Security Engineer (WAF)
DevSecOps, Inc.
Atlanta, United States of America
2 days ago
Role details
Contract type
Temporary to permanent Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
Senior Compensation
$ 187KJob location
Remote
Atlanta, United States of America
Tech stack
Adobe Analytics
.NET
API
Artificial Intelligence
Amazon Web Services (AWS)
Amazon Web Services (AWS)
Data analysis
Applications Architecture
Application Firewall
Automation of Tests
Azure
Bash
Cloud Computing
Cloud Computing Security
Configuration Management
Computer Security
Software Debugging
DevOps
Github
Python
Network Security
Open Web Application Security
Performance Tuning
Systems Development Life Cycle
Ansible
Akamai
Security Information and Event Management
Systems Integration
TypeScript
Web Applications
Scripting (Bash/Python/Go/Ruby)
Google Cloud Platform
Load Balancing
Computer Network Technologies
Software Security
Multi-Cloud
Cloudformation
GWAPT
Infrastructure Automation Frameworks
Cloudflare
Api Gateway
Terraform
Splunk
Devsecops
Job description
The Security Engineer (WAF) will play a critical role in protecting web applications and APIs by managing and optimizing Web Application Firewall protections across cloud environments. This engineer will focus on hands-on WAF operations, rule tuning, automation, and security integrations within DevSecOps environments while partnering closely with engineering, product, and security teams to strengthen the organization's application security posture.
Day-to-Day Responsibilities:
- Implement, operate, and maintain WAF protections across web applications and API environments
- Write, tune, and optimize WAF rules including custom protections, bot mitigation controls, and rate limiting policies
- Apply WAF protections to specific hosts, endpoints, and API gateways as a first line of defense during security events
- Monitor and analyze WAF logs and alerts to identify malicious activity, reduce false positives, and continuously improve security posture
- Partner with Incident Response (IR) and SOC teams to support security triage by implementing WAF-based mitigations
- Collaborate with product and engineering teams to understand application architecture and embed WAF controls into system design
- Integrate WAF protections into SDLC processes and CI/CD pipelines
- Support cloud security initiatives focused on securing the application perimeter within AWS environments
- Configure and support cloud networking components including Application Load Balancers, CloudFront distributions, and API Gateways
- Develop automation scripts and tooling (primarily Python or Go) to scale WAF operations and security processes
- Deploy and manage WAF configurations using Infrastructure as Code tools such as Terraform or CloudFormation
- Contribute to GitHub repositories supporting security tooling and configuration management
- Document operational procedures, runbooks, change management processes, and incident response playbooks
- Participate in an on-call rotation supporting production security incidents and operational needs, Job Title: Service Delivery Analyst/ CMDB Administrator Location-Type: Remote working CST Start Date Is: ASAP Duration: 6 month contract to hire Job Description: The CMDB Administrator/ Service Delivery Analyst is responsible for managing and maintaini...
Requirements
Must-Have Skills/Experiences:
- 2-4 years of experience in application security, network security, or cloud security
- Hands-on experience managing Web Application Firewalls (AWS WAF strongly preferred; Cloudflare, Akamai, Fastly, Azure Front Door, or GCP Cloud Armor acceptable)
- Strong understanding of HTTP/HTTPS protocols, OWASP Top 10 vulnerabilities, and API security fundamentals
- Experience securing web applications and APIs within AWS cloud environments
- Foundational networking knowledge including firewall concepts and cloud perimeter security
- Experience applying WAF protections to API gateways, endpoints, and hostnames
- Experience analyzing security telemetry and logs using Splunk or similar SIEM tools
- Scripting experience with Python (preferred) and familiarity with Go, Bash, or TypeScript
- Experience deploying infrastructure and security configurations through Infrastructure as Code (Terraform, CloudFormation, or similar)
- Experience working within DevOps or DevSecOps environments
- Experience collaborating with IR and SOC teams to support incident response activities
- Ability to write, debug, and maintain automation code supporting security operations
- Strong communication skills with the ability to work cross-functionally with engineering, product, and operations teams
- Demonstrated ownership mindset with the ability to take initiatives from design through execution
- Ability to work onsite in a hybrid environment (3 days per week)
Nice-to-Have Skills/Experiences (NOT required, but a plus!) :
- Experience supporting multi-cloud environments (AWS, Azure, GCP)
- Experience integrating WAF protections with CDN platforms
- Security certifications such as GIAC, GWAPT, CISSP, or CSSLP
- Experience within media, entertainment, telecommunications, or financial services environments
- Experience with configuration management tools such as Ansible
- Exposure to incident response processes (not required to lead incidents)
- Strong learning mindset with interest in expanding security engineering capabilities