Why This Role Stands Out
This hybrid role offers exciting growth potential as you lead the architecture and deployment of cutting-edge Web Application and API Protection (WAAP) solutions for a reputable company. You'll thrive here if you're a mid-senior security engineer eager to develop expertise in WAF, API security, and DDoS mitigation, contributing to a robust defense-in-depth strategy. Apply today to leverage your skills and shape the future of application security.
Quick Overview
Job Description
Key Responsibilities
Translate business and application security requirements into enterprise-grade WAAP and network security architectures.
Develop and support solutions aligned with Client application security and defense-in-depth strategy.
Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments.
Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.
WAAP Responsibilities (Primary Focus)
Architect, implement, and manage WAAP platforms, including:
o Web Application Firewall (WAF)
o API Security (discovery, protection, runtime analysis)
o Bot Management
o DDoS Protection (L3 L7)
Design and deploy WAAP solutions using platforms such as:
o Thales Imperva
o Cloud-native WAFs (Azure, AWS WAF) or equivalent
Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.
Perform false positive tuning, policy optimization, and rule of lifecycle management.
Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.
Integrate WAAP with:
o SIEMSOAR platforms
o Identity providers
o Threat intelligence feeds
Collaborate with application teams to:
o Onboard applications into WAAP platforms
o Perform security assessments and risk reviews
o Ensure minimal performance impact while enforcing strong security controls
Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).
Lead WAAP incident response and root cause analysis for application-layer attacks.
Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).
Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).
Similar jobs
- QS
Information Systems Security Officer (ISSO) with Security Clearance
NewQED Systems, LLC
Fort Belvoir, VA🇺🇸$100k - $130k/yrHybrid21 hours agoTechnology - PI
Network Security Engineer Locals to Nashville, TN W2 role
NewParadigm Infotech
Nashville, TN🇺🇸On-site21 hours agoEncryptionTCP/IPTechnology - SS
Senior Product Security Engineer
NewSunrise Systems, Inc.
Waukesha, WI🇺🇸Hybrid21 hours agoEmbedded SystemsRoboticsIoT+1Technology - SR
Security Engineer Pentesting
Strategic Resources International
San Jose, CA🇺🇸Hybrid6 days agoAWSMachine LearningOWASP+10Technology - LM
Cyber Systems Security Engineering Sr - E3 with Security Clearance
NewLockheed Martin
Marietta, GA🇺🇸Hybrid21 hours agoConfluenceJiraTechnology - LE
SteelCloud Security Engineer with Security Clearance
NewLeidos
Suitland, MD🇺🇸$107.9k - $195.1k/yrHybrid21 hours agoZero TrustTechnology