The Web Application Security Engineer is responsible for enterprise Web Application Firewall and edge security operations protecting high-traffic ecommerce applications and APIs. This role provides hands-on ownership of Akamai security platforms and supports additional security technologies.
This position requires strong operational discipline, deep understanding of web application threats, and the ability to balance security enforcement with availability and customer experience in production environments.
Responsibilities Essential Functions: - Monitor and analyze inbound web traffic to identify and respond to suspicious activities, ensuring real-time threat mitigation.
- Collaborate with cross functional teams to integrate WAF solutions into CI/CD pipelines and application architectures and focus on maturing WAF protections.
- Maintain and optimize WAF configurations to balance security, performance, and user experience and enable process optimization and automation.
- Be involved in regular security assessments, vulnerability scans, and penetration testing to identify gaps in WAF protection.
- Maintain a close working relation with the Application Development team to ensure optimal protections are used for all new application releases.
- Ensure adequate testing and validation and has been performed for all protections and mitigations before rollout.
- Collaborate with our Software Development, Quality Assurance, and Project Management teams to solve difficult technical problems, define and deliver highly scalable cloud applications and make fact-based recommendations regarding tactical and strategic technology adoption for our team.
- Promote, foster, and proactively implement agile best practices daily.
- Design, deploy, and manage WAF solutions for on-premise and cloud-based platforms
- Develop and fine-tune WAF policies, rules, and signatures to mitigate known threats and application abuses as well as emerging threats.
- Lead incident response efforts for web application and network attacks, including root cause analysis and remediation.
- Participate in on-call rotations to support 24/7 operations as needed.
Qualifications Qualifications & Required Skills: - 4 year University/College Degree or equivalent.
- 5+ years in the IT field and 3+ years of hands-on experience managing cloud-based WAF platforms, Akamai preferred
- You are comfortable working in a full stack software development environment.
- Experience analyzing security logs, traffic patterns, and attack behavior
- Strong networking fundamentals and familiarity with network protocols (HTTP/HTTPS, TCP/IP, DNS) and web technologies (HTML, JavaScript, APIs).
- Solid understanding of all phases of the web Software Development Life Cycle
- Deep understanding of digital platforms and technologies
- Experience in System Integration touch points – API Gateway, ETL, WebServices (REST,SOAP)
- Experience in working within an Agile/SCRUM software development model
- Strong troubleshooting, analytical, and problem-solving skills
- Ability to adapt to changing roles and changing priorities
- Strong interpersonal skills and relate well with all levels of the organization
- Excellent written and verbal communication skills