Application Delivery-WAF Content Security Engineer
Own end-to-end application delivery, global traffic management, Web Application Firewall (WAF), and content/file threat protection across F5 BIG-IP (LTM & Advanced WAF), F5 GTM, FortiWeb WAF, and OPSWAT. Responsible for traffic steering, SSL/TLS lifecycle, high availability, API/bot protection, file-based threat triage, and automation of infrastructure delivery.
- Configure and manage F5 BIG-IP LTM: virtual servers, pools, health monitors, persistence profiles, and traffic steering.
- Administer F5 GTM for global DNS-based load balancing, south-north traffic steering, private DNS integration, and pool/health monitor management.
- Own SSL/TLS lifecycle across the app delivery stack: offloading, certificate management, SSL profiles, and TLS hardening on F5 and FortiWeb tiers.
- Design and maintain High Availability: device clustering, config sync, failover, and resiliency across F5 platforms.
- Manage Web Application Protection: OWASP Top 10 profiles, custom security policies, signature management, API protection, bot mitigation, rate limiting, and IP intelligence (F5 Advanced WAF, FortiWeb).
- Tune attack detection policies, manage signature updates, and reduce false positives across WAF platforms; build custom attack signatures where required.
- Lead BIG-IP and FortiWeb appliance/VE deployment, provisioning, TMOS/firmware upgrades, hotfixes, backup/restore, and configuration lifecycle management.
- Integrate FortiWeb with OCI Load Balancer and other cloud LB services for L7 inspection.
- Manage OPSWAT file scanning platform for Data-in-Transit and Data-at-Rest content inspection; triage, analyze, and action file scan results, including false-positive review.
- Maintain scanning policies and workflows to support secure file transfer and content-handling processes across the organization.
- Drive Infrastructure Automation using REST API, AS3, Terraform, and Ansible for automated configuration deployment.
- Perform health/performance monitoring, logging, analytics, and root-cause analysis; own vulnerability assessment, hardening, and patch compliance for all app-delivery and content-security assets.
Required Qualifications & Experience
- Bachelor’s degree in computer science, Information Security, or related field.
- 8+ years' experience with F5 BIG-IP (LTM/GTM/Advanced WAF) and/or FortiWeb in enterprise production environments.
- Experience with content disarm & reconstruction (CDR) / multi-scanning platforms (OPSWAT or equivalent) is highly desirable.
- Working knowledge of infrastructure-as-code and automation (Terraform, Ansible, REST API/AS3).
- Certifications preferred: F5 Certified BIG-IP Administrator (F5-CA), F5 301a/302 (Advanced WAF), NSE 6 (FortiWeb).
- Strong understanding of DNS, SSL/TLS, Layer 4–7 traffic management, and file-based threat triage.