We are seeking a skilled WAF Security Engineer to design, implement, and maintain web application firewall solutions that... Read more
We are seeking a skilled WAF Security Engineer to design, implement, and maintain web application firewall solutions that protect critical applications, APIs, and digital services from evolving cyber threats. In this role, you will work closely with security, infrastructure, development, and operations teams to strengthen application security and ensure reliable protection across cloud and on-premises environments.
Your responsibilities will include configuring and tuning WAF policies, managing rulesets, reducing false positives, and responding to alerts and security incidents. You will analyse web traffic, investigate suspicious activity, and support the identification and mitigation of vulnerabilities, including injection attacks, cross-site scripting, bot activity, and denial-of-service attempts. You will also contribute to security assessments, penetration testing remediation, change management, and the development of monitoring, reporting, and incident response procedures. Keeping accurate documentation and ensuring solutions align with internal security standards and relevant regulatory requirements will be an important part of the role.
The successful candidate will have practical experience administering WAF technologies such as F5, Imperva, Cloudflare, AWS WAF, or comparable platforms, together with a solid understanding of HTTP, TLS, DNS, TCP/IP, web application architectures, APIs, and common OWASP risks. Experience with cloud security, SIEM platforms, automation, scripting, and infrastructure-as-code would be advantageous. You should be analytical, methodical, and confident working in a fast-paced environment, with the ability to communicate technical risks clearly to both technical and non-technical stakeholders. Relevant security certifications or demonstrable equivalent experience are desirable.
Read lessWellington, England, United KingdomPermanent
We are seeking a Security Engineer specialising in firewall administration and NetDevSecOps to design, implement and maintain secure,... Read more
We are seeking a Security Engineer specialising in firewall administration and NetDevSecOps to design, implement and maintain secure, resilient network infrastructure. You will play a key role in protecting applications, systems and data by developing effective security controls, improving operational processes and embedding security throughout the network and software delivery lifecycle. This is an opportunity to work across infrastructure, cloud and engineering teams in a technically varied environment.
Your responsibilities will include configuring, managing and troubleshooting enterprise firewalls, VPNs, security policies, network segmentation and traffic inspection services. You will review and optimise firewall rules, investigate security events, support incident response and contribute to vulnerability remediation and risk reduction activities. You will also help integrate security controls into CI/CD pipelines, automate infrastructure and policy deployment, and promote infrastructure-as-code and configuration management practices. The role will involve creating technical documentation, maintaining operational standards, participating in change management and supporting audits and compliance reviews.
Applicants should have solid experience administering enterprise firewall technologies and a strong understanding of TCP/IP, routing, switching, DNS, HTTP/S, VPNs and common network security principles. Practical knowledge of cloud networking, DevSecOps, CI/CD tooling, scripting or programming, and infrastructure-as-code technologies is highly desirable. Experience with automation using Python, PowerShell or similar languages, together with familiarity with security monitoring, logging and incident management, will be advantageous. You should be analytical, collaborative and comfortable working in a fast-paced environment, with the ability to communicate complex technical issues clearly to both technical and non-technical stakeholders. Relevant security or networking certifications are welcomed but not essential.
Read lessLondon, England, United KingdomContract
We are seeking a skilled WAF Security Engineer to design, implement, and maintain web application security controls across... Read more
We are seeking a skilled WAF Security Engineer to design, implement, and maintain web application security controls across a complex and evolving technology environment. You will be responsible for protecting internet-facing applications and APIs from common and emerging threats, including injection attacks, cross-site scripting, bot activity, credential abuse, and denial-of-service attempts. The role will involve configuring and tuning Web Application Firewalls, developing security policies, reviewing traffic patterns, and reducing false positives while maintaining a strong security posture and reliable application performance.
You will work closely with application development, infrastructure, cloud, networking, and security operations teams to embed protective controls throughout the software development and deployment lifecycle. Key responsibilities include analysing security alerts and event logs, investigating suspicious activity, supporting incident response, and contributing to threat hunting and vulnerability remediation. You will also create and maintain rules, dashboards, runbooks, and operational documentation; support change management; and provide clear recommendations based on risk, business impact, and industry best practice. The role may include managing WAF technologies across cloud and on-premises environments, integrating controls with SIEM and monitoring platforms, and automating routine tasks using scripting or infrastructure-as-code tools.
The successful candidate will have practical experience administering or engineering WAF solutions, with a strong understanding of HTTP, HTTPS, TLS, DNS, TCP/IP, web architectures, REST APIs, and common application security principles. Experience with OWASP Top 10 risks, bot management, rate limiting, DDoS mitigation, vulnerability assessment, and security monitoring is highly desirable. Familiarity with major cloud platforms, CI/CD pipelines, containers, automation, and scripting languages such as Python, PowerShell, or Bash will be advantageous. You should be analytical, methodical, and comfortable communicating with both technical and non-technical stakeholders. Relevant security certifications or equivalent professional experience are welcome, along with a commitment to continuous learning and improving secure, resilient digital services.
Read lessLeeds, England, United KingdomPermanent
We are seeking a WAF Security Engineer to design, implement, and maintain web application firewall protections across a... Read more
We are seeking a WAF Security Engineer to design, implement, and maintain web application firewall protections across a complex digital environment. The successful candidate will be responsible for configuring and tuning WAF policies, monitoring traffic patterns, investigating security alerts, and protecting internet-facing applications from common and emerging threats. You will work closely with application, infrastructure, network, and security teams to ensure that security controls are effective while supporting reliable application performance and availability.
Key responsibilities include developing and maintaining WAF rules, signatures, access controls, rate-limiting policies, bot-management controls, and virtual patching measures. You will analyse logs and security events, identify false positives and malicious activity, and recommend improvements to detection and prevention capabilities. The role will also involve supporting incident response activities, conducting root-cause analysis, documenting security decisions, and assisting with vulnerability remediation and application onboarding. You will contribute to security reviews, change management, operational reporting, and the continuous improvement of monitoring, alerting, and response procedures.
Applicants should have practical experience administering or engineering WAF technologies, preferably within large-scale, highly available environments. Strong knowledge of HTTP, HTTPS, TLS, DNS, TCP/IP, web application architectures, reverse proxies, and common attack techniques such as injection, cross-site scripting, credential abuse, and denial-of-service attacks is required. Experience with cloud platforms, CDN services, API security, automation, and scripting using tools such as Python, PowerShell, or Bash would be advantageous. Familiarity with OWASP guidance, SIEM platforms, vulnerability management, and security frameworks is desirable. Excellent analytical, communication, and documentation skills are essential, along with the ability to manage priorities, collaborate across technical teams, and participate in an on-call or out-of-hours support rota when required.
Read lessManchester, England, United KingdomPermanent
We are seeking a WAF Security Engineer to design, implement, and maintain web application firewall protections across a... Read more
We are seeking a WAF Security Engineer to design, implement, and maintain web application firewall protections across a complex digital environment. You will help safeguard customer-facing applications, APIs, and online services from threats including automated attacks, injection attempts, bot activity, data leakage, and application-layer denial-of-service attacks. The role will involve working closely with application, infrastructure, cloud, DevOps, and security teams to ensure that protective controls are effective, resilient, and aligned with business requirements.
Key responsibilities include developing and tuning WAF policies, rules, signatures, exclusions, and rate-limiting controls; analysing security events, traffic patterns, and false positives; and responding to alerts and incidents involving web-based threats. You will conduct regular reviews of WAF performance and coverage, recommend improvements, and support the secure onboarding of new applications and APIs. The role also includes investigating complex attacks, contributing to incident response and root-cause analysis, maintaining accurate documentation, and producing operational and security reports. You may also support vulnerability management, penetration testing activities, threat modelling, and the integration of WAF technologies with SIEM, SOAR, monitoring, and ticketing platforms.
Applicants should have practical experience administering and troubleshooting enterprise WAF platforms, with a strong understanding of HTTP, HTTPS, TCP/IP, DNS, TLS, reverse proxies, load balancers, and web application architectures. Knowledge of OWASP Top 10 risks, API security, bot management, DDoS mitigation, common attack techniques, and secure development practices is essential. Experience with cloud environments, automation, scripting, infrastructure as code, and security monitoring tools would be highly advantageous. Strong analytical and communication skills are required, together with the ability to explain technical risks clearly, manage competing priorities, and collaborate effectively with technical and non-technical stakeholders. Relevant security certifications or demonstrable equivalent experience are welcomed.
Read lessEdinburgh, Scotland, United KingdomPermanent
All your saved jobs are no longer available or you've already applied.
for the following search criteria