> Markdown version of [/jobs/ext/1312609-security-engineer-cloud-web-protection](https://www.wearedevelopers.com/jobs/ext/1312609-security-engineer-cloud-web-protection). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Cloud & Web Protection - **Company:** AllSTEM Connections - **Location:** Ontario, CA, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Applications Architecture, User Authentication, Automation of Tests, Cloud Computing, Complex Networks, Cyber Security, Continuous Integration, DDoS Mitigation, Python (Programming Language), Network Security, Network Architecture, Network Segmentation, Open Web Application Security, Zero Trust Network Access, Web Application Security, SQL Injection, Web Applications, Transport Layer Security, Software Security, Cyber Threat Analysis, Firewalls (Computer Science), Cross-Site Scripting (XSS), Rate Limiting, Git, Containerization, Kubernetes, Drilldown, Restful APIs, Terraform, Devsecops, Security Orchestration, Automation & Response, Web Api - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/ecf1541c-ec04-4628-8261-ab52b383cf6e ## About the Role Experience Baseline: 5+ years of combined experience in web application and network security. Technical Mastery: Hands-on experience with enterprise-grade WAF/DDoS mitigation platforms and Next-Generation Firewalls (NGFW). Automation: Demonstrated ability to build security automation with Terraform, Python, and Git. AppSec Core: Strong understanding of authentication attacks, SQLi, XSS, and API-specific vulnerabilities. Preferred Attributes Experience securing Kubernetes and containerized environments. Experience within a DevSecOps/CI/CD culture, including integrating automated security scanning into development workflows. Industry certifications (e.g., CISSP, GIAC, or vendor-specific security architecture certifications). A "threat-hunting" mindset-the ability to identify patterns in traffic that suggest malicious intent rather than just reacting to alerts. ## Description This is a high-impact role for an engineer who thrives at the intersection of network architecture and application-layer defense. You will not only manage the security platforms but also drive automation and DevSecOps integration, ensuring that as our application architecture evolves, our security posture scales with it. If you are passionate about protecting critical services from sophisticated automated threats, we want to hear from you., Application & Edge Security Edge Protection: Lead the administration of enterprise WAF and CDN platforms. Deploy and tune security policies to defend against OWASP Top 10, API abuse, credential stuffing, and advanced bot threats. API Security: Architect and manage security controls for API endpoints, including rate limiting, schema validation, and traffic anomaly detection. Incident Response: Provide high-level support for web application security incidents. Conduct deep-dive analysis on false positives and tune detection logic to minimize disruption to production traffic. Network & Cloud Perimeter Infrastructure Security: Administer and support Next-Generation Firewall (NGFW) environments, secure remote access/ZTNA solutions, and complex network routing policies. Network Segmentation: Design and implement robust segmentation and SSL decryption strategies to maintain visibility into encrypted traffic without compromising performance. Operations & On-Call: Participate in an on-call rotation to provide rapid response for production-critical network or application security incidents. Automation & DevSecOps Security as Code: Develop automation scripts using Python and REST APIs to streamline security workflows. Manage security infrastructure using Terraform and integrate security checks into CI/CD pipelines. Dashboards & Reporting: Build real-time dashboards to provide leadership with visibility into our security posture, threat trends, and remediation metrics. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Web APIs you might not know about](https://www.wearedevelopers.com/videos/281-web-apis-you-might-not-know-about) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)