Senior Cybersecurity Engineer - Web Application Firewall
Jakarta
Horangi Cyber Security
Leading cyber security firm in Asia, offering advanced cyber security products and services, including consulting. We specialize in equipping businesses with robust security solutions and expert guidance to navigate the digital landscape...As a Senior Cybersecurity Engineer, you will develop, support, tune and deploy Web Application Firewall security solutions for Horangi customers. Primary day-to-day job duties involve:
-Web Application Security: Engineering, deployment, and operations of Web Application Firewall security solutions and integration of those platforms with other security solutions as required.-Performing hands-on Web Application Firewall deployment, configuration, policy fine-tuning and maintenance
This is a hands-on technical job. We are looking for an experienced candidate with extensive experience with Akamai, Cloudflare, Imperva, and/or AWS Web Application Firewall policy fine-tuning and administration.
What you will be doing
- Engineers, configures, deploys, and maintains Web Application Firewall solutions
- Develops advanced alerts/reports to meet the requirements of key stakeholders
- Develops automation for security tools management and workflow integration
- Collaborates with key stakeholders within Information Security and Engineering teams to develop specific use cases to address specific business needs
- Creates WAF rules/signatures to mitigate threats and implements best practices
- Creation and implementation of custom alerting in SIEM for investigations
- Works extensively with different stakeholders across Visa for tuning WAF policies or creating custom signatures
- Aids in gathering metrics for measuring Performance and Risk
- Provides ongoing support to existing monitoring capabilities and data collection systems.
- Provides development support for the expansion and implementation of new systems.
What you will need to succeed
- Over 5 years of experience in Cybersecurity engineering with experience that includes configuring and managing Web Application Firewalls.
- Expert Python Scripting, Perl, Shell scripting. Development experience in C++, Java, Java Script.
- Excellent experience with Regular Expressions
- Excellent experience with Security Incident and Event Management (SIEM)
- Solid understanding of web applications, web servers, application firewalls, frameworks and protocols with respect to web application development, deployment, and operation
- Extensive knowledge of Imperva, Akamai and/or Cloudflare Web Application Firewall configuration and management
- Extensive knowledge of web technologies and concepts
- Strong understanding of TCP/IP, web protocols and networking concepts
- Expertise in one or more areas such as operating systems, web services, programming languages, network devices, application vulnerabilities and attack vectors
- Experience in reviewing and analyzing log files and data correlation
- Excellent Logical and Practical understanding of SSDLC
- Experience with managing Web/Application Servers
- Scripting/programming using Python
- Excellent understanding and hands on experience with Java and/or .NET technologies
- Excellent understanding of PKI Technology
- Excellent knowledge of open source and commercial application security tools and frameworks, including but not limited to Kali Web application testing tools
- Experience in exploiting web apps and web services security vulnerabilities including cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks.
- Excellent understanding of OWASP Risks, Vulnerabilities and Mitigation Mechanisms
- Experience with Web Application Firewall management and rules
- Well versed in system exploits (e.g. Buffer Overflows, PTH attacks, windows authentication framework etc.)
- Excellent understanding of DDoS techniques and mitigation mechanisms
- Solid understanding of Incident Response Process
- Prior experience in Security Operations and Incident Response
- Excellent understanding of Cyber Security Operations, Incident Response processes
- Excellent communication skills
- Excellent team player
- CISSP, SANS GCIA, SANS GIAC, and/or AWS Security is a Plus
- Bachelor’s degree in engineering, computer science, information security, or information systems
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security Automation AWS C CISSP Cloudflare Computer Science DDoS Exploits Firewalls GCIA GIAC Incident response Java Kali Log files Monitoring Open Source OWASP Perl PKI Python SANS Scripting Security strategy SIEM SQL SQL injection Strategy TCP/IP Vulnerabilities Web application testing Windows XML XSS
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Cyber Security Architect jobs
- Open Manager Pentest H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Senior Security Architect jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open ISO 27001-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Security assessment-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open CI/CD-related jobs
- Open IDS-related jobs
- Open DevSecOps-related jobs
- Open CEH-related jobs