Job Listing

Security Engineer – Akamai WAF/BotManager

Must Haves:

  • 5+ years managing Akamai Web Application Firewall (WAF) and Bot Manager Premier (BMP)
  • Experience in enterprise environments, including rule sets, configuration management, reporting, and alerting capabilities.
  • Hands-on experience responding to web application security incidents and tuning Bot Manager policies to balance security effectiveness and application usability.
  • Strong knowledge of web application security threats –  OWASP Top 10 vulnerabilities, and mitigation strategies via WAF technologies.
  • Familiarity with cloud network architectures, particularly AWS, and how WAF fits into hybrid/multi-cloud security postures.
  • Proficient in log analysis, SIEM integration, and security alert triage.

Plusses:

·      Relevant certifications (e.g., GIAC Web Application Penetration Tester, Certified Cloud Security Professional (CCSP), Akamai Certified Professional)

  • Experience working in financial services or similarly regulated industries.
  • Prior exposure to infrastructure-as-code tooling for WAF policy management is a bonus.
  • Understanding of DevSecOps principles and security automation.

We are seeking an experienced Security Engineering Consultant with deep expertise in Akamai Web Application Firewall (WAF) and Bot Manager Premier (BMP) to support a critical migration of applications and workloads to the AWS public cloud. This is a high-impact role requiring an individual who can enhance and optimize existing Akamai WAF and BMP policies and serve as a key responder during critical operational incidents and security events.

Responsibilities:

  • Lead the assessment, optimization, and continuous improvement of Akamai WAF policies to ensure robust protection against OWASP Top 10 and emerging web vulnerabilities.
  • Collaborate closely with cloud, application, and security teams to align WAF/BMP configurations with evolving business and compliance requirements.
  • Respond rapidly and effectively to critical security incidents, performing root cause analysis, mitigating ongoing threats, and implementing preventive measures.
  • Manage day-to-day Akamai WAF operations including policy updates, tuning, false positive mitigation, and rule deployment.
  • Conduct periodic reviews of WAF logs and alerts, generating actionable insights and recommendations.
  • Assist with knowledge transfer and documentation related to WAF policies, incidents, and operational procedures.
  • Provide expert guidance on integrating Akamai WAF protections within a hybrid cloud environment, focusing on security posture during the AWS migration.
  • Ensure adherence to enterprise security standards, industry best practices, and regulatory requirements.

Job details