Web Application Firewall (WAF) Engineer
Inmar IntelligenceAbout the role
Primary Accountabilities
Technical (80%)
Monitoring: Monitor the usage, performance and availability of the web application firewall (WAF) infrastructure and services.
Design: Maintain a comprehensive understanding of WAF design concepts, including managed rules, shared objects, exclusions and routing rules
Configure: You will be primarily responsible for the configuration, deployment and maintenance of web application firewall (WAF) deployments
Administration: Monitor and troubleshoot for security impact on performance and connectivity issues.
Compliance: Ensure compliance with security best practices and organizational policies.
Collaborate: Develop relationships and collaborate with cross-functional teams to deliver scalable and efficient security solutions.
Documentation: Document WAF configurations, deployments, standards and best practices
Policy Contribution: Collaborate with policy stakeholders to develop and enforce WAF protection
Continuous Improvement: Stay current with industry trends and advancements in WAF technologies and continuously integrate learnings into our standards and practices
Incident Response: Collaborate with the incident response team as part of the CSIRT (cyber security incident response team) to support DFIR operations, e.g. applying virtual patches and rules to address emerging threats
Education: Bachelor’s degree in computer science, Information Security, or a related field (or equivalent experience)
Certifications: One or more of the following: CCNA, CCNP, CCIE, Azure Security Engineer Associate, AWS Certified Security Specialty, Google Cloud Security Professional, GWEB, GWAPT
Experience:
Design, deploy, configure, and maintain WAF solutions to protect our web applications from various attacks, including OWASP Top 10 and Zero-Day vulnerabilities
Collaborate with application development teams to transition their apps behind the WAF. Then provide ongoing support as application design changes necessitate
Stay up to date on the latest WAF technologies, threats, and best practices
Participate in security assessments and penetration testing activities
Document WAF configurations, policies, and procedures and also create and maintain technical documentation
Assist with onboarding and training junior security engineers
3-5 years of experience in information security and 2-3 years in Web Application Security
In-depth knowledge of WAF technologies and solutions (e.g., Akamai, AWS WAF, F5 BIG-IP WAF, Imperva Secure Sphere, Cloud flare WAF)
Strong understanding of web application security concepts (OWASP Top 10, Structured Query Language (SQL) Injection, XSS, etc.)
High level understanding of web application technologies, e.g. HTTP, HTML, common web programming languages, Caching and Content Delivery Networks (CDNs)
Experience with network security concepts (firewalls, intrusion detection/prevention systems)
Experience using threat intelligence (CTI) and attacker tactics, techniques and protocols (TTP) (like MITRE ATT&CK and/or D3FEND) to inform architecture, design and configurations
Ability to write code in common programming languages, e.g. Python
Strong analytical and problem-solving skills with an ability to assimilate, analyze, and correlate large amounts of fo
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s