Security Engineer- Web Application Firewall
Role details
Job location
Tech stack
Job description
This is a fully remote position, allowing you to work from home or location of record within the U.S. with no in-office requirements. You must be available five days per week during designated work hours. The work arrangement for this role is subject to change based on business needs and individual performance. This may include adjustments to on-site requirements or schedule expectations, as necessary., The Sr. Security Engineer (WAF) is responsible for architecting, implementing, and continuously improving application-layer security controls across Paylocity's SaaS platforms. This role operates within the newly established Product Security function and focuses on protecting web, API, and AI workflows beyond traditional authentication boundaries., This position requires deep expertise in Web Application Firewall technologies, Layer 7 threat patterns, and behavioral abuse mitigation. The Sr. Security Engineer (WAF) will lead enforcement strategy, mature detection capabilities, and serve as a subject matter expert for application-layer risk, working closely with Product, Engineering, Infrastructure, and Security teams. The role also plays a key part in supporting Product Security Incident Response (PSIRT)., The below represents the primary duties of the position; others may be assigned as needed. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.
- Architect, implement, and maintain Web Application Firewall (WAF) protections across web and API endpoints.
- Lead strategy and tuning for rate limiting, bot mitigation, and automation abuse prevention.
- Design scalable enforcement models for high-risk workflows including authentication, reporting/export, file uploads, and administrative functions.
- Analyze application-layer traffic patterns to identify behavioral anomalies, scraping activity, credential abuse, and logic misuse.
- Partner with Product and Engineering teams to ensure enforcement decisions align with intended business logic and user experience.
- Support and help operationalize Product Security Incident Response (PSIRT) for application-layer events.
- Develop investigation playbooks and continuously refine rule sets based on incident learnings.
- Optimize enforcement coverage while minimizing false positives and customer friction.
- Conduct periodic architecture and rule reviews to ensure controls evolve with emerging attack patterns and platform growth.
- Provide technical leadership and mentorship within the Product Security team on application-layer protection strategies.
Requirements
-
Bachelor's degree in information security, Computer Science, or a related discipline required.
-
Minimum 7 years of experience in application security, WAF engineering, or edge security roles.
-
Deep hands-on experience with enterprise WAF platforms across both on-premises and cloud-based environments (F5, Akamai, Imperva, AWS WAF, Cloud-based edge platforms, or equivalent).
-
Experience leading or participating in WAF modernization initiatives, including migration from legacy, appliance-based architectures to scalable, distributed or cloud-aligned enforcement models.
-
Strong understanding of DNS fundamentals and DNS security concepts, including authoritative vs. recursive resolution, DNS-based attack vectors, DNSSEC, and traffic steering considerations.
-
Strong expertise in OWASP Top 10 and OWASP API Security Top 10. Experience protecting large-scale, multi-tenant SaaS applications and high-volume web/API environments.
-
Proven experience designing and tuning rate limiting, bot mitigation, and automation detection controls.
-
Experience investigating and responding to application-layer security incidents. Strong understanding of HTTP, TLS, API architectures, session handling, identity flows, and Layer 7 attack patterns.
-
Experience integrating WAF and application-layer telemetry into SIEM or observability platforms.
-
Experience working in hybrid architectures spanning data center and cloud environments preferred.
-
Experience with scripting (Python, PowerShell, Bash, etc.) for automation and rule management is a plus
-
Foundational knowledge of AI/ML principles and their impact on modern application-layer threat landscapes.
Physical requirements
- Ability to sit for extended periods: The role requires sitting at a desk or workstation for long periods, typically 7-8 hours a day.
- Use of computer and phone systems: The employee must be able to operate a computer, use phone systems, and type. This includes using multiple software programs and inquiries simultaneously.
Benefits & conditions
The base pay range for this position is $101,100k - $150k/yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via www.paylocity.com/careers.