> Markdown version of [/jobs/ext/1885128-security-engineer-web-application-network-protection](https://www.wearedevelopers.com/jobs/ext/1885128-security-engineer-web-application-network-protection). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Web Application & Network Protection - **Company:** Revel IT - **Location:** Merrillville, IN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Applications Architecture, User Authentication, Cloud Computing, Cloud Computing Security, Cyber Security, Cross-Site Request Forgery, DDoS Mitigation, Domain Name System (DNS), Virtual Private Networks (VPN), Python (Programming Language), Network Security, Network Segmentation, Open Web Application Security, Web Application Security, SQL Injection, Software Vulnerability Management, Web Applications, Transport Layer Security, Captcha, Software Security, Cross-Site Scripting (XSS), Rate Limiting, Git, Kubernetes, Palo Alto Networks, Restful APIs, Terraform, Devsecops - **Published:** August 1, 2026 - **Apply:** https://www.techlifecolumbus.com/job/37200-senior-security-engineer-web-application-network-protection-1060305-merrillville-indiana/ ## About the Role * Experience with: * Bot Management * API Security * DDoS Protection * CDN technologies * DevSecOps * CI/CD pipelines * Kubernetes * Containers * Terraform Certifications: * OWASP Foundation certifications * ISC2 CISSP * GIAC certifications * F5 certifications * Palo Alto Networks certifications ## Description We are seeking a Senior Cybersecurity Engineer in Merrillville, IN to lead the design, implementation, and support of enterprise web application and network security solutions. This role will be responsible for securing internet-facing applications through F5 Distributed Cloud WAF, API security, bot protection, and network security technologies including Palo Alto firewalls and secure remote access solutions. The ideal candidate possesses a blend of application security, network security, and cloud security experience and is passionate about protecting critical enterprise services., * Web Application Security * Administer and support F5 Distributed Cloud (XC) WAF platform. * Deploy and maintain WAF policies, signatures, and security controls. * Configure: + API Protection + Bot Defense + DDoS Mitigation + Geolocation Policies + Rate Limiting + CAPTCHA Challenges * Investigate and tune false positives. * Perform application onboarding into WAF services. * Conduct WAF policy reviews and optimization. * Support incident response involving web application attacks. * Application Security * Understand and mitigate: + OWASP Top 10 + Authentication attacks + API abuse + Credential stuffing + Session hijacking + Cross-Site Scripting (XSS) + SQL Injection + SSRF + CSRF * Review application architectures and recommend security improvements. * Partner with development teams during application onboarding and troubleshooting. * Network Security * Administer and support: + Palo Alto Networks NGFW + Prisma Access + Site-to-site VPNs + SSL decryption + NAT and security policies * Network segmentation * DNS and routing troubleshooting * Support production incidents and participate in on-call rotation. * Cloud & Automation * Develop automation using: + Python + REST APIs + Terraform + Git * Build dashboards and reporting around security posture. * Automate repetitive operational tasks. * Security Operations * Participate in: + Incident response + Threat hunting + Security assessments + Vulnerability remediation + Root cause analysis + Architecture reviews ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [From clicks to cribs - How to find your dream home with web scraping](https://www.wearedevelopers.com/videos/767-from-clicks-to-cribs-how-to-find-your-dream-home-with-web-scraping) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [The Overflow: 5 Security and Privacy Tools for Developers](https://www.wearedevelopers.com/magazine/710-the-overflow-5-security-and-privacy-tools-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)