waf & application security engineer - sheffield, uk.

Randstad UK
Sheffield, UK
16 days ago
Apply on www.randstad.co.uk
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Application Firewall Software System Penetration Testing Cyber Security Continuous Integration Open Web Application Security Reverse Engineering Web Application Security Software Security Devsecops Programming Languages

Job description

The Role: We need a defender who thinks like a hacker. You will act as the WAF Subject Matter Expert for a global banking leader, utilizing your offensive security skills to build robust defenses. You will be responsible for crafting, testing, and automating advanced Web Application Firewall (WAF) solutions to protect critical infrastructure from complex web and API attacks., * Develop and refine complex, custom WAF rules to mitigate vulnerabilities and close security gaps.

  • Reverse-engineer attacker tactics to proactively counter evasions.
  • Write code to build testing mechanisms and seamlessly integrate them into CI/CD pipelines.
  • Advise engineering teams on OWASP Top 10, emerging threats, and DevSecOps best practices.

Requirements

  • 7-11 years of Cyber Security experience.
  • Mandatory Skills: Deep knowledge of Web Security (OWASP), and CI/CD Architecture.
  • Strong background in Ethical Hacking / Penetration Testing.
  • Proven ability to write custom WAF rules and automate security testing.
  • Proficiency in at least one programming language and strong DevSecOps principles.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.randstad.co.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:15 min

Scaling DevSecOps and researching mobile application security standards

Moataz Nabil Moataz Nabil · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all