Security Engineer, Web Application Security
- Configure, maintain, and support Web Application Firewall (WAF) protections using Akamai App & API Protector and related security technologies.
- Monitor and investigate web security events involving:
- OWASP Top 10 vulnerabilities
- API attacks
- Bot traffic
- Credential stuffing
- DDoS attacks
- Layer 7 attacks
- Other suspicious or malicious web traffic
- Assist with WAF policy tuning to reduce false positives while maintaining appropriate security protections.
- Review application traffic and security logs to identify attack patterns, application behavior, and potential security concerns.
- Implement approved WAF policy changes, exceptions, allowlists, and security configuration updates.
- Support senior engineers during complex security investigations and production incidents.
- Configure and maintain CDN and edge security configurations supporting internet-facing applications.
- Work with Akamai technologies including:
- Property Manager
- Edge Hostnames
- Cloudlets
- DNS integrations
- Origin connectivity
- Caching and delivery configurations
- Troubleshoot common CDN and web application issues involving:
- HTTP response codes
- Cache behavior
- DNS
- Routing
- Origin connectivity
- TLS/SSL
- Application availability
- Support the onboarding of new websites and APIs onto the enterprise WAF/CDN platform.
- Support the lifecycle management of public TLS certificates, including:
- Request validation
- Issuance
- Deployment
- Renewal
- Revocation
- Replacement
- Monitor certificate inventories and upcoming expiration dates.
- Coordinate certificate changes and renewals with application owners and other technical teams.
- Validate certificates after deployment and troubleshoot common certificate, trust chain, DNS validation, and TLS issues.
- Maintain accurate certificate ownership and lifecycle documentation.
- Escalate certificate risks or renewal issues before they can impact production applications.
- Monitor and investigate WAF alerts, application issues, and security events.
- Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other available telemetry to assist with troubleshooting and investigations.
- Participate in incident response activities involving WAF, CDN, DDoS, certificates, and internet-facing applications.
- Assist with troubleshooting customer-impacting production issues and determining whether issues originate from the security/CDN layer or another application component.
- Implement approved mitigations and validate application functionality following security changes.
- Follow established incident management, escalation, and change management processes.
- Participate in the team's on-call rotation supporting globally distributed applications and services.
- Identify repetitive operational activities that could benefit from automation.
- Develop and maintain basic scripts and tools using technologies such as Python, PowerShell, Bash, or REST APIs.
- Assist with improving security monitoring, reporting, inventory management, and operational dashboards.
- Contribute to automation and standardization of application onboarding, WAF configuration, and certificate management processes.
- Learn and adopt Infrastructure-as-Code and API-driven security management practices where appropriate.
- Work closely with:
- Software Engineering
- Cloud Engineering
- Networking
- Infrastructure
- IAM
- Enterprise Architecture
- Compliance
- Security Operations
- Partner with application teams during WAF/CDN onboarding, troubleshooting, security changes, and certificate activities.
- Participate in technical discussions and architecture reviews alongside senior engineers.
- Create and maintain technical documentation, troubleshooting guides, operational procedures, and runbooks.
- Share knowledge and lessons learned with other members of the team.
- Identify opportunities to improve existing processes and operational practices.
- Follow established security standards, change management procedures, and operational processes.
- Support PCI DSS and internal audit activities by gathering technical evidence and documentation.
- Assist with periodic security reviews and control assessments.
- Maintain accurate documentation for WAF configurations, certificates, application ownership, exceptions, and operational processes.
- Support remediation activities identified through audits, vulnerability assessments, penetration testing, and security reviews.
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
- 2–4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
- Foundational understanding of:
- HTTP/HTTPS
- TLS/SSL
- DNS
- TCP/IP
- Web applications
- REST APIs
- Reverse proxies and CDN concepts
- Familiarity with Web Application Firewall technologies or web application security concepts.
- Familiarity with common web security threats and the OWASP Top 10.
- Experience troubleshooting technical issues using logs and other diagnostic information.
- Ability to analyze technical problems and follow issues through resolution.
- Strong written and verbal communication skills.
- Ability and willingness to learn new security technologies and platforms.
- Hands-on experience with Akamai or similar WAF/CDN platforms.
- Experience with Akamai technologies such as:
- App & API Protector
- Property Manager
- Certificate Manager
- Edge DNS
- Cloudlets
- Bot Manager
- Experience with public TLS certificate management.
- Experience working with cloud environments such as AWS, Azure, or GCP.
- Experience with SIEM or log analysis platforms such as Splunk, Sentinel, or similar technologies.
- Basic scripting experience with Python, PowerShell, or Bash.
- Experience working with REST APIs.
- Familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
- Security certifications such as Security+, GSEC, Akamai certifications, or equivalent technical certifications.
Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.