WAF Engineer (Azure WAF)

Willis Towers Watson

Philippines

On-site

PHP 1,339,000 - 2,009,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Willis Towers Watson is seeking a WAF Engineer to maximize the performance of WTW services and maintain a secure posture. The role covers BAU support, policy compliance and change activities in a Tier 3 capacity.

Responsibilities include tuning WAF policies, designing multi-cloud rules, mitigating attacks, and leading incident response. Collaboration with developers and security stakeholders is essential to secure internet-facing applications.

Qualifications

  • Experience investigating WAF false positives and false negatives.
  • Experience tuning WAF in Detection and Prevention modes through validation.
  • Developing and maintaining custom WAF rules and rate-limiting policies.
  • Knowledge of OWASP Top 10 and web-based attack vectors.
  • Hands-on attack mitigation, threat analysis and bespoke security controls.

Responsibilities

  • Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining a strong security posture.
  • Design, implement, maintain and optimise WAF policies across multi-cloud environments.
  • Lead the investigation and mitigation of web application attacks including OWASP Top 10 threats and bot attacks.
  • Develop, maintain and enhance custom WAF rules and bot protection controls.
  • Support transition of WAF policies from Detection to Prevention/Block mode through testing and stakeholder engagement.
  • Analyse attack patterns, logs and telemetry to identify emerging threats and mitigations.
  • Work with application teams to secure onboarding and operation of internet-facing apps.
  • Provide SME for web app security, delivery and WAF best practices.
  • Provide technical leadership during major incidents and drive rapid resolutions.
  • Restore service and perform root cause analysis to mitigate recurrence.

Skills

WAF analysis
Policy tuning
Incident response
Root cause analysis
Threat mitigation
Azure WAF
Multi-cloud security

Tools

Azure Front Door WAF
Azure Application Gateway WAF
Threat telemetry tools

Job description

About the role

The WAF Engineer role is intended to maximise the operational performance of WTW services and maintain a strong secure posture. The role is accountable for BAU support of issues, controlling policy & compliance and supporting change activities. This role ensures the technical success of WAF services within the WTW environment in a Tier 3 capacity.


Key responsibilities


  • Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining an appropriate security posture.


  • Design, implement, maintain and optimise WAF policies across multi-cloud environments.


  • Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.


  • Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.


  • Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement.


  • Analyse attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.


  • Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications.


  • Provide subject matter expertise for web application security, secure application delivery and WAF best practices.


  • Provide technical leadership during major incidents and drive to quick resolutions.


  • Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.



About you


  • Demonstrable experience investigating, analysing and resolving WAF false positives and false negatives.


  • Strong experience implementing WAF solutions in Detection mode and transitioning policies to Prevention/Block mode through appropriate tuning and validation.


  • Proven experience developing and maintaining custom WAF rules, rule exclusions, rate limiting controls and attack mitigation policies, rather than solely relying on out-of-the-box managed rules.


  • Extensive knowledge of web application attack vectors, including OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), bot attacks, credential stuffing and API abuse.


  • Hands‑on experience with attack mitigation, threat analysis and creation of bespoke security controls based on observed attack patterns.


  • Strong understanding of bot protection technologies, managed rule sets, policy tuning and wider web application security best practices.


  • Experience with Azure Front Door WAF and Azure Application Gateway WAF in enterprise‑scale environments.


  • Experience working across multi-cloud environments and/or vendor‑agnostic WAF platforms.


  • Minimum 5 years' experience in IT or Telecoms industry. Financial Services experience preferred.


  • Minimum 5 years' Azure WAF/Network management experience.



About us

Willis Towers Watson (NASDAQ: WLTW) is a leading global advisory, broking and solutions company that helps clients around the world turn risk into a path for growth. With roots dating to 1828, Willis Towers Watson has 49,000 employees in more than 140 countries. We design and deliver solutions that manage risk, optimize benefits, cultivate talent, and expand the power of capital to protect and strengthen institutions and individuals.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Waf Engineer
Waf Engineer

W.T.W., Ltd. • Philippines

On-site
PHP 600,000 - 1,200,000
Azure WAF Engineer: Secure Web Apps & Threat Mitigation
Azure WAF Engineer: Secure Web Apps & Threat Mitigation

Willis Towers Watson • Philippines

On-site
PHP 1,339,000 - 2,009,000
Senior WAF Engineer - Multi-Cloud Web Security
Senior WAF Engineer - Multi-Cloud Web Security

W.T.W., Ltd. • Philippines

On-site
PHP 600,000 - 1,200,000
WAF System Lead
WAF System Lead

Boehringer Ingelheim GmbH • Muntinlupa

On-site
PHP 1,674,000 - 2,344,000
WAF System Lead
WAF System Lead

Boehringer Ingelheim GmbH • Philippines

On-site
PHP 1,200,000 - 2,400,000
Azure Cloud Operations Engineer
Azure Cloud Operations Engineer

WTW • Taguig

On-site
PHP 600,000 - 900,000
Manager of Cloud Services - IT Infrastructure and Operations
Manager of Cloud Services - IT Infrastructure and Operations

BW Maritime Pte. Ltd. • Santo Niño 1st

On-site
PHP 1,200,000 - 2,000,000
WAF & Firewall Specialist: Fortinet, Zscaler & Cloudflare
WAF & Firewall Specialist: Fortinet, Zscaler & Cloudflare

V2 Solutions • Hinoba-an

On-site
PHP 500,000 - 900,000
EUC Security Operations Engineer
EUC Security Operations Engineer

Willis Towers Watson • Pateros

On-site
PHP 600,000 - 900,000
WAF System Lead
WAF System Lead

Boehringer Ingelheim • Muntinlupa

On-site
PHP 1,800,000 - 2,400,000