1

Web Application Firewall Waf Engineer Jobs in Reston, VA

... Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), endpoint ... Collaborate with software developers, data engineers, and cloud architects to integrate security ...

... Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), endpoint ... Collaborate with software developers, data engineers, and cloud architects to integrate security ...

... Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), endpoint ... Collaborate with software developers, data engineers, and cloud architects to integrate security ...

... Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), endpoint ... Collaborate with software developers, data engineers, and cloud architects to integrate security ...

Network Security

Herndon, VA

$107K - $147K/yr

Web Application Firewall such as Barracuda. Good hands on experience in configuring firewall policies, VPN access, Intrusion Prevention system (IPS), Intrusion detection system (IDS), Web application ...

Web Developer Security Engineer

Washington, DC ยท On-site

$145K - $175K/yr

The successful candidate will serve as a senior technical contributor responsible for web application and api security engineering, threat modeling, vulnerability remediation, owasp top 10, waf/fim ...

New

Application Security

Bethesda, MD

$63 - $84/hr

... application developers for applying Security Software Development Life Cycle Collaborate with ... web application security issues, such as those outlined in OWASP Top 10 Strong knowledge of ...

Review and analyze web server and application logs to detect anomalies and indicators of compromise ... application firewalls (WAFs), file integrity monitoring, and security testing tools. * Ability to ...

New

Sr. WAF Security Engineer

Silver Spring, MD ยท On-site

$118K - $162K/yr

Develop and fine-tune custom firewall rules, bot mitigation controls, and DDoS mitigation security ... Research and stay current on the latest attack vectors, vulnerabilities, and exploits affecting web ...

... Security Engineer to support the security of mission-critical web applications, APIs, and ... Experience deploying, configuring, and maintaining Web Application Firewalls (WAFs). * Experience ...

Security Engineer (Web Application)

Arlington, VA ยท On-site

$67.50 - $90.25/hr

Security Engineer (Web Application) Location: Arlington, VA Security Clearance: Secret Duties and Responsibilities The Security Engineer (Web Application) supports this Transportation Security ...

Showing results 41-60

Web Application Firewall Waf Engineer information

See Reston, VA salary details

$31

$69

$100

How much do web application firewall waf engineer jobs pay per hour?

As of Aug 8, 2026, the average hourly pay for web application firewall waf engineer in Reston, VA is $69.08, according to ZipRecruiter salary data. Most workers in this role earn between $58.75 and $78.51 per hour, depending on experience, location, and employer.

What are some common challenges faced by Web Application Firewall (WAF) engineers, and how can they be addressed?

WAF Engineers often encounter challenges such as tuning firewall rules to minimize false positives while ensuring robust security, keeping up with rapidly evolving web application threats, and balancing security needs with application performance. Successfully addressing these issues requires continuous monitoring, regular updates to security policies, and close collaboration with development and DevOps teams to understand application changes. Adopting automation tools and participating in ongoing security training can also help WAF Engineers stay effective and proactive against new vulnerabilities.

What is a Web Application Firewall (WAF) engineer?

A Web Application Firewall (WAF) Engineer is a cybersecurity professional responsible for configuring, managing, and maintaining web application firewalls to protect web applications from threats such as SQL injection, cross-site scripting (XSS), and other common web exploits. They work to ensure that web applications are secure by designing WAF policies, monitoring traffic, and responding to security incidents. WAF Engineers also collaborate with development and operations teams to identify vulnerabilities and implement effective protection strategies. Their role is critical in safeguarding sensitive data and maintaining the integrity and availability of web-based services.

What are the key skills and qualifications needed to thrive as a Web Application Firewall (WAF) engineer?

To thrive as a Web Application Firewall (WAF) Engineer, you need a solid understanding of web security concepts, HTTP/HTTPS protocols, and experience with firewall configuration, often supported by a degree in computer science or a related field. Familiarity with WAF platforms (such as AWS WAF, F5, or Imperva), scripting languages, and certifications like CEH or CISSP are typically required. Attention to detail, strong problem-solving skills, and effective communication help you proactively identify threats and work closely with development and security teams. These skills are crucial to protect web applications against evolving cyber threats and ensure organizational security.
What are popular job titles related to Web Application Firewall Waf Engineer jobs in Reston, VA? For Web Application Firewall Waf Engineer jobs in Reston, VA, the most frequently searched job titles are:
What job categories do people searching Web Application Firewall Waf Engineer jobs in Reston, VA look for? The top searched job categories for Web Application Firewall Waf Engineer jobs in Reston, VA are:
What cities near Reston, VA are hiring for Web Application Firewall Waf Engineer jobs? Cities near Reston, VA with the most Web Application Firewall Waf Engineer job openings:
Infographic showing various Web Application Firewall Waf Engineer job openings in Reston, VA as of August 2026, with employment types broken down into 76% Full Time, 18% Part Time, and 6% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $143,690 per year, or $69.1 per hour.

DevSecOps Engineer

Occam Solutions

Washington, DC โ€ข On-site

Full-time

Posted 9 days ago


Job description

Primary Responsibility
The DevSecOps Engineer shall serve as the lead technical engineer responsible for designing, implementing, securing, automating, and sustaining the cloud infrastructure supporting the Office of Naval Research (ONR) Data & Analytics environment. The DevSecOps Engineer shall lead the implementation and execution of the technical requirements identified in PWS Section 4.5 - Technical Infrastructure and Platform Support, including infrastructure automation, Continuous Integration/Continuous Deployment (CI/CD), cloud security, container orchestration, Infrastructure-as-Code (IaC), and operational sustainment of the FedRAMP High and DoD Impact Level 5 (IL5) cloud environment.
The DevSecOps Engineer shall architect and maintain secure cloud infrastructure, automate deployment pipelines, support AI/ML platform integration, implement cloud-native security controls, monitor system health and security events, and ensure compliance with DoD cybersecurity requirements. This position will work closely with software developers, data engineers, cloud architects, cybersecurity personnel, and Government stakeholders to deliver resilient, scalable, and secure cloud services.
Duties and Responsibilities
The DevSecOps Engineer shall:
  • Design, deploy, automate, and maintain secure cloud infrastructure supporting mission applications and analytics platforms.
  • Develop, implement, and manage automated CI/CD pipelines using tools such as Jenkins, GitLab CI/CD, or equivalent technologies.
  • Build and maintain Infrastructure-as-Code (IaC) solutions utilizing Terraform, Ansible, or similar automation frameworks.
  • Implement and manage containerized application environments using Docker, Kubernetes, or comparable orchestration platforms.
  • Configure, monitor, and optimize cloud-native security services including Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), endpoint protection, and Security Information and Event Management (SIEM) platforms.
  • Analyze security logs, audit events, vulnerability reports, and SIEM alerts to identify threats, recommend mitigation strategies, and support incident response activities.
  • Support continuous Authority to Operate (ATO) compliance through configuration management, security patching, vulnerability remediation, and security documentation.
  • Implement secure API management, identity and access management (IAM), secrets management, encryption, and least-privilege access controls.
  • Develop automated monitoring, logging, alerting, and operational dashboards to improve system reliability and performance.
  • Support deployment and operationalization of AI/ML platforms and services, including cloud-native machine learning environments.
  • Collaborate with software developers, data engineers, and cloud architects to integrate security throughout the software development lifecycle (SDLC).
  • Ensure cloud infrastructure complies with DoD cybersecurity policies, FedRAMP High requirements, DoD IL5 controls, and applicable security frameworks.
  • Support system scalability, resilience, disaster recovery, and operational continuity.
  • Document system architectures, deployment procedures, security configurations, and operational processes.

Minimum Qualifications
The DevSecOps Engineer shall meet the requirements for the "DevSecOps Engineer - Intermediate" labor category as defined in the CHESS ITES-3S contract vehicle and possess the following additional qualifications:
  • Seven (7) years of combined experience in DevSecOps, DevOps, SecOps, or MLOps engineering and development.
  • Five (5) years of hands-on experience designing, securing, implementing, and maintaining cloud environments, preferably within AWS GovCloud, Azure Government, or similarly regulated cloud environments.
  • Demonstrated experience supporting cloud environments operating under FedRAMP High, DoD Impact Level 5 (IL5), or comparable federal security requirements.
  • Verifiable experience on at least two (2) projects designing, implementing, and managing Continuous Integration/Continuous Deployment (CI/CD) pipelines using Jenkins, GitLab CI/CD, Azure DevOps, GitHub Actions, or equivalent technologies.
  • Demonstrated expertise implementing and managing containerization and orchestration technologies, including Docker, Kubernetes, OpenShift, or similar platforms.
  • Hands-on experience implementing Infrastructure-as-Code (IaC) using Terraform, Ansible, CloudFormation, or comparable automation tools.
  • Experience configuring and administering cloud-native security capabilities including Web Application Firewalls (WAF), Intrusion Detection/Prevention Systems (IDS/IPS), Security Information and Event Management (SIEM), vulnerability management, and cloud security monitoring solutions.
  • Verifiable experience analyzing security logs, SIEM data, audit records, and threat intelligence to identify vulnerabilities, investigate security events, and implement corrective actions.
  • Experience implementing secure Identity and Access Management (IAM), encryption, secrets management, and Zero Trust security principles.
  • Experience supporting automated monitoring, logging, system performance optimization, and operational sustainment of enterprise cloud platforms.
  • Strong understanding of DevSecOps best practices, secure software development lifecycle (SSDLC), and cloud security architectures.

Qualifications
  • Active Secret security clearance (required).
  • Current DoD 8140 (or legacy DoD 8570) cybersecurity certification applicable to privileged access functions (e.g., Security+, CySA+, CASP+, CISSP, CCSP).
  • AWS Certified DevOps Engineer - Professional, AWS Security Specialty, Azure DevOps Engineer Expert, Certified Kubernetes Administrator (CKA), or comparable cloud certifications.
  • Experience supporting AI/ML environments, including AWS SageMaker, Azure Machine Learning, or similar platforms.
  • Experience with streaming data technologies such as Apache Kafka, AWS Kinesis, or equivalent event-driven architectures.
  • Familiarity with NIST RMF, DISA STIGs, FedRAMP, Zero Trust Architecture, and DoD cybersecurity compliance requirements.