> Markdown version of [/jobs/ext/2801412-waf-application-security-engineer-sheffield-uk](https://www.wearedevelopers.com/jobs/ext/2801412-waf-application-security-engineer-sheffield-uk). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # waf & application security engineer - sheffield, uk. - **Company:** Randstad UK - **Location:** Sheffield, UK - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Application Programming Interfaces (APIs), Application Firewall, Software System Penetration Testing, Cyber Security, Continuous Integration, Open Web Application Security, Reverse Engineering, Web Application Security, Software Security, Devsecops, Programming Languages - **Published:** September 9, 2026 - **Apply:** https://www.randstad.co.uk/jobs/waf-application-security-engineer-sheffield-uk_sheffield_47407358/ ## About the Role * 7-11 years of Cyber Security experience. * Mandatory Skills: Deep knowledge of Web Security (OWASP), and CI/CD Architecture. * Strong background in Ethical Hacking / Penetration Testing. * Proven ability to write custom WAF rules and automate security testing. * Proficiency in at least one programming language and strong DevSecOps principles. ## Description The Role: We need a defender who thinks like a hacker. You will act as the WAF Subject Matter Expert for a global banking leader, utilizing your offensive security skills to build robust defenses. You will be responsible for crafting, testing, and automating advanced Web Application Firewall (WAF) solutions to protect critical infrastructure from complex web and API attacks., * Develop and refine complex, custom WAF rules to mitigate vulnerabilities and close security gaps. * Reverse-engineer attacker tactics to proactively counter evasions. * Write code to build testing mechanisms and seamlessly integrate them into CI/CD pipelines. * Advise engineering teams on OWASP Top 10, emerging threats, and DevSecOps best practices. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)