Full Time

Web Application Security Engineer - The Provato Group - Mayfield Heights, OH

The Provato Group

Mayfield Heights, OH
Posted 12 days ago

The Web Application Security Engineer is responsible for enterprise Web Application Firewall and edge security operations protecting high-traffic ecommerce applications and APIs. This role provides hands-on ownership of Akamai security platforms and supports additional security technologies.

This position requires strong operational discipline, deep understanding of web application threats, and the ability to balance security enforcement with availability and customer experience in production environments.


Responsibilities Essential Functions:

Monitor and analyze inbound web traffic to identify and respond to suspicious activities, ensuring real-time threat mitigation.
Collaborate with cross functional teams to integrate WAF solutions into CI/CD pipelines and application architectures and focus on maturing WAF protections.
Maintain and optimize WAF configurations to balance security, performance, and user experience and enable process optimization and automation.
Be involved in regular security assessments, vulnerability scans, and penetration testing to identify gaps in WAF protection.
Maintain a close working relation with the Application Development team to ensure optimal protections are used for all new application releases.
Ensure adequate testing and validation and has been performed for all protections and mitigations before rollout.
Collaborate with our Software Development, Quality Assurance, and Project Management teams to solve difficult technical problems, define and deliver highly scalable cloud applications and make fact-based recommendations regarding tactical and strategic technology adoption for our team.
Promote, foster, and proactively implement agile best practices daily.
Design, deploy, and manage WAF solutions for on-premise and cloud-based platforms
Develop and fine-tune WAF policies, rules, and signatures to mitigate known threats and application abuses as well as emerging threats.
Lead incident respons