Sr. WAF Security Engineer
Warner Bros. Discovery · Silver Spring, MD · 4 wk ago
$105k–$196k/yrFull-time
About the role
The ideal candidate will be responsible for implementing, configuring, and maintaining enterprise-grade WAF and DDoS protections across a large portfolio of properties. They will also develop and fine-tune custom firewall rules, bot mitigation controls, and DDoS mitigation security policies, perform log analysis, contribute to automation efforts, and participate in on-call rotation for WAF/DDoS incident response.
Responsibilities
- Implement, configure, and maintain WAF/DDoS solutions.
- Develop and tune custom firewall rules, bot mitigation, and DDoS protections.
- Perform log and traffic analysis to identify malicious activity and optimize defenses.
- Partner with product, engineering, and operations teams to integrate WAF/Edge security into applications and services.
- Provide guidance on best practices and support cross-team adoption of WAF/DDoS protections.
- Advise technology teams and management on identified risks and treatment options.
- Define or revise security elements, standards, and solutions for various technologies to achieve optimal security posture while delivering on business goals.
- Research emerging threats and adapt defenses.
- Recommend enhancements to strengthen edge/WAF posture.
- Contribute to automation and infrastructure-as-code efforts to scale deployments.
- Participate in Tentpole and product/feature launches in a WAF support role.
- Incident Response - Serve as an escalation point during WAF/DDoS incidents. Participate in on-call rotation to provide subject matter expertise in real-time investigations and mitigation.
Qualifications & Experiences
- Bachelor’s degree in Computer Science, Information Security, or equivalent work experience.
- 5+ years of experience in application or network security with direct hands-on work in WAF/DDoS solutions.
- Detailed understanding of the threats faced directly to consumer and digital platform organizations.
- Proven expertise with at least one major WAF platform (Akamai, Fastly NGWAF, AWS WAF, Azure, or similar).
- Practical experience writing/modifying WAF rules (e.g., AWS WAF, Azure or Cloudflare custom rules).
- Experience with one of the major Cloud Providers SDK (BOTO3, Azure SDK, GCP Client Libraries) - AWS BOTO3 Preferred.
- Strong understanding of HTTP/S protocols, OWASP Top 10, and API security models.
- Proficiency with log analysis tools, scripting (Python, Bash, PowerShell), and automation frameworks.
- Proven hands-on experience securing application across various Cloud Providers (AWS, GCP, Azure).
- Strong problem-solving skills with the ability to quickly analyze issues and implement effective mitigations.
- Excellent collaboration and communication skills across security, engineering, and product teams.
Qualifications & Experiences (continued)
- Security certifications - CISSP, CISM, CISA, SANS, etc. (Not required but preferred).
- Experience with infrastructure-as-code (Terraform, CloudFormation) for WAF/DDoS deployment.
- Familiarity with CDN integrations and API Security frameworks.
- Exposure to DDoS mitigation at scale, including volumetric and application-layer attacks.
Pay
$105,280.00 - $195,520.00 salary per year.