WAF Security Engineer reducing threats to web applications for Fiserv. Collaborating with security teams and developing protections using cyber technologies.
Responsibilities
Work in a dynamic and challenging environment where your focus is on reducing the potential impact of threats to Internet facing web application systems.
Frequently interact with Security Assessment, Security Operations and Cyber Security Incident Response Teams working together to identify ongoing threats to the application.
Develop protections for web applications utilizing state of the art cyber technologies (Web Application Firewalls, Network Firewalls, Intrusion Prevention, Network Traffic Scrubbing) protecting operational applications in real-time.
Maintain and operate Web Application Firewall Configurations.
Perform false positive analysis on WAF events.
Be comfortable driving work efforts outside business-hours, when necessary, as part of on-call rotation schedule.
Act as a front-line and escalation interface to the business, reviewing trouble tickets and executing the required actions.
Be Self-motivated to identify requirements for projects and process improvements.
Requirements
10+ years related IT and cyber protection experience.
Strong understanding of cyber threats as related to Internet facing web applications.
Experience with utilizing NIST CVE data relating to web application vulnerabilities to develop threat response actions utilizing OSI Layer 4 through 7 deep inspections.
Experience with threat analysis of web application network traffic protocols and patterns.
Experience using scripting or automation to reduce team workload on repetitive tasks and communicating with CISO/CIO/CTO level leadership.
CISSP or other professional cyber certification desirable.
Bachelor’s degree in cyber security, Computer Science, Engineering, Mathematics or an equivalent combination of education, work, or military experience.
Expert knowledge of and experience with maintaining cyber technologies that can protect operational web application systems, such as: Signal Sciences WAF / F5 Big IP Application Security Manager. F5 Local Traffic Manager / F5 Silverline WAF & Denial of Service (DDOS) Scrubbing systems. F5 Distributed Cloud WAF / Radware WAF.
Benefits
Annual incentive opportunity (mix of cash bonus and equity awards)
Entry level Associate Security Engineer at Navy Federal securing technical infrastructure and workloads with operational capabilities and threat monitoring practices.
Machine Learning Researcher focusing on innovative AI and intelligent automation for cybersecurity. Driving research in Agentic AI and collaborating with cross - functional teams for production - grade features.
EHS - Management expert overseeing environmental, health, and safety compliance at ZF. Collaborating with teams to foster a safe work culture and manage regulatory compliance.
Senior Technical Lead architecting and securing multi - cloud environments for Celestica. Leading cloud security projects focusing on Google Cloud, Azure, and Google Workspace.
Senior Manager of Information Security at Celestica overseeing cybersecurity policies and practices. Requires extensive experience in threat hunting, control validation, and security architecture reviews.
Cybersecurity Lead - Product Security at Celestica securing network hardware and operating systems. Lead the 'Secure by Design' principles and operationalize standardized SDLC within product engineering teams.
Senior Technical Lead responsible for architecting and implementing global network security solutions. Collaborating with internal and external teams to meet cybersecurity requirements for Celestica.
Cloud Security Engineer focusing on cloud technologies and security practices to innovate and drive projects for IA Talent. Collaborate with a team to implement cutting - edge cloud solutions.
Senior Security Threat Assessment and Management Specialist at Boeing overseeing threat management and security operations. Collaborating with various departments to ensure safety protocols and incident management.
Boeing Cybersecurity is seeking an ISSO to manage information system security across classified domains. Responsibilities include leading risk assessments, A&A processes, and compliance monitoring.