WAF & Application Security SME
WAF & Application Security SME

WAF & Application Security SME

Edinburgh Full-Time 48000 - 84000 ยฃ / year (est.) Home office (partial)
Go Premium
J

At a Glance

  • Tasks: Join our team to enhance Web Application Firewalls and improve security measures.
  • Company: Be part of a leading retail banking client focused on innovative security solutions.
  • Benefits: Enjoy flexible working options and the chance to work with cutting-edge technology.
  • Why this job: Make a real impact by defending against web attacks and enhancing security posture.
  • Qualifications: Experience in WAF management, SOC, AppSec, or Ethical Hacking is essential.
  • Other info: Work in Edinburgh or Sheffield at least 2 days a week; contract inside IR35.

The predicted salary is between 48000 - 84000 ยฃ per year.

We are currently looking for a WAF & Application Security SME to join an existing team at one of our retail banking clients.The role will be working on the enhancement of a Web Application Firewall across multiple solutions and applications and will be pivotal in crafting, testing, and implementing advanced WAF uplifts.This role involves a strong focus on WAF Efficacy and security posture uplift by crafting efficacy testing custom rules and configurations; additionally, the role will cover WAF tuning via detailed log analysis, false positive detection and mitigation, and making tuning and configuration recommendations. The ideal candidate will have experience in SOC or CSIRT and AppSec or Ethical Hacking for in-depth log analysis and have previously worked with at least three major WAF vendors such as Akamai, F5, AWS, GCP, etc.Key ResponsibilitiesIdentification and crafting of complex custom WAF rules & features to mitigate MVP and security posture gapsCrafting efficacy testing for baseline & custom rules and features and integrating testing in the automation pipelinesProviding SME support for other security testing such as WAF PoCs, new features and solutions โ€“ with a potential cost saving if we use in-house resource instead of 3rd party vendorsProviding WAF focused SME support and advice on Web & API based attack methodologies, evasions and mitigation techniquesProviding DevSecOps SME & pipeline build support for the automation worksMonitor and review all tuning requests.Conduct detailed log analysis to identify false positives and optimize WAF rules for improved accuracy and performance.Create and maintain comprehensive documentation for WAF tuning, tuning procedures, policies, and configurations.Develop, test, and recommend WAF policies and rules tailored to specific applications and environments.Proactively assist with identifying false positivesCollaborate with cross-functional teams to ensure seamless integration of WAF solutions into existing security infrastructure.Provide recommendations for WAF configuration based on best practices and security requirements.Perform regular assessments and audits of WAF configurations to ensure optimal security posture and compliance with industry standards.Stay updated with the latest web security threats, vulnerabilities, and trends to continually enhance WAF effectiveness.Key AccountabilitiesHelp defend the organization and its customers from web based attacks that could cause substantial harm to the company\’s operations, reputation, and customersConduct detailed analyses and technical evaluations of various Web Application Firewall (WAF) solution rulesets and functionalities to confirm adherence to agreed baselines and to maximize detection of web, API, and other traffic-based security threatsCreate custom rules and features where needed to augment WAF solutions to be able to meet the agree baselineIdentify and mitigate technical circumventions and evasions of WAF solutions.Develop and implement testing packages to assess the efficacy of various initiatives, including WAF Proofs of Concept, managed and custom rules, new features, and solutions.Facilitate the automation of efficacy testing procedures and their integration into Continuous Integration/Continuous Deployment (CI/CD) pipelines.Contribute to DevSecOps and pipeline construction projects.When needed, reverse-engineer attackersโ€™ exploits and payloads to devise mitigation rulesEnsuring timely and accurate review and action on all WAF tuning requests.Conducting thorough log analyses to effectively identify and mitigate false positives, ensuring optimized WAF rules.Maintaining comprehensive and up-to-date documentation for all WAF tuning procedures, policies, and configurations.Developing and recommending tailored WAF policies and rules for various applications and environments.Proactively identifying and addressing false positives to enhance overall WAF accuracy.Collaborating effectively with cross-functional teams to integrate WAF solutions seamlessly into existing security infrastructure.Providing expert recommendations for WAF configurations based on best practices and current security requirements.Performing regular assessments and audits of WAF configurations to maintain optimal security posture and compliance with industry standards.Staying informed about the latest web security threats, vulnerabilities, and trends to ensure continuous enhancement of WAF effectiveness.Experience RequiredExtensive experience in WAF management, tuning, and engineering, with a strong understanding of web application security principles.Proven track record of proactively identifying and mitigating false positives to optimize WAF performance.Background in SOC or CSIRT and AppSec or Ethical Hacking, demonstrating hands-on experience for the key responsibilitiesProficiency in log analysis tools and techniques, with the ability to identify patterns and anomalies in web trafficExperience with tools such as Splunk, Wireshark, or custom scripts to process and analyse logs.Experience with at least three major WAF solutions (e.g., Akamai, F5, AWS, GCP) and an understanding of their unique configurations and capabilities.Strong analytical and problem-solving skills, with a keen attention to detail.Excellent communication skills, capable of articulating complex security concepts to technical and non-technical stakeholders.Ability to develop, test, and recommend WAF policies and rules tailored to specific applications and environments.Experience collaborating with cross-functional teams to integrate WAF solutions into existing security infrastructure.Competence in maintaining comprehensive documentation for WAF tuning procedures, policies, and configurations.Extensive experience in configuring WAF solutions to align with best practices and security requirements.A proactive, detail-oriented individual who thrives in a dynamic, fast-paced environment and stays updated with the latest web security threats and trends.Applicants must be able to work in the client office at least 2 days per week, either Edinburgh or Sheffield.Contract will be inside IR35.#LI-DNI #J-18808-Ljbffr

WAF & Application Security SME employer: JobLeads GmbH

Join a leading retail banking client as a WAF & Application Security SME, where you will be part of a dynamic team dedicated to enhancing web application security. Our company fosters a collaborative work culture that prioritises employee growth through continuous learning and development opportunities, while also offering competitive benefits and a flexible work environment in vibrant locations like Edinburgh and Sheffield. With a strong focus on innovation and security, we empower our employees to make a meaningful impact in safeguarding our clients' operations and reputation.
J

Contact Detail:

JobLeads GmbH Recruiting Team

StudySmarter Expert Advice ๐Ÿคซ

We think this is how you could land WAF & Application Security SME

โœจTip Number 1

Familiarise yourself with the specific WAF solutions mentioned in the job description, such as Akamai, F5, AWS, and GCP. Understanding their unique configurations and capabilities will give you an edge during discussions and interviews.

โœจTip Number 2

Stay updated on the latest web security threats and vulnerabilities. Being knowledgeable about current trends will not only help you in your role but also demonstrate your commitment to continuous learning during the interview process.

โœจTip Number 3

Prepare to discuss your experience with log analysis tools like Splunk or Wireshark. Be ready to share specific examples of how you've identified patterns and anomalies in web traffic, as this is crucial for the role.

โœจTip Number 4

Highlight your collaborative skills by preparing examples of how you've worked with cross-functional teams in the past. This will show that you can effectively integrate WAF solutions into existing security infrastructures, which is a key responsibility of the role.

We think you need these skills to ace WAF & Application Security SME

WAF Management
Web Application Security Principles
Log Analysis Techniques
False Positive Mitigation
Custom Rule Development
Security Posture Assessment
Experience with Major WAF Vendors (Akamai, F5, AWS, GCP)
Technical Evaluation of WAF Rulesets
CI/CD Pipeline Integration
DevSecOps Practices
Documentation Skills
Analytical Skills
Problem-Solving Skills
Communication Skills
Collaboration with Cross-Functional Teams

Some tips for your application ๐Ÿซก

Tailor Your CV: Make sure your CV highlights relevant experience in WAF management, tuning, and application security. Emphasise your familiarity with major WAF vendors like Akamai, F5, AWS, or GCP, and any specific projects that showcase your skills in log analysis and false positive mitigation.

Craft a Strong Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Discuss your background in SOC or CSIRT, and how your experience aligns with the responsibilities outlined in the job description. Be specific about your achievements in enhancing WAF efficacy and security posture.

Highlight Relevant Skills: Clearly list your technical skills related to WAF tuning, log analysis, and security best practices. Mention any tools you are proficient in, such as Splunk or Wireshark, and provide examples of how you've used these tools to improve security measures in previous roles.

Showcase Collaboration Experience: Since the role involves working with cross-functional teams, include examples of past collaborations. Describe how youโ€™ve successfully integrated security solutions into existing infrastructures and how you communicated complex security concepts to both technical and non-technical stakeholders.

How to prepare for a job interview at JobLeads GmbH

โœจShowcase Your Technical Expertise

Be prepared to discuss your experience with WAF management and tuning in detail. Highlight specific instances where you've crafted custom rules or mitigated false positives, as this will demonstrate your hands-on knowledge and problem-solving skills.

โœจFamiliarise Yourself with Major WAF Vendors

Since the role requires experience with at least three major WAF vendors, make sure you can articulate the unique features and configurations of tools like Akamai, F5, AWS, and GCP. This will show that you have a solid understanding of the landscape.

โœจPrepare for Log Analysis Questions

Expect questions related to log analysis techniques and tools. Be ready to explain how you've used tools like Splunk or Wireshark to identify patterns and anomalies in web traffic, as this is crucial for the role.

โœจDemonstrate Collaboration Skills

The role involves working with cross-functional teams, so be prepared to discuss your experience collaborating with others. Share examples of how you've integrated WAF solutions into existing security infrastructures and how you communicate complex security concepts to both technical and non-technical stakeholders.

WAF & Application Security SME
JobLeads GmbH
Go Premium

Land your dream job quicker with Premium

Youโ€™re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

J
  • WAF & Application Security SME

    Edinburgh
    Full-Time
    48000 - 84000 ยฃ / year (est.)

    Application deadline: 2027-08-15

  • J

    JobLeads GmbH

Similar positions in other companies
UKโ€™s top job board for Gen Z
discover-jobs-cta
Discover now
>