We are seeking an experienced WAF Engineer to join an Inbound Web Application Security team responsible for protecting enterprise web applications at the Layer 7 / application layer.
This is a dedicated Web Application Firewall (WAF) security role and is not a traditional network firewall position. The team focuses on protecting applications from web-based threats and preventing security incidents before they occur. The engineer will work on the front line of application protection, helping ensure inbound web traffic is properly secured, monitored, and controlled.
The ideal candidate will have strong hands‑on experience with WAF technologies, HTTPS troubleshooting, DNS, web application traffic, and Layer 7 security. Experience with Imperva Cloud WAF and/or Cloudflare WAF/ASM is highly desirable.
This team is not part of the incident response team. The focus is on preventative security—proactively protecting applications, identifying potential risks, troubleshooting web traffic issues, and maintaining effective WAF protections to help prevent incidents from occurring.
Daily Responsibilities
- Manage, configure, monitor, and troubleshoot Web Application Firewall (WAF) technologies protecting enterprise web applications.
- Protect inbound web applications and services at the Layer 7 / application layer.
- Analyze HTTP/HTTPS traffic and troubleshoot web application connectivity and security issues.
- Troubleshoot HTTPS/TLS-related issues, including certificate, handshake, and secure‑connection problems.
- Troubleshoot and analyze DNS-related issues affecting web applications and inbound traffic.
- Investigate WAF traffic, security policies, rules, alerts, blocks, and false positives.
- Analyze application traffic patterns to determine whether requests should be allowed, challenged, or blocked.
- Work with application and development teams to understand application behavior and resolve WAF-related issues.
- Configure and tune WAF policies to provide appropriate application protection while minimizing disruption to legitimate users.
- Support onboarding of applications into WAF platforms and ensure appropriate security controls are implemented.
- Troubleshoot application availability issues related to WAF configuration, routing, DNS, HTTPS, or security policies.
- Review Layer 7 traffic and security events to identify potential application‑level threats.
- Collaborate with application, infrastructure, cloud, and security teams to implement preventative security controls.
- Support proactive security improvements designed to prevent incidents before they occur.
- Document WAF configurations, troubleshooting procedures, application onboarding requirements, and operational processes.
- Participate in technology enhancements, WAF policy improvements, and application security initiatives.
- Provide technical guidance to application teams regarding inbound web traffic and WAF security requirements.
Required Skills
Core WAF Experience
- Strong hands‑on experience as a WAF Engineer or Web Application Security Engineer.
- Strong understanding of Web Application Firewall technologies.
- Experience protecting web applications at Layer 7.
- Strong understanding of inbound web application traffic and HTTP/HTTPS protocols.
- Experience troubleshooting WAF‑related application connectivity and security issues.
HTTPS / Web Traffic
- Strong hands‑on experience troubleshooting HTTPS.
- Understanding of TLS/SSL, certificates, handshakes, and secure web traffic.
- Ability to troubleshoot web application traffic flowing through a WAF.
- Understanding of HTTP request/response behavior and common web application traffic patterns.
DNS
- Strong understanding of DNS.
- Ability to troubleshoot DNS‑related issues affecting web applications and inbound traffic.
- Understanding of DNS resolution and how DNS interacts with web application traffic and WAF architecture.
Application Security
- Understanding of application‑layer security rather than traditional network perimeter security.
- Ability to distinguish application‑level threats and traffic from traditional network security events.
- Experience troubleshooting legitimate traffic that is incorrectly blocked by WAF policies.
- Ability to tune WAF policies and rules based on application behavior.
Desired Skills
- Hands‑on experience with Imperva Cloud WAF.
- Experience with Cloudflare WAF / Cloudflare application security capabilities.
- Experience with Imperva ASM or similar application security/WAF technologies.
- Experience onboarding applications into enterprise WAF platforms.
- Experience with WAF policy creation, tuning, rule management, and false‑positive reduction.
- Knowledge of common web application attacks and OWASP concepts.
- Experience with cloud‑based application security.
- Experience with CDN, reverse proxy, load balancing, or edge security technologies.
- Experience troubleshooting SSL/TLS certificates and configurations.
- Experience working with application development teams.
- Experience with scripting or automation for WAF/security operations.
- Experience with security monitoring and logging platforms.