Akamai WAF Security Engineer

Techneptune Consulting Inc
New York, United States
25 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kona Site Defender Application Programming Interfaces (APIs) Artificial Intelligence Application Firewall Botnet Cyber Security DDoS Mitigation Domain Name System (DNS) Open Web Application Security Akamai Web Application Security Software Engineering
+6 more
Enterprise Software Applications Load Balancing Large Language Models Software Security Firewalls (Computer Science) Ddos

Job description

We are seeking an experienced Akamai WAF Security Engineer with 5+ years of hands-on experience implementing, managing, and optimizing Akamai Web Application Firewall (WAF) solutions. The ideal candidate will lead enterprise application onboarding and migration to Akamai WAF, perform WAF policy tuning, support AI/LLM and API security initiatives, and collaborate with cross-functional teams to enhance web application security across the organization., * Lead onboarding and migration of internet-facing applications to Akamai Kona Site Defender (WAF).

  • Coordinate with application, DNS, load balancer, firewall, proxy, and QA teams to execute application migrations, testing, cutovers, and rollback plans.
  • Analyze WAF events, investigate false positives, and tune security policies while minimizing business impact.
  • Review production traffic, blocked requests, and implement targeted policy exceptions where appropriate.
  • Support AI/LLM workloads and API security, including troubleshooting AI-generated traffic, designing compensating controls, and implementing API-specific protections.
  • Monitor and analyze security events across WAF, Bot Manager, API Security, Client Reputation, and DDoS platforms.
  • Conduct quarterly security reviews, WAF upgrades, policy optimization, and migration from monitor mode to deny mode.
  • Investigate production incidents, application latency, traffic routing, load balancer interactions, and WAF-related outages.
  • Provide security architecture guidance on OWASP Top 10, API security, bot mitigation, DDoS protection, and secure web application design.
  • Partner with application owners, infrastructure teams, auditors, risk management, and security leadership to track onboarding progress and remediation activities.
  • Develop dashboards and metrics for WAF adoption, security exceptions, bot mitigation effectiveness, API discovery, and attack trends.
  • Serve as the primary technical liaison with Akamai, supporting product enhancements, troubleshooting, roadmap discussions, and pilot deployments.

Requirements

  • 5+ years of hands-on experience with Akamai Web Application Security.
  • Strong experience with Akamai Kona Site Defender (KSD).
  • Experience with Akamai Bot Manager.
  • Experience with Akamai API Security.
  • Strong understanding of OWASP Top 10 web application security risks.
  • Experience in WAF policy tuning, false-positive analysis, and security event monitoring.
  • Experience responding to production security incidents and troubleshooting WAF-related issues.
  • Knowledge of DNS, Load Balancers, Reverse Proxies, Firewalls, SSL/TLS, and HTTP/HTTPS protocols.
  • Excellent communication and stakeholder management skills.

Preferred Skills

  • Experience with AI/LLM Security.
  • Hands-on experience with Akamai Firewall for AI.
  • Enterprise-scale WAF migration and application onboarding experience.
  • Experience in the Financial Services domain.
  • Knowledge of API security, bot mitigation, DDoS protection, and Client Reputation controls.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

2:32 min

Dependency risks in widespread NPM supply chain attacks

Chris Heilmann +2 · LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:34 min

Protecting application endpoints with web firewalls and edge networks

Florian Mair Florian Mair · World Congress 2024

1:58 min

Application performance and its direct business impact

Jérôme Vieilledent · LIVE

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

Videos

See all

Related articles

See all