1

Web Application Firewall Waf Engineer Jobs in Oregon

Our Technical Operations team is looking for a Network Engineer to be a part of our Technology ... Web Application Firewall * Network Access Control (NAC) * Data Loss Prevention (DLP) * Anti-virus ...

The Network Engineer's responsibilities include planning, designing and implementing best practice ... Web Application Firewall * Network Access Control (NAC) * Data Loss Prevention (DLP) * Anti-virus ...

Sr. Cloud Security Engineer - FedRamp

OR · On-site +1

$114K - $156K/yr

Deploy and manage Web Application Firewalls (WAFs), including F5 and other cloud-native WAF ... Cloud Security Engineering in a multi-cloud environment. - Expert-level proficiency in ...

Sales Engineer (Application Security)

OR · On-site +1

$103K - $128K/yr

Sales Engineers are an integral part of Thales's sales organization and assist the sales team with ... DDoS Mitigation, Web application firewalls, API Management & Security, Bot Management or related ...

... firewall rules and system configuration checks. * Apply Web application and API security principles ... WAF and Zero Trust). * Adept at working with internal Product & Engineering, Legal, People ...

We are looking for contracted PHP/MySQL web developer familiar with PHP web frameworks like ... Skills/Qualifications: 3+ years experience focused on web application development Advanced ...

Application Security Engineer

OR · On-site +1

$58.75 - $78.50/hr

A conceptual understanding of vulnerability categories and web application security standards. * An ... engineering and security. Benefits * Flexible work environment * Unlimited Vacation * 100% paid ...

next page

Showing results 1-20

Web Application Firewall Waf Engineer information

What is a Web Application Firewall (WAF) engineer?

A Web Application Firewall (WAF) Engineer is a cybersecurity professional responsible for configuring, managing, and maintaining web application firewalls to protect web applications from threats such as SQL injection, cross-site scripting (XSS), and other common web exploits. They work to ensure that web applications are secure by designing WAF policies, monitoring traffic, and responding to security incidents. WAF Engineers also collaborate with development and operations teams to identify vulnerabilities and implement effective protection strategies. Their role is critical in safeguarding sensitive data and maintaining the integrity and availability of web-based services.

What are the key skills and qualifications needed to thrive as a Web Application Firewall (WAF) engineer?

To thrive as a Web Application Firewall (WAF) Engineer, you need a solid understanding of web security concepts, HTTP/HTTPS protocols, and experience with firewall configuration, often supported by a degree in computer science or a related field. Familiarity with WAF platforms (such as AWS WAF, F5, or Imperva), scripting languages, and certifications like CEH or CISSP are typically required. Attention to detail, strong problem-solving skills, and effective communication help you proactively identify threats and work closely with development and security teams. These skills are crucial to protect web applications against evolving cyber threats and ensure organizational security.

What are some common challenges faced by Web Application Firewall (WAF) engineers, and how can they be addressed?

WAF Engineers often encounter challenges such as tuning firewall rules to minimize false positives while ensuring robust security, keeping up with rapidly evolving web application threats, and balancing security needs with application performance. Successfully addressing these issues requires continuous monitoring, regular updates to security policies, and close collaboration with development and DevOps teams to understand application changes. Adopting automation tools and participating in ongoing security training can also help WAF Engineers stay effective and proactive against new vulnerabilities.

What are popular job titles related to Web Application Firewall Waf Engineer jobs in Oregon?

For Web Application Firewall Waf Engineer jobs in Oregon, the most frequently searched job titles are:

What job categories do people searching Web Application Firewall Waf Engineer jobs in Oregon look for?

The top searched job categories for Web Application Firewall Waf Engineer jobs in Oregon are:

What cities in Oregon are hiring for Web Application Firewall Waf Engineer jobs?

Cities in Oregon with the most Web Application Firewall Waf Engineer job openings:

Manager, Information Security (Remote)

Salem, OR • On-site

Full-time

Posted 9 days ago


Job description

Job Summary:

We are seeking a Manager, Information Security to lead the execution of our Security Operations and Engineering program. This is a hands-on, player-coach role: you will manage a small, high-caliber team of 2–3 direct reports while also personally rolling up your sleeves on engineering, triage, and incident response when needed. You will own the roadmap and day-to-day execution across Web Application Firewall (WAF), Data Loss Prevention (DLP), AI Security and Security Automation, Vulnerability Management, Incident Management, Cloud Security, Purple Team, and broader Security Engineering across our infrastructure.

Duties and Responsibilities: 

  • Execute the Security Operations and Engineering strategy, aligning priorities with overall business and security goals.
  • Operate as a player-coach: manage, mentor, and grow 2–3 direct reports while remaining hands-on with engineering and operational work.
  • Partner with the CISO and cross-functional leaders (Engineering, IT, Compliance, HR, Legal) to align security initiatives with business needs.
  • Manage team capacity, priorities, and career development; conduct performance reviews and coaching.
  • Own vendor and tooling deployments.
  • Report on program metrics, risk posture, and roadmap progress to Senior leaders
  • Web Application Firewall (WAF): Own configuration, tuning, and lifecycle management of WAF policies to protect production applications from evolving threats.
  • Data Loss Prevention (DLP): Design, implement, and continuously improve DLP controls across endpoints, cloud, and email to protect sensitive data.
  • AI Security / Automation: Evaluate and secure AI tools and workflows used across the business; build automation (including AI-assisted) to scale detection, triage, and response.
  • Vulnerability Management: Own the end-to-end vulnerability management lifecycle: scanning, prioritization, remediation tracking, and reporting — across infrastructure and applications.
  • Incident Management: Lead incident response efforts, from detection through containment, eradication, and post-incident review; maintain and improve incident response playbooks.
  • Cloud Security: Set and enforce cloud security architecture, configuration standards, and controls across our cloud environments.
  • Purple Team: Run and mature purple team exercises, partnering offense and defense to validate detection and response capabilities and close gaps.
  • Security Engineering: Design, build, and maintain security tooling and infrastructure (detection engineering, logging/SIEM, automation pipelines) across the environment.
  • Perform other duties as assigned.


 Education and Experience:

  • 7+ years of experience in information security, with at least 2–3 years in a people management or team lead capacity.
  • Demonstrated player-coach experience: comfortable managing a team while remaining technically hands-on.
  • Hands-on experience with WAF platforms, DLP tooling, vulnerability management platforms, and cloud security controls (AWS, Azure, and/or GCP).
  • Experience leading or participating in incident response, including root cause analysis and post-incident reporting.
  • Experience building or deploying automation to scale security operations; exposure to AI/LLM tooling and its security implications is a strong plus.
  • Relevant certifications (e.g., CISSP, CISM, GCIH, OSCP, or cloud security certifications) are a plus but not required.


Knowledge, Skills and Abilities: 

  • Familiarity with purple team methodologies and how offensive testing informs defensive engineering.
  • Strong scripting/automation skills (e.g., Python, Terraform or similar) for tooling and detection engineering.
  • Excellent communication skills, with the ability to translate technical risk for executive and non-technical audiences.
  • Proven ability to context-switch across strategic, operational, and tactical work without losing focus or quality.


Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.


Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.