Expert Engineer/Application & End Point Security

🏢 e& uae
📍 United Arab EmiratesFull-timeRemote
📅 Posted: 2w ago🔄 Updated: 2w ago
CV%
✨ AI Summary
The Expert Engineer/Application & End Point Security will be responsible for the implementation, configuration, monitoring, and maintenance of Web Application Firewalls (WAFs) for both internal and external customers. This role involves collaborating with Cybersecurity teams to protect web applications from various cyber threats and vulnerabilities, including OWASP Top 10 attacks. Key responsibilities include end-to-end WAF provisioning, fine-tuning security policies, performing security enhancements, and managing WAF system resources. The role also requires maintaining documentation, monitoring licenses and contracts, and integrating WAF deployments with other security controls like SIEM and PAM. Ideal candidates will possess a minimum of 6 years of experience in WAF administration and web application security, with a BS in Computer Science, Information Technology, or a related field. Expertise in F5 troubleshooting, a strong understanding of web application security principles and OWASP Top 10, and knowledge of network protocols and firewall technologies are essential. Experience with scripting languages for automation is preferred.
Required Skills
Other
web server platforms
Engineering, Construction & Trades
Troubleshooting
Information Technology
OT SecurityOWASPFirewalls
Requirements
Requires a minimum of 6 years of experience in WAF administration and web application security. A BS in Computer Science, Information Technology, or a related field is mandatory. Expertise in WAF F5 troubleshooting and an in-depth understanding of web application security principles, including OWASP Top 10 vulnerabilities and common attack vectors are essential. Strong knowledge of network protocols, firewall technologies, and web server platforms is required. Experience with scripting languages is preferred for automation.
Description
Job DescriptionResponsible for the implementation, configuration, monitoring, and maintenance of WAF (Web Application Firewalls) deployed for internal and external customers. Work closely with the other Cybersecurity teams to ensure the protection of web applications via WAF, from various cyber threats and vulnerabilities including OWAPS Top 10 attacks. Effectively communicate and collaborate with different stakeholders for new WAF deployments and troubleshooting of operational issues at hand.ResponsibilitiesEnd-to-end provisioning of web applications on WAF including requirements gathering, defining the scope of protection and creating appropriate/tailored web security profile on WAF as per the web application architecture. Fine-tune the new security policies via rigorous testing of all web application flows to ensure maximum possible suppression of false positives for effective SOC monitoring. Plan and perform the security enhancements on security profiles of the existing web applications protected by WAF, ensuring minimal impact on live traffic. Fine-tune the attack logs for existing web applications by identifying false positives and updating the security profiles accordingly for effective monitoring. Keep track of the web applications certificates expiry on WAF and get them updated well in time to avoid any impact to users. Evaluate all the exceptions/whitelistings for any security impact on web applications before placing them on WAF. Get regular Security Assessments and audits done to ensure the effectiveness of WAF configurations and policies. Support the SOC/Incident Response team by providing the required attack logs from WAF for incident under investigation. Regularly monitor WAF system resources like CPU, memory, disk utilization to be within the threshold range, and raise the flags in timely manner. Ensure all WAF deployments to be running up-to-date and vendor supported OS versions. Implement corrective measures and remediation actions to address newly discovered security vulnerabilities on WAF. Evaluate, plan, test and execute the WAF upgrades to latest recommend stable versions for all WAF deployments, after extensive bug-scrubbing and careful analysis of all changes in new version to ensure no impact on protected application after the upgrade. Maintain proper and updated documentation related to WAF HLD, LLD, configurations, security policies, applications status and owner information, for all WAF deployments. Identify any unusual activity and attacks by monitoring the administrative and security alerts via regular reports. Monitor licenses and vendor contract expiry of all WAF deployments and communicate with the stakeholders accordingly. Perform regular backup restoration test drill for all WAF deployments. Highlight the operational challenges and current issues on all WAF deployments. Ensure that periodic backups to remote backup server are properly configured and are running successfully as per the schedule. Apply compensatory security controls on WAF for protected web applications if they cannot be fixed on application end. Deploy and configure dedicated WAF instances based on special projects requirements and create customized security policies for protected web applications. Integrate all WAF deployments with security controls including, but not limited to SIEM, PAM, RSA, Solarwinds etc. QualificationsExperience: Minimum 6 years experience related to WAF administration and web applications security.Certified Ethical Hacker (CEH) or similar certifications preferred. Must have expertise in WAF F5 troubleshooting.In-depth understanding of web application security principles, including OWASP Top 10 vulnerabilities and common attack vectors. Strong knowledge of network protocols, firewall technologies, and web server platforms. Experience with scripting languages is preferred for automation and customization of WAF configurations. BS (Computer Science, Information Technology, or related field) Excellent analytical and problem-solving skills, with the ability to prioritize and troubleshoot complex security issues. Effective communication skills, with the ability to collaborate with cross-functional teams and articulate technical concepts to non-technical stakeholders.
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00