Jobs · Maryland

Sr. WAF Security Engineer

Warner Bros. Discovery · Silver Spring, MD · 4 wk ago
$105k–$196k/yrFull-time

About the role

The ideal candidate will be responsible for implementing, configuring, and maintaining enterprise-grade WAF and DDoS protections across a large portfolio of properties. They will also develop and fine-tune custom firewall rules, bot mitigation controls, and DDoS mitigation security policies, perform log analysis, contribute to automation efforts, and participate in on-call rotation for WAF/DDoS incident response.

Responsibilities

  • Implement, configure, and maintain WAF/DDoS solutions.
  • Develop and tune custom firewall rules, bot mitigation, and DDoS protections.
  • Perform log and traffic analysis to identify malicious activity and optimize defenses.
  • Partner with product, engineering, and operations teams to integrate WAF/Edge security into applications and services.
  • Provide guidance on best practices and support cross-team adoption of WAF/DDoS protections.
  • Advise technology teams and management on identified risks and treatment options.
  • Define or revise security elements, standards, and solutions for various technologies to achieve optimal security posture while delivering on business goals.
  • Research emerging threats and adapt defenses.
  • Recommend enhancements to strengthen edge/WAF posture.
  • Contribute to automation and infrastructure-as-code efforts to scale deployments.
  • Participate in Tentpole and product/feature launches in a WAF support role.
  • Incident Response - Serve as an escalation point during WAF/DDoS incidents. Participate in on-call rotation to provide subject matter expertise in real-time investigations and mitigation.

Qualifications & Experiences

  • Bachelor’s degree in Computer Science, Information Security, or equivalent work experience.
  • 5+ years of experience in application or network security with direct hands-on work in WAF/DDoS solutions.
  • Detailed understanding of the threats faced directly to consumer and digital platform organizations.
  • Proven expertise with at least one major WAF platform (Akamai, Fastly NGWAF, AWS WAF, Azure, or similar).
  • Practical experience writing/modifying WAF rules (e.g., AWS WAF, Azure or Cloudflare custom rules).
  • Experience with one of the major Cloud Providers SDK (BOTO3, Azure SDK, GCP Client Libraries) - AWS BOTO3 Preferred.
  • Strong understanding of HTTP/S protocols, OWASP Top 10, and API security models.
  • Proficiency with log analysis tools, scripting (Python, Bash, PowerShell), and automation frameworks.
  • Proven hands-on experience securing application across various Cloud Providers (AWS, GCP, Azure).
  • Strong problem-solving skills with the ability to quickly analyze issues and implement effective mitigations.
  • Excellent collaboration and communication skills across security, engineering, and product teams.

Qualifications & Experiences (continued)

  • Security certifications - CISSP, CISM, CISA, SANS, etc. (Not required but preferred).
  • Experience with infrastructure-as-code (Terraform, CloudFormation) for WAF/DDoS deployment.
  • Familiarity with CDN integrations and API Security frameworks.
  • Exposure to DDoS mitigation at scale, including volumetric and application-layer attacks.

Pay

$105,280.00 - $195,520.00 salary per year.

Similar jobs

Sr. WAF Security Engineer

Warner Bros. DiscoveryAtlanta, GA· 1 mo ago
Information Technology$105k–$196k/yrapply on careers.wbd.com

Sr. Security Engineer

Early WarningScottsdale, AZ· 1 mo ago
Information Technology$132k–$165k/yrapply on earlywarning.wd5.myworkdayjobs.com

Sr. Security Engineer

OpenSpaceSan Francisco, CA· 3 days ago
RemoteInformation Technology$180k–$230k/yrapply on grnh.se

Sr. Security Engineer

Yum! BrandsKansas, United States· 2 wk ago
RemoteInformation Technologyapply on yum.ongig.com

Sr. Security Engineer

OdysseyNew York, NY· 2 wk ago
Information Technology$180k–$220k/yrapply on jobs.ashbyhq.com