Position Summary
We are seeking an experienced Infrastructure Security Engineer to support, maintain, and optimize enterprise Web Application Firewall (WAF) and Application Security Manager (ASM) environments. The ideal candidate will have strong hands-on experience with F5 ASM/WAF, web security technologies, incident management, and web application security best practices. This role is responsible for protecting business-critical web applications against evolving cyber threats while ensuring high availability and optimal performance.
Key Responsibilities
- Support, administer, and maintain enterprise F5 ASM/WAF environments.
- Design, implement, configure, and optimize F5 ASM solutions to protect web applications from security threats and vulnerabilities.
- Deploy, tune, and continuously improve WAF security policies based on business requirements and emerging threats.
- Manage and support web security platforms such as F5 ASM, AppTrana, AWS WAF, Cloudflare, and Akamai.
- Configure and manage F5 LTM, including Virtual IPs (VIPs), load balancing, SSL certificates, and traffic management.
- Monitor web application traffic and investigate suspicious activities to identify and mitigate security risks.
- Analyze, troubleshoot, and respond to web application security incidents in accordance with established incident management processes.
- Review and fine-tune attack signatures and security rules to minimize false positives while maintaining strong protection.
- Ensure compliance with web application security best practices, including OWASP Top 10 recommendations.
- Perform vulnerability assessments and support the vulnerability management lifecycle by implementing remediation and mitigation controls.
- Collaborate with infrastructure, application, and security teams to strengthen the organization's security posture.
- Handle operational support tickets and ensure timely resolution within agreed service levels (SLAs).
Required Skills & Experience
- Proven experience implementing and managing F5 ASM/Web Application Firewall (WAF) solutions.
Hands-on experience with one or more web security products:
- F5 ASM
- Akamai
- AWS WAF
- Cloudflare
- AppTrana
Strong knowledge of F5 LTM, including:
- Virtual IP (VIP) configuration
- Load balancing concepts
- SSL certificate management
Strong understanding of:
- Web Application Security
- OWASP Top 10
- Common web vulnerabilities and exploits
- Attack signatures and threat detection
- Experience deploying and tuning WAF security policies.
- Knowledge of security monitoring, incident response, and incident management processes.
- Experience with vulnerability management lifecycle and remediation practices.
- Strong troubleshooting and analytical skills.
- Ability to work independently while collaborating with cross-functional teams.
Preferred Qualifications
- Experience supporting enterprise infrastructure security environments.
- Familiarity with security monitoring and threat analysis tools.
- Relevant certifications such as:
- F5 Certified Administrator (F5-CA)
- F5 Certified Technology Specialist (CTS)
- Security+
- CEH
- CISSP (preferred)