Jobs
My ads
My job alerts
Sign in
Find a job Career Tips Companies
Find

Waf sme

Sheffield
Talent Smart Limited
Posted: 23 July
Offer description

PLEASE ONLY APPLY IF YOU CAN WORK 3 DAYS PER WEEK ONSITE IN SHEFFIELD

This role is central to strengthening and enhancing WAF capabilities across multiple applications. It involves designing, testing, and implementing advanced WAF configurations to improve security posture and detection efficacy.

Key responsibilities include building custom rules, analysing logs to fine-tune the WAF, mitigating false positives, and optimizing configurations. Ideal candidates should have a background in SOC, CSIRT, AppSec, or Ethical Hacking, with hands-on experience in at least three major WAF platforms such as Akamai, F5, AWS, or GCP.

Key Responsibilities

1. Design and implement complex custom WAF rules to address security gaps.

2. Develop and integrate efficacy testing for WAF rules into automation pipelines.

3. Provide expert support for WAF proof-of-concepts, new features, and cost-saving in-house solutions.

4. Offer security expertise on web and API-based attacks, evasions, and defenses.

5. Contribute to DevSecOps automation and CI/CD pipeline integration.

6. Review and act on tuning requests and WAF logs to identify and mitigate false positives.

7. Maintain documentation for tuning activities, policies, and configurations.

8. Develop WAF policies tailored to specific environments.

9. Collaborate with teams to integrate WAF into the wider security infrastructure.

10. Perform regular audits and ensure configurations align with best practices and compliance requirements.

11. Stay informed on the latest web security threats and trends.

Key Accountabilities

12. Protect web applications and data from attacks that could harm operations, reputation, or customer trust.

13. Analyze WAF rulesets and features to ensure they meet defined baselines and maximize threat detection.

14. Identify and resolve bypass techniques and evasions used by attackers.

15. Build and test mitigation rules based on real-world attack scenarios.

16. Automate testing procedures and integrate them into DevOps workflows.

17. Reverse-engineer exploits when necessary to craft defense rules.

18. Document all tuning procedures and maintain up-to-date configuration standards.

19. Provide actionable recommendations based on evolving threat landscapes.

Ideal Candidate Profile

20. Strong hands-on experience in WAF engineering, tuning, and operations.

21. Proven ability to identify and mitigate false positives.

22. Background in SOC/CSIRT, Application Security, or Ethical Hacking.

23. Skilled in log analysis tools (eg, Splunk, Wireshark) and Scripting for traffic review.

24. Experience with multiple WAF platforms (eg, Akamai, F5, AWS, GCP).

25. Strong analytical skills and attention to detail.

26. Excellent communication skills for both technical and non-technical audiences.

27. Able to craft and implement WAF policies specific to diverse applications.

28. Familiar with integrating WAF into broader security frameworks.

29. Proactive and up-to-date on current web security trends and threats.

Apply
Create E-mail Alert
Job alert activated
Saved
Save
See more jobs
Similar jobs
jobs Sheffield
jobs South Yorkshire
jobs England
Home > Jobs > WAF SME

About Jobijoba

  • Career Advice
  • Company Reviews

Search for jobs

  • Jobs by Job Title
  • Jobs by Industry
  • Jobs by Company
  • Jobs by Location
  • Jobs by Keywords

Contact / Partnership

  • Contact
  • Publish your job offers on Jobijoba

Legal notice - Terms of Service - Privacy Policy - Manage my cookies - Accessibility: Not compliant

© 2025 Jobijoba - All Rights Reserved

Apply
Create E-mail Alert
Job alert activated
Saved
Save