Now hiring

WAF Engineer @ WTW External Careers Site

PhilippinesOnsiteFull-timeJob reference 202605201
Apply with ResuMinder

Opens on the employer's site

About this role

Duties and Responsibilities

• Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining an appropriate security posture. • Design, implement, maintain and optimise WAF policies across multi-cloud environments. • Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats. • Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls. • Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement. • Analyse attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations. • Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications. • Provide subject matter expertise for web application security, secure application delivery and WAF best practices. • Provide technical support to Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.

• Provide technical leadership during major incidents and drive to quick resolutions.

• Coach team members on a proactive basis, raising the team’s overall technical acumen.

• Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.

• Participate on the Technical Design Authority forum

• Implement changes/POCs to the environment in a controlled manner, with implementation and test plans.

-

• Demonstrable experience investigating, analysing and resolving WAF false positives and false negatives. • Strong experience implementing WAF solutions in Detection mode and transitioning policies to Prevention/Block mode through appropriate tuning and validation. • Proven experience developing and maintaining custom WAF rules, rule exclusions, rate limiting controls and attack mitigation policies, rather than solely relying on out-of-the-box managed rules. • Extensive knowledge of web application attack vectors, including OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), bot attacks, credential stuffing and API abuse. • Hands-on experience with attack mitigation, threat analysis and creation of bespoke security controls based on observed attack patterns. • Strong understanding of bot protection technologies, managed rule sets, policy tuning and wider web application security best practices. • Experience with Azure Front Door WAF and Azure Application Gateway WAF in enterprise-scale environments. • Experience working across multi-cloud environments and/or vendor-agnostic WAF platforms. • Experience deploying and managing WAF infrastructure using Terraform or other Infrastructure as Code (IaC) technologies. • Experience supporting large-scale production environments with responsibility for change implementation, incident response and threat mitigation. • Bachelor’s degree in Computer Science, Engineering, Information Technology strongly preferred, or relevant industry experience in related field. • Minimum 5 years’ experience in IT or Telecoms industry. Financial Services experience preferred. WTW is an Equal Opportunity Employer

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores