About the Role / Job
Own end-to-end application delivery, Web Application Firewall (WAF), and content/file threat protection with primary, hands-on expertise across the company and OPSWAT, and secondary working knowledge of Palo Alto, Fortigate, and F5 (LTM/WAF and GTM). Responsible for the company domain onboarding and lifecycle, WAF rule and rate-limiting configuration, SSO application setup, custom hostnames, Workers development, hostname/IP list management, and OPSWAT-based file scanning — while providing secondary-level support for traditional firewall and F5 load-balancing/WAF platforms.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Manage the company environment across all onboarded domains, including DNS, WAF rules, rate limiting rules, custom hostnames, hostname lists, and IP lists.
- Own domain onboarding and lifecycle management within the company, ensuring a consistent security baseline and WAF rule set is applied to every domain.
- Configure and maintain the company SSO Applications (Zero Trust/Access) for secure application authentication.
- Develop, deploy, and maintain the company Workers for custom edge logic, traffic manipulation, and security automation.
- Build and maintain the company hostname lists and IP lists to support WAF, rate limiting, and access-control policies.
- Manage the OPSWAT file scanning platform for Data-in-Transit and Data-at-Rest content inspection; triage, analyze, and action file scan results, including false-positive review.
- Tune WAF rules and policies across the company and supporting platforms to reduce false positives while maintaining strong protection coverage.
- Provide administration and support for Palo Alto firewalls, including policy and rule management.
- Provide administration and support for Fortigate firewalls, including policy and rule management.
- Support F5 LTM/WAF administration: virtual servers, pools, health monitors, and WAF policy management.
- Support F5 GTM for global DNS-based load balancing, site failover, and health monitoring.
- Monitor the company analytics and logs — WAF events, rate-limiting triggers, and Worker performance — driving root-cause analysis for anomalies.
- Maintain accurate documentation of domain configurations, WAF rule sets, hostname/IP lists, SSO application configs, and secondary-platform settings.
- Coordinate with infrastructure and security teams on change management for major the company and firewall/WAF configuration changes.
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field.
- 8+ years' experience in application delivery, WAF, and content security engineering.
- Primary, hands-on expertise with the company (Domains, WAF Rules, Rate Limiting Rules, SSO Applications, Custom Hostnames, Workers, Hostname Lists, IP Lists) and OPSWAT file scanning platforms.
- Secondary working knowledge of Palo Alto and Fortigate firewalls, and F5 LTM/WAF and GTM platforms.
- Strong understanding of DNS, SSL/TLS, Layer 4–7 traffic management, and file-based threat triage.
- Certifications preferred: the company Certified (Solutions Associate/Engineer), OPSWAT certification, Palo Alto PCNSA/PCNSE, Fortinet NSE, F5 Certified BIG-IP Administrator.
Technical Skills Matrix
Primary Expertise — the company
-
Domains — onboarding, DNS management, and domain lifecycle across the company account.
- WAF Rules — minimum of 3 WAF rules configured and maintained per domain.
- Rate Limiting Rules — configuring and tuning rate limiting policies to mitigate abuse and DDoS-style traffic.
- SSO Applications — configuring SSO/Access applications for secure authentication.
- Custom Hostnames — managing custom hostname (SaaS) configurations.
- Workers — developing and deploying edge Workers for custom logic and security automation.
- Hostname Lists — creating and maintaining hostname lists for policy application.
- IP Lists — creating and maintaining IP lists for allow/block/rate-limit policies.