WAF Security Engineer
We are seeking a skilled WAF Security Engineer to design, implement, and maintain web application security controls across a complex and evolving technology environment. You will be responsible for protecting internet-facing applications and APIs from common and emerging threats, including injection attacks, cross-site scripting, bot activity, credential abuse, and denial-of-service attempts. The role will involve configuring and tuning Web Application Firewalls, developing security policies, reviewing traffic patterns, and reducing false positives while maintaining a strong security posture and reliable application performance.
You will work closely with application development, infrastructure, cloud, networking, and security operations teams to embed protective controls throughout the software development and deployment lifecycle. Key responsibilities include analysing security alerts and event logs, investigating suspicious activity, supporting incident response, and contributing to threat hunting and vulnerability remediation. You will also create and maintain rules, dashboards, runbooks, and operational documentation; support change management; and provide clear recommendations based on risk, business impact, and industry best practice. The role may include managing WAF technologies across cloud and on-premises environments, integrating controls with SIEM and monitoring platforms, and automating routine tasks using scripting or infrastructure-as-code tools.
The successful candidate will have practical experience administering or engineering WAF solutions, with a strong understanding of HTTP, HTTPS, TLS, DNS, TCP/IP, web architectures, REST APIs, and common application security principles. Experience with OWASP Top 10 risks, bot management, rate limiting, DDoS mitigation, vulnerability assessment, and security monitoring is highly desirable. Familiarity with major cloud platforms, CI/CD pipelines, containers, automation, and scripting languages such as Python, PowerShell, or Bash will be advantageous. You should be analytical, methodical, and comfortable communicating with both technical and non-technical stakeholders. Relevant security certifications or equivalent professional experience are welcome, along with a commitment to continuous learning and improving secure, resilient digital services.
WAF Security Engineer
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- Security Engineer
- Security Analyst
- Security Architect
- IT Security Manager
- Security Consultant
- SOC Analyst
- Identity Access Management IAM
- Cyber Security Consultant
- Cloud Security
- Application Security
- Incident Response
- Penetration Tester
LATEST JOBS
- Security Engineer (Contractor)
- Vice President, Field CISO Com...
- Microsoft 365 & Security Infra...
- Senior ICT Security Designer
- Data Protection Expert
- Data Protection Officer: Schoo...
- Data Protection Officer
- IT CONSULTANT (IT Management,...
- Technology and Cyber Employee...
- Cyber Security Consultant
- Cyber Security Consultant (Pen...
- Platform and Services Engineer...