Cloud RTB WAF Engineer

Vallum Associates
Sheffield, UK
25 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Agile Methodology Amazon Web Services Microsoft Azure Big Data Business Process Modeling Cloud Computing Cloud Engineering Cyber Security Log Analysis Cloud Services Akamai Web Application Security
+9 more
Web Applications SSL Certificate Management Data Logging Google Cloud Cloud Platform System Delivery Pipeline Rate Limiting Software Version Control Devsecops

Job description

Overview

The Cloud RTB WAF Engineer will work on the ECB Programme to deploy WAF solutions on all Bank domains and related names, covering internet-facing and internal web applications to meet regulatory requirements.

Role is part of the Run The Bank team. Using the Agile framework, you will work closely with Global Business Teams for custom rules and exception handling, advise teams on false positive analysis and baseline policy updates. You will maintain communications with Vendor teams as well as the Bank Cloud Platform Leads. You will service existing and new requests for WAF, manage multiple requests, and coordinate with Change Teams and other stakeholders to ensure seamless implementation.

DevSecOps support for maintaining automation pipelines and delivery work, identifying additional automation use cases for RTB to streamline processes.

You will form key relationships with senior stakeholders from the Business, Cloud Teams, Compliance and Cyber, and work closely with Project Managers on early risk identification, status reporting, and escalation where required.

Responsibilities

  • Work with the Run The Bank team and Global Business Teams for custom WAF rules and exception handling; perform false positive analysis and update baseline policies.
  • Maintain communications with Vendor teams and Bank Cloud Platform Leads; serve WAF requests and resolve service issues; coordinate with Change Teams and other stakeholders for seamless implementation.
  • Provide DevSecOps support for automation pipelines and identify additional automation use cases to streamline processes.
  • Engage with senior stakeholders across Business, Cloud, Compliance and Cyber; provide risk identification, status reporting and escalation as needed.

Ideal Candidate

  • Extensive experience with Web Application Security log analysis, from a Cyber SOC/CSIRT background, aiming to become a WAF Engineering SME across CN WAF (AWS, Azure, GCP, Modsec) and Multi-Vendor WAF products (F5, Akamai, etc.).

Core skills / Technical requirements

  • Strong experience with multiple WAF solutions for edge, cloud, and on-premises.
  • Strong experience with cloud services and their WAF controls (AWS, Azure, GCP).
  • Strong understanding of web application security attack methods and mitigations.
  • Proficiency in WAF tuning and configuration with a solid foundation in web security principles.
  • Develop custom WAF rules and features to address gaps and enhance security.
  • Design and implement bespoke WAF processes and documentation with a thorough understanding of web security.
  • Analytical skills to align platforms with MVP and Baseline Configurations, leveraging deep knowledge of WAF functionalities.
  • Provide DevSecOps pipeline maintenance support for automation work.
  • Familiarity with IDAM protocols and access control for WAF management, backed by web security knowledge.
  • Understanding of HTTPS inspection, termination and certificate management.
  • Experience with rate limiting techniques and integration into security configs.
  • Experience with version control and update mechanisms for WAF solutions.
  • Ability to document platform and organizational logging options with security implications in cloud environments.
  • Experience interfacing with SOC during WAF-related security incidents.
  • General connectivity, network issue management and service management experience.

Other skills

  • Attention to detail when analysing large data sets.
  • Excellent interpersonal and communication skills (written and verbal).
  • Experience working in Agile or knowledge of its principles.
  • Experience on Information Security / Cyber Security / IT Security projects and Infrastructure projects is desirable.

Kind Regards

Senior Delivery Consultant

Office:

Email:

Seniority level

  • Mid-Senior level

Employment type

  • Contract

Job function

  • Industries: Banking

Referrals increase your chances of interviewing at Vallum Associates by 2x

Sign in to set job alerts for “Cloud Engineer” roles.

Location: Sheffield, England, United Kingdom

Posted: 1 month ago

Requirements

  • Extensive experience with Web Application Security log analysis, from a Cyber SOC/CSIRT background, aiming to become a WAF Engineering SME across CN WAF (AWS, Azure, GCP, Modsec) and Multi-Vendor WAF products (F5, Akamai, etc.)., * Strong experience with multiple WAF solutions for edge, cloud, and on-premises.
  • Strong experience with cloud services and their WAF controls (AWS, Azure, GCP).
  • Strong understanding of web application security attack methods and mitigations.
  • Proficiency in WAF tuning and configuration with a solid foundation in web security principles.
  • Develop custom WAF rules and features to address gaps and enhance security.
  • Design and implement bespoke WAF processes and documentation with a thorough understanding of web security.
  • Analytical skills to align platforms with MVP and Baseline Configurations, leveraging deep knowledge of WAF functionalities.
  • Provide DevSecOps pipeline maintenance support for automation work.
  • Familiarity with IDAM protocols and access control for WAF management, backed by web security knowledge.
  • Understanding of HTTPS inspection, termination and certificate management.
  • Experience with rate limiting techniques and integration into security configs.
  • Experience with version control and update mechanisms for WAF solutions.
  • Ability to document platform and organizational logging options with security implications in cloud environments.
  • Experience interfacing with SOC during WAF-related security incidents.
  • General connectivity, network issue management and service management experience., * Attention to detail when analysing large data sets.
  • Excellent interpersonal and communication skills (written and verbal).
  • Experience working in Agile or knowledge of its principles.
  • Experience on Information Security / Cyber Security / IT Security projects and Infrastructure projects is desirable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:28 min

Defining big data and machine learning fundamentals

Ayon Roy · LIVE

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

2:10 min

Why organizations combine big data and machine learning

Ayon Roy · LIVE

Videos

See all

Related articles

See all