WAF & Application Security SME
WAF & Application Security SME

WAF & Application Security SME

Birmingham Freelance 40000 - 60000 £ / year (est.) Home office (partial)
Go Premium
U

At a Glance

  • Tasks: Enhance Web Application Firewall (WAF) security and implement advanced configurations.
  • Company: Join a leading banking and IT recruitment firm connecting top talent with major financial institutions.
  • Benefits: Enjoy remote work flexibility and competitive daily rates up to £496.80.
  • Why this job: Be a key player in defending against web-based attacks while working in a dynamic environment.
  • Qualifications: Experience in SOC, AppSec, or Ethical Hacking with knowledge of major WAF vendors required.
  • Other info: Contract role until September 2026 with occasional travel to Birmingham.

The predicted salary is between 40000 - 60000 £ per year.

3 days ago Be among the first 25 applicants

Get AI-powered advice on this job and more exclusive features.

Direct message the job poster from Undisclosed

Banking & IT Recruiter | Connecting Top Talent with Leading Financial Institutions and IT Sectors | Specializing in Strategic Hires and Talent…

Role Title: WAF & Application Security SME

Duration: contract to run until 15/09/2026

Location: Remote with occasional AdHoc travel to Birmingham

Rate: up to £496.80 p/d Umbrellainside IR35

This role will play a critical role in enhancing our Web Application Firewall (WAF) across multiple solutions and applications and will be pivotal in crafting, testing, and implementing advanced WAF uplifts.

This role involves a strong focus on WAF Efficacy and security posture uplift by crafting efficacy testing custom rules and configurations; additionally, the role will cover WAF tuning via detailed log analysis, false positive detection and mitigation, and making tuning and configuration recommendations. The ideal candidate will have experience in SOC or CSIRT and AppSec or Ethical Hacking for in-depth log analysis and have previously worked with at least three major WAF vendors such as Akamai, F5, AWS, GCP, etc.

The successful candidate will help defend the organization and its customers from web-based attacks that could cause substantial harm to the company\’s operations, reputation, and customers and monitor and review tuning request, proactively assist with identifying false positives and provide expert recommendations and stay updated with the latest web security threats and trends to ensure optimal protection and performance.

Candidate Profile Summary:

The primary role is to tune WAF accurately and safely – avoiding outage and bypass.

We are not looking for Engineers that only list WAF as a past experience

We are looking for people with:

  • SOC / Threat / Forensics or CSIRT backgrounds – very experienced with analysing security logs to quickly ascertain TP/FP conviction and the techniques to except
  • Ideally some AppSec / DevSecOps or Ethical Hacking experience – with a good understanding of Web Application attacks and security; they must be familiar with the OWASP Top 10
  • If they have Security Engineering skills too, this a bonus

Key Skills/ requirements

  • Identification and crafting of complex custom WAF rules & features to mitigate MVP and security posture gaps.
  • Crafting efficacy testing for baseline & custom rules and features and integrating testing in the automation pipelines.
  • Providing SME support for other security testing such as WAF PoCs, new features and solutions – with a potential cost saving if we use in-house resource instead of 3rd party vendors.
  • Providing WAF focused SME support and advice on Web & API based attack methodologies, evasions and mitigation techniques.
  • Providing DevSecOps SME & pipeline build support for the automation works
  • Monitor and review all tuning requests.
  • Conduct detailed log analysis to identify false positives and optimize WAF rules for improved accuracy and performance.
  • Create and maintain comprehensive documentation for WAF tuning, tuning procedures, policies, and configurations.
  • Develop, test, and recommend WAF policies and rules tailored to specific applications and environments.
  • Proactively assist with identifying false positives.
  • Collaborate with cross-functional teams to ensure seamless integration of WAF solutions into existing security infrastructure.
  • Provide recommendations for WAF configuration based on best practices and security requirements.
  • Perform regular assessments and audits of WAF configurations to ensure optimal security posture and compliance with industry standards.
  • Stay updated with the latest web security threats, vulnerabilities, and trends to continually enhance WAF effectiveness.

Key Accountabilities:

  • Help defend the organization and its customers from web-based attacks that could cause substantial harm to the company\’s operations, reputation, and customers.
  • Conduct detailed analyses and technical evaluations of various Web Application Firewall (WAF) solution rulesets and functionalities to confirm adherence to agreed baselines and to maximize detection of web, API, and other traffic-based security threats.
  • Create custom rules and features where needed to augment WAF solutions to be able to meet the agree baseline.
  • Identify and mitigate technical circumventions and evasions of WAF solutions.
  • Develop and implement testing packages to assess the efficacy of various initiatives, including WAF Proofs of Concept, managed and custom rules, new features, and solutions.
  • Facilitate the automation of efficacy testing procedures and their integration into Continuous Integration/Continuous Deployment (CI/CD) pipelines.
  • Contribute to DevSecOps and pipeline construction projects.
  • When needed, reverse-engineer attackers’ exploits and payloads to devise mitigation rules.
  • Ensuring timely and accurate review and action on all WAF tuning requests.
  • Conducting thorough log analyses to effectively identify and mitigate false positives, ensuring optimized WAF rules.
  • Maintaining comprehensive and up-to-date documentation for all WAF tuning procedures, policies, and configurations.
  • Developing and recommending tailored WAF policies and rules for various applications and environments.
  • Proactively identifying and addressing false positives to enhance overall WAF accuracy.
  • Collaborating effectively with cross-functional teams to integrate WAF solutions seamlessly into existing security infrastructure.
  • Providing expert recommendations for WAF configurations based on best practices and current security requirements.
  • Performing regular assessments and audits of WAF configurations to maintain optimal security posture and compliance with industry standards.
  • Staying informed about the latest web security threats, vulnerabilities, and trends to ensure continuous enhancement of WAF effectiveness.

Ideal Candidate Profile:

  • Extensive experience in WAF management, tuning, and engineering, with a strong understanding of web application security principles.
  • Proven track record of proactively identifying and mitigating false positives to optimize WAF performance.
  • Background in SOC or CSIRT and AppSec or Ethical Hacking, demonstrating hands-on experience for the key responsibilities.
  • Proficiency in log analysis tools and techniques, with the ability to identify patterns and anomalies in web traffic.
  • Experience with tools such as Splunk, Wireshark, or custom scripts to process and analyze logs.
  • Experience with at least three major WAF solutions (e.g., Akamai, F5, AWS, GCP) and an understanding of their unique configurations and capabilities.
  • Strong analytical and problem-solving skills, with a keen attention to detail.
  • Excellent communication skills, capable of articulating complex security concepts to technical and non-technical stakeholders.
  • Ability to develop, test, and recommend WAF policies and rules tailored to specific applications and environments.
  • Experience collaborating with cross-functional teams to integrate WAF solutions into existing security infrastructure.
  • Competence in maintaining comprehensive documentation for WAF tuning procedures, policies, and configurations.
  • Extensive experience in configuring WAF solutions to align with best practices and security requirements.
  • A proactive, detail-oriented individual who thrives in a dynamic, fast-paced environment and stays updated with the latest web security threats and trends.

All profiles will be reviewed against the required skills and experience. Due to the high number of applications we will only be able to respond to successful applicants in the first instance. We thank you for your interest and the time taken to apply!

Seniority level

  • Seniority level

    Mid-Senior level

Employment type

  • Employment type

    Contract

Job function

  • Job function

    Information Technology

Referrals increase your chances of interviewing at Undisclosed by 2x

Sign in to set job alerts for “Application Specialist” roles.

Belfast, Northern Ireland, United Kingdom 4 days ago

Leeds, England, United Kingdom 1 week ago

Cyber Threat Detection Engineer (Incident Response)

Leeds, England, United Kingdom 2 weeks ago

Cardiff, Wales, United Kingdom 1 month ago

Carlisle, England, United Kingdom 6 days ago

Lancashire, England, United Kingdom 6 days ago

Slough, England, United Kingdom 1 month ago

London, England, United Kingdom 3 months ago

Plymouth, England, United Kingdom 1 month ago

Cambridge, England, United Kingdom 3 weeks ago

Isleworth, England, United Kingdom 1 month ago

Luton, England, United Kingdom 1 month ago

Luton, England, United Kingdom 1 month ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

#J-18808-Ljbffr

WAF & Application Security SME employer: Undisclosed

As a leading player in the banking and IT sectors, our company offers a dynamic work environment that fosters innovation and collaboration. Employees benefit from competitive rates, flexible remote working arrangements, and opportunities for professional growth through exposure to cutting-edge security technologies and practices. Join us to make a meaningful impact in safeguarding our clients' operations while advancing your career in a supportive and forward-thinking culture.
U

Contact Detail:

Undisclosed Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land WAF & Application Security SME

Tip Number 1

Make sure to highlight your experience with at least three major WAF vendors in your conversations. This will demonstrate your hands-on knowledge and familiarity with different configurations, which is crucial for the role.

Tip Number 2

Prepare to discuss specific examples of how you've conducted detailed log analyses in the past. Being able to articulate your process for identifying false positives and tuning WAF rules will set you apart from other candidates.

Tip Number 3

Stay updated on the latest web security threats and trends. Being knowledgeable about current vulnerabilities will not only help you in interviews but also show your commitment to continuous learning in the field.

Tip Number 4

Network with professionals in the SOC or CSIRT space. Engaging with others in your field can provide valuable insights and potentially lead to referrals, increasing your chances of landing the job.

We think you need these skills to ace WAF & Application Security SME

WAF Management
Log Analysis
Custom Rule Development
Web Application Security
False Positive Mitigation
Security Posture Assessment
OWASP Top 10 Familiarity
DevSecOps Practices
Automation Pipeline Integration
Technical Documentation
Cross-Functional Collaboration
Analytical Skills
Problem-Solving Skills
Communication Skills
Experience with Major WAF Vendors (Akamai, F5, AWS, GCP)

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in WAF management, SOC, CSIRT, and AppSec. Use specific examples that demonstrate your skills in log analysis and crafting custom WAF rules.

Craft a Strong Cover Letter: In your cover letter, emphasise your hands-on experience with at least three major WAF vendors. Discuss your understanding of web application security principles and how you can contribute to enhancing the company's security posture.

Highlight Relevant Skills: Clearly list your technical skills related to WAF tuning, log analysis, and security methodologies. Mention any tools you are proficient in, such as Splunk or Wireshark, and how they relate to the role.

Showcase Continuous Learning: Mention any recent training or certifications related to web security threats and trends. This shows your commitment to staying updated in a fast-paced environment, which is crucial for this role.

How to prepare for a job interview at Undisclosed

Showcase Your WAF Expertise

Make sure to highlight your experience with various WAF vendors like Akamai, F5, AWS, or GCP. Be prepared to discuss specific instances where you've crafted custom rules or tuned WAF settings to enhance security posture.

Demonstrate Log Analysis Skills

Since the role requires detailed log analysis, come ready to explain your approach to identifying false positives and how you've used tools like Splunk or Wireshark in past roles. Share examples of how your analysis led to improved WAF performance.

Understand Web Application Security

Familiarise yourself with the OWASP Top 10 and be ready to discuss how these vulnerabilities relate to WAF configurations. Showing a solid understanding of web application attacks will demonstrate your capability to enhance the organisation's security measures.

Prepare for Technical Questions

Expect technical questions related to WAF tuning and security methodologies. Brush up on your knowledge of attack vectors and mitigation techniques, as well as your experience in DevSecOps practices, to impress the interviewers with your depth of knowledge.

WAF & Application Security SME
Undisclosed
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

U
  • WAF & Application Security SME

    Birmingham
    Freelance
    40000 - 60000 £ / year (est.)

    Application deadline: 2027-08-28

  • U

    Undisclosed

Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>