Manager

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Raleigh, NC, USA
26000 Employees
129K-226K Annually

CrowdStrike Logo CrowdStrike

Sr. Systems Engineer (Remote, Eastern Time)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote
22 Locations
10000 Employees
135K-215K Annually

PwC Logo PwC

Workday Cloud Security & Controls Director

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote
Hybrid
19 Locations
364000 Employees
148K-317K Annually

PwC Logo PwC

Workday Cloud Security & Controls Sr. Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote
Hybrid
18 Locations
364000 Employees
84K-202K Annually

Similar Companies Hiring

Jobba Trade Technologies, Inc. Thumbnail
Software • Professional Services • Productivity • Information Technology • Enterprise Web • Consulting • Cloud
Chicago, IL
45 Employees
InCommodities Thumbnail
Renewable Energy • Machine Learning • Information Technology • Energy • Automation • Analytics
Austin, TX
234 Employees
HERE Thumbnail
Software • Logistics • Internet of Things • Information Technology • Computer Vision • Automotive • Artificial Intelligence
Amsterdam, NL
6000 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account