1

Web Application Firewall Waf Engineer Jobs in Michigan

Application Security Analyst

Auburn Hills, MI · On-site

$55.50 - $74.25/hr

Lead Web Application Firewall (WAF) deployment for new and existing apps * Implement application ... Modern programming languages (Java, C#, Python) * Experience performing and interpreting results ...

Application Security Analyst

Auburn Hills, MI · On-site

$55.50 - $74.25/hr

Lead Web Application Firewall (WAF) deployment for new and existing apps * Implement application ... Modern programming languages (Java, C#, Python) * Experience performing and interpreting results ...

Collaborates with development operations and engineering teams to embed security into continuous ... and web application firewall (WAF) organizations (Required) * Working knowledge of Microsoft ...

Collaborates with development operations and engineering teams to embed security into continuous ... and web application firewall (WAF) organizations (Required) * Working knowledge of Microsoft ...

As a Network Engineer, you will be responsible for designing, provisioning, monitoring, and ... Web Application Firewall (WAF) rule implementation. * Hybrid Cloud Networking (Azure): Solid ...

As a Web Application Developer you will deliver and support applications and tools that improve the efficiency of operational processes/workflows, request and resource management within a test ...

As a Web Application Developer you will deliver and support applications and tools that improve the efficiency of operational processes/workflows, request and resource management within a test ...

... web application Firewall and WSRR configuration Ensuring endpoint configuration and Policy Administration in conjunction with Information Security Works , MQ based integration, File based integration ...

... web application Firewall and WSRR configuration Ensuring endpoint configuration and Policy Administration in conjunction with Information Security Works , MQ based integration, File based integration ...

next page

Showing results 1-20

Web Application Firewall Waf Engineer information

What are some common challenges faced by Web Application Firewall (WAF) engineers, and how can they be addressed?

WAF Engineers often encounter challenges such as tuning firewall rules to minimize false positives while ensuring robust security, keeping up with rapidly evolving web application threats, and balancing security needs with application performance. Successfully addressing these issues requires continuous monitoring, regular updates to security policies, and close collaboration with development and DevOps teams to understand application changes. Adopting automation tools and participating in ongoing security training can also help WAF Engineers stay effective and proactive against new vulnerabilities.

What is a Web Application Firewall (WAF) engineer?

A Web Application Firewall (WAF) Engineer is a cybersecurity professional responsible for configuring, managing, and maintaining web application firewalls to protect web applications from threats such as SQL injection, cross-site scripting (XSS), and other common web exploits. They work to ensure that web applications are secure by designing WAF policies, monitoring traffic, and responding to security incidents. WAF Engineers also collaborate with development and operations teams to identify vulnerabilities and implement effective protection strategies. Their role is critical in safeguarding sensitive data and maintaining the integrity and availability of web-based services.

What are the key skills and qualifications needed to thrive as a Web Application Firewall (WAF) engineer?

To thrive as a Web Application Firewall (WAF) Engineer, you need a solid understanding of web security concepts, HTTP/HTTPS protocols, and experience with firewall configuration, often supported by a degree in computer science or a related field. Familiarity with WAF platforms (such as AWS WAF, F5, or Imperva), scripting languages, and certifications like CEH or CISSP are typically required. Attention to detail, strong problem-solving skills, and effective communication help you proactively identify threats and work closely with development and security teams. These skills are crucial to protect web applications against evolving cyber threats and ensure organizational security.
What are popular job titles related to Web Application Firewall Waf Engineer jobs in Michigan? For Web Application Firewall Waf Engineer jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Web Application Firewall Waf Engineer jobs in Michigan look for? The top searched job categories for Web Application Firewall Waf Engineer jobs in Michigan are:
What cities in Michigan are hiring for Web Application Firewall Waf Engineer jobs? Cities in Michigan with the most Web Application Firewall Waf Engineer job openings:

Application Security Analyst

Stellantis

Auburn Hills, MI • On-site

$55.50 - $74.25/hr

Full-time

Re-posted 29 days ago


Stellantis rating

7.5

Company rating: 7.5 out of 10

Based on 130 frontline employees who took The Breakroom Quiz

14th of 44 rated automakers


Job description

This role focuses on identifying, analyzing, and mitigating application security vulnerabilities throughout the SDLC. It supports a broader "Shift Left" cybersecurity strategy, ensuring security is integrated early in development and reinforced through DevSecOps practices.
Key Responsibilities:
Application Security & Testing
  • Perform security testing: SAST, DAST, IAST, mobile security, and dynamic testing
  • Analyze vulnerabilities and recommend secure coding fixes
  • Demonstrate vulnerabilities to development teams
  • Drive remediation efforts to closure

DevSecOps & Tooling
  • Work within CI/CD pipelines using tools such as:
    • Jenkins, GitLab, GitHub Actions, TeamCity
    • Checkmarx, GitHub Advanced Security, Burp Suite
  • Integrate security controls into development workflows

WAF & Security Controls
  • Lead Web Application Firewall (WAF) deployment for new and existing apps
  • Implement application security policies, controls, and standards

Collaboration & Enablement
  • Partner with development, platform, and supplier teams
  • Provide clear remediation guidance
  • Train teams on secure coding and application security practices
  • Develop training materials

Assessment & Reporting
  • Conduct security assessments using standard tools
  • Track and report:
    • Risks
    • Milestones
    • Deliverables
    • Status updates
  • Recommend strategies based on application risk posture

This role is based in Auburn Hills, MI and is required to be on-site in our HQ building 5 days per week.
Basic Qualifications:
  • Bachelor's degree in Computer Science, Information Technology, or related field
  • 3+ years of hands-on experience in application security, security testing, and DevSecOps
  • Strong understanding of:
    • Application architectures (web, mobile, APIs)
    • Software development methodologies (Agile, SDLC)
    • Modern programming languages (Java, C#, Python)
  • Experience performing and interpreting results from:
    • SAST, DAST, IAST, SCA, and mobile security testing tools
  • Hands-on experience with secure code review in common languages (Java, C#, Python preferred)
  • Prior background in application development, including:
    • Compiled code
    • Web applications / services
    • Mobile app development
  • Knowledge of security frameworks and standards:
    • NIST, ISO 27001
    • NIST SSDF or similar secure development frameworks
  • Strong understanding of:
    • OWASP Top 10 vulnerabilities and mitigation techniques
    • Common attack vectors (web exploits, DDoS, bot attacks)
  • Experience with WAF technologies:
    • Akamai, Cloudflare, AWS WAF, Azure Front Door
  • Familiarity with cloud platforms and modern environments:
    • AWS, Azure, GCP
    • Containers (Docker, Kubernetes)
  • Working knowledge of:
    • Programming/scripting: Java, JavaScript, SQL, HTML
    • Scripting languages (Python, Bash preferred)
  • Strong analytical, problem-solving, and communication skills
    • Ability to explain technical risks to non-technical audiences
    • Experience writing security reports and documentation
  • Ability to work independently and cross-functionally

Preferred Qualifications:
  • Industry certifications:
    • GIAC GWEB
    • ISC2 CSSLP
    • EC-Council CASE
    • Or equivalent AppSec certifications

What Stellantis employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom