About the job
Responsible for the implementation, configuration, monitoring, and maintenance of WAF (Web Application Firewalls) deployed for internal and external customers. Work closely with other Cybersecurity teams to ensure the protection of web applications via WAF from various cyber threats and vulnerabilities, including OWASP Top 10 attacks. Effectively communicate and collaborate with different stakeholders for new WAF deployments and troubleshoot operational issues as they arise.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- End-to-end provisioning of web applications on WAF, including requirements gathering, defining the scope of protection, and creating an appropriate/tailored web security profile on WAF as per the web application architecture.
- Fine-tune the new security policies via rigorous testing of all web application flows to ensure maximum possible suppression of false positives for effective SOC monitoring.
- Plan and perform security enhancements on security profiles of existing web applications protected by WAF, ensuring minimal impact on live traffic.
- Fine-tune the attack logs for existing web applications by identifying false positives and updating the security profiles accordingly for effective monitoring.
- Keep track of the web application certificates’ expiry on WAF and get them updated in a timely manner to avoid any impact on users.
- Evaluate all exceptions/whitelistings for any security impact on web applications before placing them on WAF.
- Conduct regular Security Assessments and audits to ensure the effectiveness of WAF configurations and policies.
- Support the SOC/Incident Response team by providing required attack logs from WAF for incidents under investigation.
- Regularly monitor WAF system resources like CPU, memory, and disk utilization to ensure they remain within the threshold range; raise flags in a timely manner.
- Ensure all WAF deployments are running up-to-date and vendor-supported OS versions.
- Implement corrective measures and remediation actions to address newly discovered security vulnerabilities on WAF.
- Evaluate, plan, test, and execute WAF upgrades to the latest recommended stable versions for all deployments, after extensive bug-scrubbing and careful analysis of all changes in the new version to ensure no impact on protected applications after the upgrade.
- Maintain proper and updated documentation related to WAF high-level design (HLD), low-level design (LLD), configurations, security policies, applications status, and owner information for all WAF deployments.
- Identify any unusual activity and attacks by monitoring administrative and security alerts via regular reports.
- Monitor licenses and vendor contract expiry of all WAF deployments and communicate with stakeholders accordingly.
- Perform regular backup restoration test drills for all WAF deployments.
- Highlight operational challenges and current issues on all WAF deployments.
- Ensure that periodic backups to the remote backup server are properly configured and running successfully as per the schedule.
- Apply compensatory security controls on WAF for protected web applications if they cannot be fixed on the application end.
- Deploy and configure dedicated WAF instances based on special project requirements and create customized security policies for protected web applications.
- Integrate all WAF deployments with security controls including, but not limited to, SIEM, PAM, RSA, Solarwinds, etc.
Qualifications
Experience: Minimum 6 years’ experience related to WAF administration and web application security.
- Certified Ethical Hacker (CEH) or similar certifications preferred.
- Must have expertise in WAF F5 troubleshooting.
- In-depth understanding of web application security principles, including OWASP Top 10 vulnerabilities and common attack vectors.
- Strong knowledge of network protocols, firewall technologies, and web server platforms.
- Experience with scripting languages is preferred for automation and customization of WAF configurations.
- BS (Computer Science, Information Technology, or related field).
- Excellent analytical and problem-solving skills with the ability to prioritize and troubleshoot complex security issues.
- Effective communication skills, with the ability to collaborate with cross-functional teams and articulate technical concepts to non-technical stakeholders.