Network Security Engineer
Summary
Monitor web traffic and WAF logs to block OWASP Top 10 threats; tune rules, write custom regex signatures, and support incident response for Equifax’s security infrastructure.
Equifax es donde puedes impulsar tus posibilidades. Si deseas alcanzar tu verdadero potencial, trazar nuevos caminos, desarrollar nuevas habilidades, colaborar con mentes brillantes y tener un impacto significativo, queremos saber de ti.
What you’ll do
- Monitor and Analyze Traffic: Actively monitor real-time web traffic and analyze WAF logs using SIEM tools (like DEVO) to detect and mitigate threats such as SQL injection, XSS, and bot attacks.
- Deploy and Tune Security Policies: Safely deploy and tune WAF rules, transitioning them from Log/Simulate mode to Block mode while investigating false positives to ensure valid business traffic is never disrupted.
- Provide Virtual Patching: Write custom regex signatures (PCRE) to "virtually patch" OWASP Top 10 vulnerabilities, protecting applications before developers can implement permanent code fixes.
- Support Incident Response: Actively participate in security incident response by providing WAF telemetry, and collaborate with web development teams to share actionable feedback on application vulnerabilities.
- Reporting and Documentation: Draft technical documentation and weekly reports detailing attack trends, blocked threats, and system performance metrics for and security metrics.
What experience you need
2-4 years of experience in a corporate role. Bachelor's Degree highly preferred (Willing to consider experience that aligns closely to all requirements w/out a degree).
Deep HTTP Knowledge: Must understand headers, cookies, sessions, and the full request/response lifecycle.
OWASP Top 10: Proven experience mitigating SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Cross-Site Request Forgery (CSRF).
Policy Tuning: Ability to transition WAF rules from Log/Simulate mode to Block mode without breaking production traffic.
Regex & Custom Rules: Proficiency in writing custom signatures (PCRE) to virtually patch vulnerabilities before developers can fix the code.
What could set you apart
Demonstrated expertise in managing the request-response lifecycle, including deep familiarity with status codes, headers, and payloads.
Ofrecemos modalidad de trabajo híbrido, horarios flexibles, días libres adicionales, paquetes integrales de compensación y seguro médico complementario, convenio con gimnasio, beneficios para madres y padres, acceso a nuestra plataforma de aprendizaje en línea, programas de reconocimiento, desarrollo de carrera profesional y un entorno diverso y multicultural, ¡entre otros!
Equifax fue ranqueado en el top 5 de empresas con mejor desarrollo de carrera por LinkedIn.
¿Estás listo para impulsar tus posibilidades? ¡Aplica hoy y comienza un camino hacia una nueva y emocionante carrera en Equifax, donde puedes marcar la diferencia!
Primary Location:
CHL-Santiago-Technology-CenterFunction:
Function - Security Governance and ComplianceSchedule:
Full time