WAF Engineer
Location: Remote
Rate: £550 Inside IR35
6 Month Contract
The Role
We are seeking an experienced WAF / WAAP Security Engineer / SME to play a key role in enhancing and strengthening our Web Application Firewall (WAF) and Web Application & API Protection (WAAP) capabilities across multiple solutions and applications.
This is a hands-on technical role focused on designing, developing, testing and implementing advanced WAF/WAAP security controls to protect web applications and APIs against evolving and sophisticated cyber threats.
The successful candidate will bring strong ethical hacking, web/API security, WAF engineering, security testing, coding and DevSecOps experience, with responsibility across the full WAF/WAAP use-case lifecycle.
Key Responsibilities
- Develop, enhance and maintain complex custom WAF/WAAP rules and features, addressing MVP requirements and security posture gaps.
- Own and support the full WAF/WAAP use-case lifecycle, including:
- Baseline lifecycle management
- Tiered baseline design
- Baseline and rule tuning
- Emergency rule updates
- WAF/WAAP incident management
- Consolidation feasibility study
- Conduct detailed technical evaluations of WAF/WAAP rulesets to assess the detection and prevention of web and API security threats.
- Identify WAF weaknesses, bypasses and evasion techniques through ethical hacking and security testing.
- Reverse-engineer attacker tactics and techniques to develop effective mitigation and detection rules.
- Design and develop automated testing mechanisms for baseline and custom WAF rules and features.
- Integrate WAF/security testing into CI/CD and automation pipelines, supporting DevSecOps and DevOps objectives.
- Provide SME support for security testing activities, including WAF Proofs of Concept (PoCs), technical assessments and solution evaluations.
- Provide specialist advice on web/API attack methodologies, exploitation, evasions and mitigation techniques.
- Support incident investigations and provide rapid WAF rule changes in response to emerging threats and vulnerabilities.
- Work closely with Security, Application, Engineering, DevOps and DevSecOps teams to embed effective security controls.
- Maintain accurate technical documentation, test evidence and reports to support traceability, governance and compliance.
- Keep the EPS Management team informed of emerging web/API threats and vulnerabilities, providing clear recommendations and countermeasures.
Key Skills & Experience
- 8+ years’ experience in cybersecurity, application security, WAF engineering or a related discipline.
- Strong hands-on experience with WAF / WAAP technologies.
- Proven experience developing, testing and tuning complex WAF rules and policies.
- Strong understanding of web application and API security, including OWASP-based attack techniques.
- Solid ethical hacking / penetration testing background.
- Experience identifying and exploiting WAF bypass and evasion techniques.
- Strong coding/scripting skills for security testing and automation.
- Experience integrating security testing into CI/CD pipelines and DevSecOps environments.
- Experience with WAF baselines, rule tuning, emergency changes and security incident management.
- Experience supporting WAF PoCs and technical evaluations.
- Strong analytical and problem-solving skills with the ability to translate offensive security findings into practical defensive controls.
- Excellent communication skills and the ability to operate effectively as a WAF/WAAP SME.
Desirable
- Experience across multiple WAF/WAAP platforms or vendors.
- Strong API security and automated security testing experience.
- Experience with WAF/WAAP platform rationalisation or consolidation assessments.
- Relevant security certifications such as OSCP, CREST, GWAPT, CEH or equivalent.