Duties and Responsibilities
• Perform analysis and tuning of WAF policies to minimise false positives and
false negatives while maintaining an appropriate security posture.
• Design, implement, maintain and optimise WAF policies across multi-cloud
environments.
• Lead the investigation and mitigation of web application attacks, including
OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7
DDoS attacks and other web-based threats.
• Develop, maintain and enhance custom WAF rules, managed rule exclusions,
rate-limiting policies and bot protection controls.
• Support transition of WAF policies from Detection mode to Prevention/Block
mode through structured analysis, tuning, testing and stakeholder engagement.
• Analyse attack patterns, logs and telemetry to identify emerging threats and
implement effective mitigations.
• Work closely with application owners, development teams and security
stakeholders to ensure secure onboarding and operation of internet-facing
applications.
• Provide subject matter expertise for web application security, secure
application delivery and WAF best practices.
• Provide technical support to Audit & Compliance, Capacity Management,
Lifecycle Management, Vulnerability Management and Risk Management Functions.
• Provide technical leadership during major incidents and drive to quick
resolutions.
• Coach team members on a proactive basis, raising the team’s overall technical
acumen.
• Restore service and complete root cause analysis of all incidents, driving
actions to mitigate the root cause and remove risk of reoccurrence.
• Participate on the Technical Design Authority forum
• Implement changes/POCs to the environment in a controlled manner, with
implementation and test plans.
Sign in and build your Career Profile to see your AI match score, strengths, and the exact skills to add for this role.