Akamai WAF Security Engineer
The AES Group · Alpharetta, GA · 2 wk ago
HybridContract
Location: NYC, NY or Alpharetta, GA - 3 days a week onsite (in-person interview is mandatory)
About The AES Group
The AES Group is a premier technology and engineering consulting company that has been bringing businesses and talent together for over 20 years to deliver innovative solutions that have the greatest positive impact on society. AES has helped over 40 business enterprises, including Fortune 500 companies, engage their customers, empower their employees, and transform their business operations with the power of cloud, data, AI, engineering, and other emerging technologies.
Responsibilities
- Lead onboarding and migration of internet-facing applications to Akamai Kona Site Defender (WAF).
- Coordinate with application, DNS, load balancer, firewall, proxy, and QA teams to execute application migrations, testing, cutovers, and rollback plans.
- Analyze WAF events, investigate false positives, and tune security policies while minimizing business impact.
- Review production traffic, blocked requests, and implement targeted policy exceptions where appropriate.
- Support AI/LLM workloads and API security, including troubleshooting AI-generated traffic, designing compensating controls, and implementing API-specific protections.
- Monitor and analyze security events across WAF, Bot Manager, API Security, Client Reputation, and DDoS platforms.
- Conduct quarterly security reviews, WAF upgrades, policy optimization, and migration from monitor mode to deny mode.
- Investigate production incidents, application latency, traffic routing, load balancer interactions, and WAF-related outages.
- Provide security architecture guidance on OWASP Top 10, API security, bot mitigation, DDoS protection, and secure web application design.
- Partner with application owners, infrastructure teams, auditors, risk management, and security leadership to track onboarding progress and remediation activities.
- Develop dashboards and metrics for WAF adoption, security exceptions, bot mitigation effectiveness, API discovery, and attack trends.
- Serve as the primary technical liaison with Akamai, supporting product enhancements, troubleshooting, roadmap discussions, and pilot deployments.
Requirements
- 5+ years of hands-on experience with Akamai Web Application Security.
- Strong experience with Akamai Kona Site Defender (KSD).
- Experience with Akamai Bot Manager.
- Experience with Akamai API Security.
- Strong understanding of OWASP Top 10 web application security risks.
- Experience in WAF policy tuning, false-positive analysis, and security event monitoring.
- Experience responding to production security incidents and troubleshooting WAF-related issues.
- Knowledge of DNS, Load Balancers, Reverse Proxies, Firewalls, SSL/TLS, and HTTP/HTTPS protocols.
- Excellent communication and stakeholder management skills.
Preferred Skills
- Experience with AI/LLM Security.
- Hands-on experience with Akamai Firewall for AI.
- Enterprise-scale WAF migration and application onboarding experience.
- Experience in the Financial Services domain.
- Knowledge of API security, bot mitigation, DDoS protection, and Client Reputation controls.
Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or a related field.
- Relevant Akamai or cybersecurity certifications are a plus.