Zero Trust Engineer

Deloitte France

Tampa (FL)

On-site

USD 110,000 - 160,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Deloitte Global seeks an Application Security Engineer to strengthen our web app protections and Zero Trust posture. You will deploy, configure, and maintain WAFs, manage Zero Trust Proxy connectors, and analyze logs to detect threats across global customer deployments.

Collaborate with SOC, infrastructure, and development teams to implement remediation, craft detection rules, and report security trends. Strong communication skills and experience with cloud security are essential.

Qualifications

  • Bachelor's degree in Information Security, IT, CS, Engineering or equivalent.
  • 4+ years in security; at least 2 years in network security and 2 in application security.
  • Strong web app security knowledge, OWASP Top 10.
  • Experience with WAF, Zero Trust Network Access, APIs, and cloud security.
  • Understanding OAuth/OIDC; authentication flows.
  • Excellent communication and ability to explain security to non-security teams.

Responsibilities

  • Web Application Firewall Management: Deploy, configure, and maintain WAF systems to protect web apps.
  • Zero Trust Proxy: Deploy, configure, and maintain ZT proxies and connectors.
  • Security Incident Response: Monitor, analyze logs, and respond to incidents with SOC support.
  • Detection and Analysis: Develop alerts and reports to identify risks and share findings.
  • CDN Integration: Collaborate to integrate WAF with CDNs like Akamai/Radware.
  • Vulnerability Assessment: Use WAF data to identify vulnerabilities and recommend remediation.
  • Documentation and Reporting: Maintain docs and prepare security reports and trends.
  • Collaboration: Explain security details to non-security teams and guide developers.

Skills

WAF management
Zero Trust
Security incident response
Log analysis
Threat detection

Education

Bachelor's degree in Information Security / IT / CS or equivalent

Tools

WAF
Zero Trust Proxy
APIs security
Cloud security

Job description

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

Work you'll do

The Application Security Engineer candidate will have a strong background in cybersecurity and understanding of web application and zero trust proxy security practices. The primary responsibility of the Engineer will be to ensure the effective deployment, configuration, and maintenance of our systems for Global customers. This role requires expertise in Web Application Firewalls, Zero Trust Proxy, Cloud security as well as experience with alerts and detections and data log analysis. This role will be part of the Application Edge Protection Service within the CyberSecurity pillar.

Role Specific Responsibilities:
  • Web Application Firewall Management: Deploy, configure, and maintain web application firewall systems to protect our web applications against potential threats and vulnerabilities.

  • Zero Trust Proxy: Deploy, configure, and Zero Trust Proxy systems to support identity gates to include defining and maintaining policies and connectors.

  • Security Incident Response: Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and other Cybersecurity teams.

  • Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks utilizing logs. Provides investigation findings to relevant business units to help improve information security posture.

  • CDN Integration: Collaborate with the infrastructure and application teams to integrate the web application firewall with CDNs such Akamai and Radware, ensuring seamless traffic management and content delivery.

  • Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers.

  • Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed.

  • Collaboration: This role requires ability to explain security details to non- security teams such as application and engineering teams. Must be able to collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide guidance to application teams on application security best practices and security awareness, as needed.

The team

Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in what is but rather what can be to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Qualifications
Required:
  • Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience

  • 4+ years with minimum 2 years in network security and 2 years in application security

  • Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques

  • Understanding of authentication and authorization flows (OAuth, SAMAL, OIDC)

  • Strong technical background with Web Application Firewall (WAF), Zero Trust Network Access, APIs, and Cloud security policies

  • Understanding of API security issues and API authentication

  • Good understanding of information security principles and policy enforcement.

  • Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs

  • Strong technical background in web development and familiarity with potential attack vectors/methods

  • Understanding of Authentication, DNS, Networks, Firewalls, SSL Certificates

  • Excellent written and oral communication and presentation skills for technical and business audiences

  • Strong analytical skills with high attention to detail and accuracy

  • Experience with and the ability to thrive in a complex and fast-paced technology and/or information security organization, within a large enterprise environment

Experience in the following areas are strongly preferred:
  • Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis, log analysis, and threat detection is highly desirable.

  • Knowledge of Web Application Firewall technologies (Akamai)

  • Knowledge of Zero Trust framework and technologies

  • Experience integrating zero trust with WAF

  • Familiarity with cloud security services, concepts, and best practices (AWS, Azure, GCP)

  • Infrastructure as code (Terraform)

  • Ethical hacking

  • ServiceNow experience

  • Technical documentation experience

  • CISSP, CISM, CISA, GIAC or other security certifications are desired

  • Bi-lingual a plus (Spanish/Japanese)

  • Automation/Scripting experience

  • Experience with CI/CD pipelines

Limited immigration sponsorship may be available.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Zero Trust Engineer
Zero Trust Engineer

Deloitte France • Cincinnati (OH)

On-site
USD 120,000 - 180,000
Zero Trust & WAF Security Engineer
Zero Trust & WAF Security Engineer

Deloitte France • Tampa (FL)

On-site
USD 110,000 - 160,000
Zero Trust & WAF Engineer — Cloud Security & SOC
Zero Trust & WAF Engineer — Cloud Security & SOC

Deloitte France • Cincinnati (OH)

On-site
USD 120,000 - 180,000
IT & Security Engineer (Part Time)
IT & Security Engineer (Part Time)

Ultimate Staffing • Salt Lake City (UT)

Hybrid
USD 55,000 - 96,000
Zero Trust & Network Security Manager
Zero Trust & Network Security Manager

The Depository Trust & Clearing Corporation (DTCC) • Jersey City (NJ)

On-site
USD 180,000 - 240,000
Transformation O&M Security Engineer II
Transformation O&M Security Engineer II

Deloitte France • Morristown (NJ)

On-site
USD 89,000 - 148,000
Transformation O&M Security Engineer II
Transformation O&M Security Engineer II

Deloitte France • United States

On-site
USD 89,000 - 148,000
Zero Trust Cybersecurity Engineer
Zero Trust Cybersecurity Engineer

ProTalent Finders • Washington

On-site
USD 100,000 - 140,000
Competitive compensation
PTO and paid holidays
Continuing education reimbursements
+2
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2
Cyber Network Security Architecture - Manager
Cyber Network Security Architecture - Manager

Deloitte France • Kansas City (MO)

On-site
USD 135,000 - 265,000