> Markdown version of [/jobs/ext/1754061-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/1754061-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Engineer - **Company:** Visa Inc. - **Location:** United States - **Experience:** Experienced - **Salary:** $123,700.0 - $191,300.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Microsoft Windows, Application Programming Interfaces (APIs), Amazon Web Services, Amazon Cloudfront, Application Firewall, Confluence, JIRA, Unix, C++ (Programming Language), Cyber Security, Cross-Site Request Forgery, DOS (Disk Operating System), Perl (Programming Language), Github, Intrusion Detection Systems, Python (Programming Language), Knowledge Management, Open Source Technology, Open Web Application Security, Regular Expressions, Akamai, Web Application Security, Security Software, Shell Script, Security Information and Event Management, Simple Object Access Protocol (SOAP), SQL Injection, Web Applications, Web Testing, WS-Security, Extensible Markup Language (XML), Software Repository, Scripting, Software Security, Firewalls (Computer Science), Gitlab, Cloudformation, Cross Site Scripting, Cloudflare, Functional Programming, Api Gateway, Puppet, Terraform, Ddos, Cyber Warfare, Network Server, Jenkins, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/62afe80c-12be-4d68-8f33-c3b87c8090c3 ## About the Role * Knowledge of SSDLC processes, procedures, and tools. * Knowledge of open source and commercial application security tools and frameworks, including but not limited to Kali Web application testing tools. * Experience in exploiting web apps and web services security vulnerabilities including cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks such as Broken Object Level Authorization (BOLA). * Excellent understanding of OWASP Risks, Vulnerabilities and Mitigation Mechanisms. * Strong experience with Web Application Firewall management and rules. * Excellent understanding of common network and web protocols. * Excellent understanding of DDoS, Bot, and ATO techniques and mitigation mechanisms. Cyber Defense and Incident Response: * Solid understanding of events, related fields in log records and alerts reported by various data sources such as Windows/Unix systems, IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, and web proxies. * Prior experience or support of Security Operations and Incident Response. * Excellent understanding of Cyber Security Operations and Incident Response processes. Infrastructure management and support: * System administration experience with Windows and Unix servers. * Experience working in a large enterprise environment. * Experience integrating solutions in a multi-vendor environment. * Familiarity with Atlassian JIRA. This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience Preferred Qualifications 3 or more years of work experience with a Bachelor's Degree or more than 2 years of work experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) Experience with one or more: Akamai, AWS CloudFront, Cloudflare, or other CDN solutions Experience with one or more of the following: Imperva WAF, F5 WAF, and CDN Firewall Experience with API Security solutions such as Imperva API Anywhere, Cloudflare API Shield, or other similar solutions Web Application Firewall Experience (Must have), Experience with one or more of the following: SecDevOps Experience Expertise in one or more of the following: Python, Perl, shell scripting, C++, Java, Java Script Excellent experience in creating Regular Expressions for security polices and rules Experience in maintaining and enhancing infrastructure as code with one or more of the following: CloudFormation, Terraform, Chef, Puppet, Jenkins, CodeDeploy Experience with using knowledge management and code repositories with GitHub, Gitlab, Jira, and Confluence Experience with Lambda, API Gateway, API Security controls including API Inventory, Runtime detection of threats, and Offensive Security testing or API DAST Experience with API Security solutions such as Imperva API Anywhere, Cloudflare API Shield, or other similar solutions ## Description * Web Application Security: Engineering, deployment, and operations of security solutions, including Web Application Firewalls, as well as integration of those platforms with other solutions as required. * Security Software Development: Scripting and Development in Python, Shell scripting and development in other languages. * Engineers, configures, deploys, and maintain Web Application Firewall solutions. * Develop scripts for manipulation of multiple data repositories to support analysts. * Develop alerts/reports to meet the requirements of key stakeholders. * Develops automation for security tools management and workflow integration. * Collaboration with key stakeholders within Cybersecurity Engineering teams to develop specific use cases to address web and application security requirements. * Creates WAF rules to mitigate threats and implement security best practices. * Develop and enhance SIEM content for Cybersecurity teams, including correlations, enrichments, dashboards, reports, and alerts that appropriately illustrate and characterize web application attacks and mitigation mechanisms. ## Related Videos - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)