Talent.com
Senior WAF Security Engineer
Senior WAF Security EngineerPearson • Durham, North Carolina
Senior WAF Security Engineer

Senior WAF Security Engineer

Pearson • Durham, North Carolina
[job_card.30_days_ago]
[job_preview.job_type]
  • [job_card.full_time]
[job_card.job_description]

WAF Security Engineer

Role Purpose

  • The Enterprise Application Security team is responsible for protecting Pearson’s commercial digital products and data, our learner’s data, and Pearson’s internal applications. By employing a blend of technology, developer training, test integration, and process automation, the Application Security team’s goal is to reduce our risks and provide ongoing Internet safe havens for our learners.

  • This role will play a critical role in enhancing our Web Application Firewall (WAF) across multiple solutions and applications and will be pivotal in crafting, testing, and implementing advanced WAF solutions. This role involves a strong focus on developing robust security measures against web-based attacks, contributing significantly to the security posture of our organization, and achieving audits.

Responsibilities

As a direct report to the Head of Application Security Engineering, you will have the following accountabilities:

  • Develop and refine complex custom WAF rules and features, ensuring mitigation of Minimum Viable Product (MVP) and security posture gaps.

  • Ownership of all technical aspects tasks essential for passing WAF audits ensuring they are compliant and included in DevOps Automation processes, including aspects such as management plan access control traffic visibility, application of mitigative OWASP Top 10 based rules and features, versioning strategies for each WAF solution, etc.

  • Coding expertise to create effective testing mechanisms for baseline and custom WAF rules, integrating these tests seamlessly into automation pipelines.

  • Offer subject matter expert (SME) support in various security testing areas, including WAF Proofs of Concept (PoCs)

  • Provide specialized WAF-focused advice on web and API attack methodologies, evasions, and mitigation techniques, leveraging your ethical hacking background.

  • Contribute security and technical knowledge alongside organizational skills to assist Cyber teams with effective WAF SIEM Use Cases

Skills and Experience

  • Someone that has extensive experience with Web Application Security log analysis and that is derived from a Cyber SOC/CSIRT work background who is willing to up-skill into a WAF Engineering SME – AWS and Akamai

  • Strong background in ethical hacking

  • Extensive experience with web-based attack methodologies, including knowledge of tools, payloads, exploits, and countermeasures.

  • Proficient in web application and API security.

  • Skilled in identifying and mitigating WAF/IPS/CSPM security vulnerabilities.

  • Expertise in developing custom WAF rules and security testing packages.

  • Solid understanding of OWASP top 10 vulnerabilities.

  • Proficiency in at least one programming language

  • Ability to automate security testing within CI/CD pipelines.

  • Knowledgeable in networking, cloud firewalls, and web technologies.

  • Strong grasp of DevSecOps principles and practices.

  • Awareness of Agile methodologies

What to expect from Pearson

Did you know Pearson is one of the 10 most innovative education companies of 2022?

At Pearson, we add life to a lifetime of learning so everyone can realize the life they imagine. We do this by creating vibrant and enriching learning experiences designed for real-life impact. We are on a journey to be 100 percent digital to meet the changing needs of the global population by developing a new strategy with ambitious targets. To deliver on our strategic vision, we have five business divisions that are the foundation for the long-term growth of the company: Assessment & Qualifications, Virtual Learning, English Language Learning, Workforce Skills and Higher Education. Alongside these, we have our corporate divisions: Digital & Technology, Finance, Global Corporate Marketing & Communications, Human Resources, Legal, Strategy and Direct to Consumer. Learn more at

We value the power of an inclusive culture and also a strong sense of belonging. We promote a culture where differences are embraced, opportunities are accessible, consideration and respect are the norm and all individuals are supported in reaching their full potential. Through our talent, we believe that diversity, equity and inclusion make us a more innovative and vibrant place to work. People are at the center, and we are committed to building a workplace where talent can learn, grow and thrive.

[job_alerts.create_a_job]

Senior WAF Security Engineer • Durham, North Carolina

[internal_linking.similar_jobs]
Security Architecture Lead for AI & Cloud Systems

Security Architecture Lead for AI & Cloud Systems

NVIDIA • Durham, NC, United States
[job_card.full_time]
A leading tech company in Durham is seeking a Senior Manager for Software Security Architecture.The role involves leading a team of security architects, developing strategic security software roadm...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Store Security Specialist

Store Security Specialist

Wegmans Food Markets • Chapel Hill, NC, US
[job_card.full_time]
Morning, Afternoon, Evening (Includes Weekends).EARN A BONUS UP TO $2,500! Hiring immediately!.At Wegmans, our store security teams are committed to keeping our customers and employees safe.Our sec...[show_more]
[last_updated.last_updated_1_day] • [promoted]
Lead Analog and Mixed-Signal Design Engineer

Lead Analog and Mixed-Signal Design Engineer

Ampere • Durham, NC, United States
[job_card.full_time]
Ampere is a semiconductor design company for a new era, leading the future of computing with an innovative approach to CPU design focused on high-performance, energy efficient AI compute.As a pione...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Sr. Engineer- Stormwater Infrastructure Work Group

Sr. Engineer- Stormwater Infrastructure Work Group

City of Durham • Durham, NC, United States
[job_card.full_time] +1
Engineer- Stormwater Infrastructure Work Group.Engineer- Stormwater Infrastructure Work Group.Environmental & Street Services.Advance in your career while making a real difference in the community ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Integration Engineer @ Research Triangle Park, Durham NC (Onsite Mode)

Senior Integration Engineer @ Research Triangle Park, Durham NC (Onsite Mode)

My3Tech Inc • Durham, NC, United States
[job_card.full_time]
Position: NC FAST Integration Engineer.Location: Research Triangle Park, Durham NC (Onsite Mode).Please list AWS based tools and technologies on which the candidate has hands-on experience.The refe...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Forward Deployed Engineer - Entry Level

Forward Deployed Engineer - Entry Level

IBM • Durham, NC, United States
[job_card.full_time]
A career in IBM Software means you'll be part of a team that transforms our customer's challenges into solutions.Seeking new possibilities and always staying curious, we are a team dedicated to cre...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Traffic Engineer

Senior Traffic Engineer

Cubic • Durham, NC, United States
[job_card.full_time]
Business Unit: Cubic Transportation Systems Company Details: When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's live...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Director, Product Marketing - Endpoint Security GTM

Senior Director, Product Marketing - Endpoint Security GTM

Tanium • Durham, NC, United States
[job_card.full_time]
A leading cybersecurity firm is seeking a Senior Director of Product Marketing to drive the go-to-market strategy for endpoint security solutions.This pivotal role requires comprehensive market ana...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior SCOM Monitoring Engineer

Senior SCOM Monitoring Engineer

Saxon Global • Durham, NC, United States
[job_card.full_time]
Title: Senior SCOM Monitoring Engineer / IT Infrastructure & Monitoring.Senior SCOM Monitoring Engineers.These individuals will be responsible for designing, implementing, optimizing, and supportin...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
CrowdStrike Cloud Security Engineer

CrowdStrike Cloud Security Engineer

Openkyber • NC, United States
[job_card.full_time]
[filters_job_card.quick_apply]
Job Title: DevSecOps Engineer Location: Raleigh, NC / Remote Duration: Long-term (12+ Months) Must be able to obtain a Security Clearance Description: Seeking a DevSecOps Engineer to strengthen our...[show_more]
[last_updated.last_updated_variable_days]
Experienced Mothers Wanted - Make a Life Changing Impact and Earn $60,000+

Experienced Mothers Wanted - Make a Life Changing Impact and Earn $60,000+

Newborn Advantage Surrogacy • Roxboro, NC, US
[job_card.full_time]
Compensated Surrogacy Opportunity - Make a Life Changing Impact and Earn $60,000+.Newborn Advantage Surrogacy is seeking qualified women to become gestational surrogates and help intended parents g...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Electrical Engineer-Analog/Mixed-Signal & FPGA

Senior Electrical Engineer-Analog/Mixed-Signal & FPGA

AURA Technologies, LLC • Durham, NC, United States
[job_card.full_time]
AURA Technologies, LLC (AURA) is an advanced research and development (R&D) company creating game-changing innovations for the US Department of Defense and the private sector in cutting-edge techno...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Facets Configuration Manager - Remote

Senior Facets Configuration Manager - Remote

Cognizant • Durham, NC-555 S Mangum St, NC, US
[filters.remote]
[job_card.full_time]
Senior Facets Configuration Manager.Senior Facets Configuration Manager.Facets Benefit and Workflow functionality while leveraging deep ANSI SQL expertise to support complex data environments.You w...[show_more]
[last_updated.last_updated_variable_hours] • [promoted] • [new]
Security Operations Manager (WTVD)

Security Operations Manager (WTVD)

The Walt Disney Company • Durham, NC, United States
[job_card.full_time]
Security Operations is responsible for the security and safety of cast members, guests and the protection of company assets for all non-theme park locations in all areas of the United States and Ca...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
SAP Security Analyst #ESF5948

SAP Security Analyst #ESF5948

ExpertHiring • Apex, NC, us
[job_card.full_time]
[filters_job_card.quick_apply]
Top reasons to work for our client:.Manager is well respected by team!.Awesome career development opportunities!.This global organization operates complex SAP environments supporting critical busin...[show_more]
[last_updated.last_updated_variable_days]
Senior Engineer, Interoperability

Senior Engineer, Interoperability

Pluto Health • Durham, NC, United States
[job_card.full_time]
Pluto Health is on a mission to connect people with the care they need when they need it.Pluto bridges AI and health services, unifying health information from siloed sources and.Whether it involve...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Senior Engineer -Technology

Senior Engineer -Technology

Tata Consultancy Services • Durham, NC, United States
[job_card.full_time]
Must Have Technical/Functional Skills 10 years professional experience, with 7+ years on AEM & Related Technologies.Design and development experience in Adobe AEM experience in AEM building blocks ...[show_more]
[last_updated.last_updated_variable_days] • [promoted]
Mixed Signal Engineer

Mixed Signal Engineer

Analog Devices • Durham, NC, United States
[job_card.permanent]
NASDAQ: ADI ) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge.ADI combines analog, digital, and software technologies i...[show_more]
[last_updated.last_updated_variable_days] • [promoted]