Akamai WAF Security Engineer

Momento USA LLC
Alpharetta, GA, United States
2 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Kona Site Defender Application Programming Interfaces (APIs) Artificial Intelligence Cyber Security DDoS Mitigation Domain Name System (DNS) Open Web Application Security Performance Tuning Akamai Web Application Security SQL Injection Load Balancing
+4 more
Large Language Models Software Security Firewalls (Computer Science) Ddos

Job description

  • Work with application, DNS, load balancer, proxy, firewall, and QA teams to migrate applications into monitor/alert mode and ultimately deny mode.
  • Coordinate testing, rollout plans, traffic cutovers, validation, and rollback procedures.
  1. WAF Policy Tuning & False Positive Analysis * Analyze production traffic and WAF events to identify false positives. * Tune security policies to reduce business impact while maintaining strong protection. * Review blocked requests, investigate application behavior, and create narrowly scoped exceptions when justified.

  2. AI, LLM & API Security Support * Troubleshoot AI- and LLM-related traffic that triggers WAF protections, such as SQL injection controls. * Work with application teams and vendors to design compensating controls, header-based attestation mechanisms, and API-specific protections. * Evaluate emerging Akamai AI security capabilities, including AI-powered detections, Firewall for AI, bot identification, and agentic AI protections.

  3. Security Event Monitoring & Threat Analysis * Review WAF, Bot Manager, DDoS, Client Reputation, and API Security events. * Analyze attack patterns and determine whether activity is malicious or legitimate. * Recommend policy improvements and mitigations based on observed threats.

  4. Quarterly Security Reviews & Platform Upgrades * Conduct structured reviews of applications protected by Akamai. * Evaluate opportunities to move applications from monitoring to mitigation mode. * Perform quarterly WAF upgrades, policy reviews, and security-control tuning to keep protections aligned with current threat intelligence.

  5. Incident Response & Troubleshooting * Assist with production incidents where application behavior changes after WAF enablement. * Investigate latency issues, traffic-routing problems, load-balancer interactions, client IP handling, surge queue events, and application outages. * Coordinate with Akamai engineering resources and internal teams to identify root causes and corrective actions.

  6. Security Architecture & Design Consulting * Advise application teams on secure web architectures, OWASP protections, API security, bot mitigation, client reputation controls, and DDoS protection. * Provide guidance on best practices for onboarding, secure application design, and remediation of web vulnerabilities.

  7. Program Management & Stakeholder Engagement * Partner with application owners, infrastructure teams, auditors, risk managers, and security leadership. * Track onboarding progress, risks, dependencies, and remediation activities through program governance and ticketing systems. * Present status updates, metrics, risks, and remediation plans to senior management.

  8. Operational Metrics & Reporting * Produce dashboards and reporting covering:

  • WAF adoption
  • Deny-mode coverage
  • Bot mitigation effectiveness
  • API discovery
  • Security exceptions
  • Attack activity
  • Measure onboarding progress, control effectiveness, and risk reduction across the organization.
  1. Vendor Liaison & Technology Roadmap Guidance * Act as the primary interface between the enterprise and Akamai. * Engage Akamai product teams on product defects, enhancement requests, AI roadmap discussions, policy recommendations, and complex troubleshooting. * Evaluate new Akamai capabilities and coordinate pilot deployments where appropriate.

Requirements

  • 5+ years of Akamai experience
  • Akamai Kona Site Defender
  • Akamai Bot Manager
  • Akamai API Security
  • OWASP Top 10
  • Incident response experience, * AI/LLM security
  • Akamai Firewall for AI
  • Enterprise-scale migration experience
  • Financial services experience

About the company

Momento USA is a global technology consulting, talent acquisition and creative development firm that addresses clients most pressing needs and challenges., Yousuf M Technical Recruiter. Momento USA | Exceeding Customer Expectations 440 Benigno Blvd, Unit #A 2nd Floor. Bellmawr, NJ 08031 Interstate Business Park Direct: Fax: Email: LinkedIn: Web: Minority Certified by SWAM National Minority Certified by NMSDC One of the fastest growing company in NJ Awarded fastest growing Asian American business by Diversitybusiness.com E-verified Company Information transmitted by this e-mail is proprietary to Momento USA and/ or its Customers and is intended for use only by the individual or entity to which it is addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If you are not the intended recipient or it appears that this mail has been forwarded to you without proper authority, you are notified that any use or dissemination of this information in any manner is strictly prohibited. In such cases, please notify us immediately at and delete this mail from your records. Note: Momento USA is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:34 min

Leveraging Akamai edge workers for broad geographic scale

Austin Gil · LIVE

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann Chris Heilmann +2 · LIVE

2:10 min

Comparing prompt injection to traditional SQL injection attacks

Sebastian Schrittwieser · World Congress 2023

1:28 min

Security risks involving prompt injection attacks

Cheuk Ho · World Congress 2023

4:58 min

Scaling security teams through developer advocates

Tanya Janca · World Congress 2021

1:58 min

Application performance and its direct business impact

Jérôme Vieilledent · LIVE

Videos

See all

Related articles

See all