WAF (Web Application Firewall) Engineer

Motion Recruitment

Irving (TX)

On-site

USD 130,000 - 170,000

Full time

13 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance

Job summary

Motion Recruitment is seeking an experienced WAF Engineer to join an outbound inbound Web Application Security team focused on protecting enterprise web applications at the Layer 7 / application layer.

The role emphasizes preventative security and hands-on work with Imperva Cloud WAF, Cloudflare WAF/ASM, and TLS/DNS troubleshooting, collaborating with development teams to minimize disruption while strengthening protections.

Qualifications

  • Hands-on experience as a WAF Engineer or Web Application Security Engineer.
  • Strong understanding of Web Application Firewall technologies.
  • Experience protecting web applications at Layer 7.
  • Strong understanding of inbound web traffic and HTTP/HTTPS protocols.
  • Experience troubleshooting WAF‑related connectivity and security issues.

Responsibilities

  • Manage, configure, monitor, and troubleshoot WAF technologies protecting enterprise web applications.
  • Protect inbound web applications and services at the Layer 7 / application layer.
  • Analyze HTTP/HTTPS traffic and troubleshoot web application connectivity and security issues.
  • Troubleshoot HTTPS/TLS-related issues, including certificate, handshake, and secure‑connection problems.
  • Troubleshoot and analyze DNS-related issues affecting web applications and inbound traffic.
  • Investigate WAF traffic, security policies, rules, alerts, blocks, and false positives.
  • Analyze application traffic patterns to determine whether requests should be allowed, challenged, or blocked.
  • Work with application and development teams to understand application behavior and resolve WAF-related issues.
  • Configure and tune WAF policies to provide appropriate application protection while minimizing disruption to legitimate users.
  • Support onboarding of applications into WAF platforms and ensure appropriate security controls are implemented.
  • Troubleshoot application availability issues related to WAF configuration, routing, DNS, HTTPS, or security policies.
  • Review Layer 7 traffic and security events to identify potential application‑level threats.
  • Collaborate with application, infrastructure, cloud, and security teams to implement preventative security controls.
  • Support proactive security improvements designed to prevent incidents before they occur.
  • Document WAF configurations, troubleshooting procedures, application onboarding requirements, and operational processes.
  • Participate in technology enhancements, WAF policy improvements, and application security initiatives.
  • Provide technical guidance to application teams regarding inbound web traffic and WAF security requirements.

Skills

WAF Engineer
Web App Security
Layer 7 Security
HTTPS Troubleshooting
DNS Troubleshooting
HTTP/HTTPS Protocols
WAF Policy Tuning

Tools

Imperva Cloud WAF
Cloudflare WAF
Imperva ASM

Job description

We are seeking an experienced WAF Engineer to join an Inbound Web Application Security team responsible for protecting enterprise web applications at the Layer 7 / application layer.

This is a dedicated Web Application Firewall (WAF) security role and is not a traditional network firewall position. The team focuses on protecting applications from web-based threats and preventing security incidents before they occur. The engineer will work on the front line of application protection, helping ensure inbound web traffic is properly secured, monitored, and controlled.

The ideal candidate will have strong hands‑on experience with WAF technologies, HTTPS troubleshooting, DNS, web application traffic, and Layer 7 security. Experience with Imperva Cloud WAF and/or Cloudflare WAF/ASM is highly desirable.

This team is not part of the incident response team. The focus is on preventative security—proactively protecting applications, identifying potential risks, troubleshooting web traffic issues, and maintaining effective WAF protections to help prevent incidents from occurring.

Daily Responsibilities
  • Manage, configure, monitor, and troubleshoot Web Application Firewall (WAF) technologies protecting enterprise web applications.
  • Protect inbound web applications and services at the Layer 7 / application layer.
  • Analyze HTTP/HTTPS traffic and troubleshoot web application connectivity and security issues.
  • Troubleshoot HTTPS/TLS-related issues, including certificate, handshake, and secure‑connection problems.
  • Troubleshoot and analyze DNS-related issues affecting web applications and inbound traffic.
  • Investigate WAF traffic, security policies, rules, alerts, blocks, and false positives.
  • Analyze application traffic patterns to determine whether requests should be allowed, challenged, or blocked.
  • Work with application and development teams to understand application behavior and resolve WAF-related issues.
  • Configure and tune WAF policies to provide appropriate application protection while minimizing disruption to legitimate users.
  • Support onboarding of applications into WAF platforms and ensure appropriate security controls are implemented.
  • Troubleshoot application availability issues related to WAF configuration, routing, DNS, HTTPS, or security policies.
  • Review Layer 7 traffic and security events to identify potential application‑level threats.
  • Collaborate with application, infrastructure, cloud, and security teams to implement preventative security controls.
  • Support proactive security improvements designed to prevent incidents before they occur.
  • Document WAF configurations, troubleshooting procedures, application onboarding requirements, and operational processes.
  • Participate in technology enhancements, WAF policy improvements, and application security initiatives.
  • Provide technical guidance to application teams regarding inbound web traffic and WAF security requirements.
Required Skills
Core WAF Experience
  • Strong hands‑on experience as a WAF Engineer or Web Application Security Engineer.
  • Strong understanding of Web Application Firewall technologies.
  • Experience protecting web applications at Layer 7.
  • Strong understanding of inbound web application traffic and HTTP/HTTPS protocols.
  • Experience troubleshooting WAF‑related application connectivity and security issues.
HTTPS / Web Traffic
  • Strong hands‑on experience troubleshooting HTTPS.
  • Understanding of TLS/SSL, certificates, handshakes, and secure web traffic.
  • Ability to troubleshoot web application traffic flowing through a WAF.
  • Understanding of HTTP request/response behavior and common web application traffic patterns.
DNS
  • Strong understanding of DNS.
  • Ability to troubleshoot DNS‑related issues affecting web applications and inbound traffic.
  • Understanding of DNS resolution and how DNS interacts with web application traffic and WAF architecture.
Application Security
  • Understanding of application‑layer security rather than traditional network perimeter security.
  • Ability to distinguish application‑level threats and traffic from traditional network security events.
  • Experience troubleshooting legitimate traffic that is incorrectly blocked by WAF policies.
  • Ability to tune WAF policies and rules based on application behavior.
Desired Skills
  • Hands‑on experience with Imperva Cloud WAF.
  • Experience with Cloudflare WAF / Cloudflare application security capabilities.
  • Experience with Imperva ASM or similar application security/WAF technologies.
  • Experience onboarding applications into enterprise WAF platforms.
  • Experience with WAF policy creation, tuning, rule management, and false‑positive reduction.
  • Knowledge of common web application attacks and OWASP concepts.
  • Experience with cloud‑based application security.
  • Experience with CDN, reverse proxy, load balancing, or edge security technologies.
  • Experience troubleshooting SSL/TLS certificates and configurations.
  • Experience working with application development teams.
  • Experience with scripting or automation for WAF/security operations.
  • Experience with security monitoring and logging platforms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior WAF Engineer — Proactive Web App Security
Senior WAF Engineer — Proactive Web App Security

Motion Recruitment • Irving (TX)

On-site
USD 130,000 - 170,000
Health insurance
Cyber Security Engineer (WAF SME)
Cyber Security Engineer (WAF SME)

Ampcus, Inc • Atlanta (GA)

On-site
USD 110,000 - 160,000
Cyber Security Engineer (WAF SME)
Cyber Security Engineer (WAF SME)

Ampcus Inc • Atlanta (GA)

On-site
USD 100,000 - 135,000
WAF Operations Engineer | Cloudflare/Imperva + IaC
WAF Operations Engineer | Cloudflare/Imperva + IaC

EY • Salt Lake City (UT)

Hybrid
USD 104,000 - 193,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
+2
WAF Operations Engineer | Cloudflare/Imperva Expert
WAF Operations Engineer | Cloudflare/Imperva Expert

EY • Hartford (CT)

Hybrid
USD 82,000 - 136,000
Medical and dental coverage
401(k) and retirement plans
Paid time off
+2
WAF Operations Engineer - Cloudflare/Imperva Specialist
WAF Operations Engineer - Cloudflare/Imperva Specialist

EY • Richmond (VA)

Hybrid
USD 82,000 - 136,000
Medical and dental coverage
401(k) plan
Paid time off
WAF Operations Engineer — Hybrid, Cloudflare/Imperva & IaC
WAF Operations Engineer — Hybrid, Cloudflare/Imperva & IaC

EY • City of Albany (NY)

Hybrid
USD 82,000 - 155,000
Medical & dental coverage
401(k) plan
Paid time off
WAF Operations Engineer: Cloudflare/Imperva Expert
WAF Operations Engineer: Cloudflare/Imperva Expert

EY • Los Angeles (CA)

Hybrid
USD 82,000 - 155,000
Hybrid work model
Medical and dental coverage
Pension and 401(k)
WAF Operations Engineer: Cloudflare/Imperva & IaC
WAF Operations Engineer: Cloudflare/Imperva & IaC

EY • Alpharetta (GA)

Hybrid
USD 83,000 - 136,000
Compensation package
Hybrid work model
Generous vacation policy
WAF Operations Engineer - Cloud Security & IaC
WAF Operations Engineer - Cloud Security & IaC

EY • Portland (OR)

Hybrid
USD 82,000 - 136,000
Hybrid work model
Total Rewards package (medical, dental
Flexible vacation policy