Jobs and Careers
TR

Cybersecurity Engineer - Web Application Firewall (open to remote)

Triumph Financial
United StatesRemotefull_timeVerifiedPosted 6 Jun 2024

About the role

Join TriumphX!

TriumphX, a member of the Triumph Financial portfolio of brands, provides a concentration of technology and project management resources the members of the Triumph Financial portfolio of brands – TriumphPay, Triumph and TBK Bank – via a shared service model. We’re looking for top tech and project management talent to analyze, recommend and build strategic solutions that support Triumph Financial’s mission to become a world-class, market-leading financial and technology company.

This is a networking requisition and not a job opening. We are in the process of networking for anticipated future job openings.

Position Summary

The web application firewall analyst provides advanced, hands-on representation of the cybersecurity defense team. Candidates for this technical role must possess a solid understanding of information security and should have held positions in cybersecurity and systems administration. The role also requires an understanding of business and governance processes.  Web application firewall (WAF) analyst analysts accept primary responsibility for the overall management lifecycle of the program.

Web application firewall analysts should understand that legacy and present-day systems and applications may have weaknesses that can be exploited by external threat actors and potentially lead to a breach. The position must collaborate with others on the team for remediation and additional validation, as well as contribute to other collaborative approaches driven by the security team strategy.

Web application firewall analysts oversee the strategic initiatives for short- as well as long-term plans to identify and reduce the attack surface across applications and systems. Use of automated tools to identify, assess and report is expected, with emphasis placed on effective communication to constituents relying on applications and systems that support their business.

Essential Duties & Responsibilities

  • Create, deploy, maintain and troubleshoot Web Application Firewalls (WAF) policies for new and existing web applications.

  • Review vulnerabilities that impact web applications and develop WAF “Virtual Patching” solutions.

  • Monitor and analyze activity logs to detect malicious internet traffic and indicators of compromise as well as to reduce false positive blocks.

  • Review WAF usage and define means to improve and mature protection policies.

  • Understand web applications at a sufficient level to work with developers to implement protective controls that may need to be customized for specific applications.

  • Interpret web protocol information to determine source, intent, and risk of threat agents.

  • Provide preventative maintenance, troubleshooting and quickly resolve problems to ensure infrastructure and application stability.

  • Participate in technical design activities to ensure a sound design and any infrastructure impact is understood.

  • Create and maintain technical documentation regarding the WAF including network diagrams, policies and operational procedures for managing the infrastructure.

  • Work closely with Development, QA, DevOPS, Operations, InfoSec, and design engineers to ensure security requirements are met and web-applications are adequately protected from cyber-attacks.

  • Review vulnerability and application scan output and assess where WAF configuration can be used to mitigate attacks.

  • Awareness of mainstream operating systems and a wide range of security technologies including network firewall, IPS, and web proxy.

  • Work as a team to consistently learn and share advanced skills and foster team excellence.

  • Support internal and external auditors in their duties that focus on compliance and risk reduction.

  • Collaborate with security groups such as red teams, threat intelligence and risk management to form a holistic team dedicated to thwarting attackers and reducing attack surface.

  • Periodically attend and participate in change management policy discussions and meetings.

  • Define key performance indicators (KPIs) and metrics across business units to illustrate effectiveness with WAF controls.

  • Understand breach and attack simulation solutions for known vulnerabilities and work with the team to validate controls effectiveness.

  • Liaise with the security engineering team to improve tool usage and workflow, as well as with the advanced threats and assessment team to mature monitoring and response capabilities.

  • Perform other duties as assigned.

Experience & Education

  • Understanding of Windows and *nix operating systems, endpoint applications, networking

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Triumph Financial

View company profile →