WAF Engineer securing web applications and APIs for healthcare technology. Collaborating with DevOps/SRE teams to enhance security while minimizing performance impact.
Responsibilities
Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod)
Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.)
Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor → challenge → block)
Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing
Integrate WAF logs with SIEM/log platforms (Splunk, Sentinel, ELK, QRadar) and build dashboards/alerts for threat monitoring
Support incident response for active attacks (L7 DDoS, exploit attempts), including rapid mitigation and post-incident improvements
Automate deployments using IaC (Terraform/CloudFormation/ARM/Bicep) and integrate with CI/CD pipelines
Conduct periodic security reviews, reporting, and metrics tracking (blocked events, top attacks, FP rate, MTTR)
Collaborate with app teams on secure configuration (headers, TLS, authentication flows) and compatibility testing
Requirements
5+ years experience in WAF engineering / application security / edge security
Hands-on experience with at least one WAF platform: AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF, Imperva, Akamai, ModSecurity (any one or more)
Strong understanding of HTTP/HTTPS, web app architecture, REST APIs, and common attack patterns
Proven experience tuning WAF rules and balancing security vs. false positives
Experience with logging/monitoring and SIEM integrations
Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML)
Familiarity with CI/CD and Infrastructure-as-Code principles
Good troubleshooting and stakeholder communication skills.
Project Engineer leading innovative testing and certification projects at BRE, focusing on building safety and sustainability. Collaborating with clients and managing testing projects for impactful solutions.
Backup Engineer responsible for managing and ensuring data protection and recovery at Qualysoft, an IT consulting firm. Focus on innovative IT solutions and compliance with business requirements.
Modern Workplace Engineer for Microsoft 365 improving infrastructure and user experience. Collaborating on projects and technical support for migration and transformation in a hybrid work environment.
V&V Intern supporting testing and validation of electronic products at Fluke Engineering. Collaborating with engineers and participating in lab activities for product reliability.
Electrical Project Engineer supporting Project Managers and collaborating on electrical infrastructure projects. Preparing and reviewing designs, performing analyses, and ensuring project delivery with multi - disciplinary teams.
Mechatronics Engineer responsible for product design and automatized systems development at Videndum. Collaborating with teams to ensure design intent and product testing.
Hardware Engineer responsible for designing hardware solutions and supporting manufacturing efficiency at Emerson. Collaborating across engineering, project management, and supply chain for successful project execution.
Repair Engineer at Ebara Elliott Energy performing engineering assignments and providing technical support in Indonesia. Responsibilities include design improvements and planning for repair jobs.
Electrical Project Engineer at Samudera Indonesia overseeing product/service development and project budgeting. Collaborating on engineering projects in the shipping industry with a global reach.