WAF Engineering Lead
WTW · New York, NY · 6 days ago
On-siteEngineering$120k–$160k/yrFull-time
About the role
The WAF Engineering Lead role is intended to maximise the operational performance of WTW services and maintain a strong secure posture. The role is accountable for BAU support of issues, controlling policy & compliance, and supporting change activities. This role ensures the technical success of WAF services within the WTW environment in a Tier 3 capacity and management of direct reports.
Responsibilities
- Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining an appropriate security posture.
- Design, implement, maintain and optimise WAF policies across multi-cloud environments.
- Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.
- Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.
- Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement.
- Analyse attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.
- Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications.
- Provide subject matter expertise for web application security, secure application delivery and WAF best practices.
- Provide technical leadership to Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.
- Provide leadership during major incidents and drive to quick resolutions.
- Provide line management for direct reports.
- Act as point of escalation for areas of accountability.
- Coach team members on a proactive basis, raising the team’s overall technical acumen.
- Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.
- Participate on the Technical Design Authority forum.
- Implement changes/POCs to the environment in a controlled manner, with implementation and test plans.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Information Technology strongly preferred, or relevant industry experience in related field.
- Minimum 5 years’ leadership experience (direct reports) in similar role.
- Minimum 5 years’ experience in IT or Telecoms industry. Financial Services experience preferred.
- Minimum 5 years’ Azure WAF/Network management experience.
- Minimum 5 years’ Network Security experience. Azure Firewall, Palo Alto Firewall/VPN, Cisco would be advantageous.
- Demonstrable experience investigating, analysing and resolving WAF false positives and false negatives.
- Strong experience implementing WAF solutions in Detection mode and transitioning policies to Prevention/Block mode through appropriate tuning and validation.
- Proven experience developing and maintaining custom WAF rules, rule exclusions, rate limiting controls and attack mitigation policies, rather than solely relying on out-of-the-box managed rules.
- Extensive knowledge of web application attack vectors, including OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), bot attacks, credential stuffing and API abuse.
- Hands-on experience with attack mitigation, threat analysis and creation of bespoke security controls based on observed attack patterns.
- Strong understanding of bot protection technologies, managed rule sets, policy tuning and wider web application security best practices.
- Experience with Azure Front Door WAF and Azure Application Gateway WAF in enterprise-scale environments.
- Experience working across multi-cloud environments and/or vendor-agnostic WAF platforms.
- Experience deploying and managing WAF infrastructure using Terraform or other Infrastructure as Code (IaC) technologies.
- Experience supporting large-scale production environments with responsibility for change implementation, incident response and threat mitigation.
- Ability to blend creativity, problem solving, and technical skills for refining existing concepts or developing new approaches.
- Ability to enable changes in the business processes and ability to work cooperatively with stakeholders and peers is essential.
- Ability to work under pressure and to resolve issues effectively.
- Excellent interpersonal and communication skills.
Employment-based non-immigrant visa sponsorship and/or assistance is not offered for this specific job opportunity.
Pay
The base salary compensation range for this role is $120,000.00 - $160,000.00 USD annually. This role is also eligible for an annual short-term incentive bonus.
Benefits
- Health and Welfare: Mental health/emotional wellbeing (including Employee Assistance Program), medical (including prescription drug coverage and fertility benefits), dental, vision, Health Savings Account, Commuter Accounts, Health Care and Dependent Care Flexible Spending Accounts, company-paid life insurance, supplemental life insurance, AD&D, group accident, group critical illness, group legal, identity theft protection, wellbeing program, adoption assistance, surrogacy assistance, auto/home insurance, pet insurance, and other work/life resources.
- Leave Benefits: Paid Holidays, Annual Paid Time Off (includes state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave), Paid Time Off (only included for Washington roles).
- Retirement Benefits: Qualified contributory pension plan (if eligible) and 401(k) plan with annual nonelective company contribution. Non-qualified retirement plans available to senior level colleagues who satisfy the plans’ eligibility requirements.