> Markdown version of [/jobs/ext/1182729-principal-iam-web-security-engineer](https://www.wearedevelopers.com/jobs/ext/1182729-principal-iam-web-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal IAM & Web Security Engineer - **Company:** Waters - **Location:** Milford, MA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Firewall, Software System Penetration Testing, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Python (Programming Language), Lightweight Directory Access Protocols (LDAP), Log Analysis, OAuth, Open Web Application Security, Windows PowerShell, Role-Based Access Control, Openid Connect, Azure Active Directory, Akamai, Security Assertion Markup Language (SAML), Secure Coding, Web Application Security, Security Information and Event Management, User Provisioning Software, Scripting, Okta, Software Security, Cloudflare, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** July 4, 2026 - **Apply:** https://www.careerjet.com/job/us2d8d51b57da8bde4dafa7d1b2b84ff7b/eaa ## About the Role * 3+ years of experience in a program lead role with hands-on experience in Okta/Azure AD * 5+ years of experience in implementing and managing WAF & CDN solutions using platforms such as Akamai/Cloudflare * Strong knowledge of identity protocols (SAML, OAuth2, LDAP, OpenID Connect) * Expert-level knowledge of RBAC, MFA, privileged access management, and identity governance. * Experience in OWASP Top 10, secure coding, DAST/SAST and API security * Proven experience in risk prioritization, remediation planning, and use of enterprise vulnerability scanning tools. * Strong scripting or automation skills (e.g., PowerShell, Python) * Hands-on experience with WAF management, SOC workflows, SIEM tools, and log analysis for threat detection. * Certifications: Possession of the CISSP (Certified Information Systems Security Professional) is highly preferred. ## Description Are you ready to be the primary defender of the digital experience and commerce ecosystem for a global leader in scientific discovery? Waters is seeking a Security Lead-an expert in application, and operational security-to ensure the health, integrity, and compliance of our mission-critical platforms. This is more than a security compliance job; it's a chance to embed security "left-of-boom" (in the development pipeline) while maintaining robust operational defenses against threats to our global digital backbone. You will be the technical authority ensuring our solutions scale globally and perform flawlessly, all while remaining secure. Responsibilities * Implement and manage Web Application Firewalls (WAF) and security policies, focusing on policy tuning, bot management, and rule optimization. * Align IAM configs & controls to meet compliance, and security requirements * Lead and execute secure code reviews, application penetration testing, and dynamic application security testing (DAST) to proactively identify vulnerabilities in the engineering lifecycle. * Serve as the subject matter expert on Application Security best practices, including the OWASP Top 10, secure coding standards, and API security. * Identify and track vulnerabilities across applications, coordinating remediation efforts and ensuring timely patching and risk prioritization based on business impact. * Manage user provisioning, Role-Based Access Control (RBAC), and privileged access management (PAM). * Enforce strong authentication mechanisms, including multi-factor authentication (MFA) and the principle of least privilege across all digital environments. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [What the Heck is Edge Computing Anyway?](https://www.wearedevelopers.com/videos/593-what-the-heck-is-edge-computing-anyway) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers)