Security Engineer - Web Application & Network Protection
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+17 more
Job description
- Web Application Security
- Administer and support F5 Distributed Cloud (XC) WAF platform.
- Deploy and maintain WAF policies, signatures, and security controls.
- Configure:
- API Protection
- Bot Defense
- DDoS Mitigation
- Geolocation Policies
- Rate Limiting
- CAPTCHA Challenges
- Investigate and tune false positives.
- Perform application onboarding into WAF services.
- Conduct WAF policy reviews and optimization.
- Support incident response involving web application attacks.
- Application Security
- Understand and mitigate:
- OWASP Top 10
- Authentication attacks
- API abuse
- Credential stuffing
- Session hijacking
- Cross-Site Scripting (XSS)
- SQL Injection
- SSRF
- CSRF
- Review application architectures and recommend security improvements.
- Partner with development teams during application onboarding and troubleshooting.
- Network Security
- Administer and support:
- Palo Alto Networks NGFW
- Prisma Access
- Site-to-site VPNs
- SSL decryption
- NAT and security policies
- Network segmentation
- DNS and routing troubleshooting
- Support production incidents and participate in on-call rotation.
- Cloud & Automation
- Develop automation using:
- Python
- REST APIs
- Terraform
- Git
- Build dashboards and reporting around security posture.
- Automate repetitive operational tasks.
- Security Operations
- Participate in:
- Incident response
- Threat hunting
- Security assessments
- Vulnerability remediation
- Root cause analysis
- Architecture reviews
Requirements
We are seeking a Senior Cybersecurity Engineer to lead the design, implementation, and support of enterprise web application and network security solutions. This role will be responsible for securing internet-facing applications through F5 Distributed Cloud WAF, API security, bot protection, and network security technologies including Palo Alto firewalls and secure remote access solutions. The ideal candidate possesses a blend of application security, network security, and cloud security experience and is passionate about protecting critical enterprise services., * Experience with:
- Bot Management
- API Security
- DDoS Protection
- CDN technologies
- DevSecOps
- CI/CD pipelines
- Kubernetes
- Containers
- Terraform
Certifications:
- OWASP Foundation certifications
- ISC2 CISSP
- GIAC certifications
- F5 certifications
- Palo Alto Networks certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.techlifecolumbus.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Dev Digest 134 - Where pixels sing?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking