GMS-Senior-Web Application Firewall
EY
EY
Join EY and build a career defining your own path. We are seeking a Senior Web Application Firewall (WAF) Engineer to take ownership of our application security gateway infrastructure throughout its entire lifecycle. This role requires deep technical expertise in safeguarding modern web applications, APIs, and microservices against advanced Layer 7 threats, including OWASP Top 10, botnets, and DDoS attacks.
The ideal candidate will possess hands-on experience with advanced WAF rule tuning, managing both positive and negative security models, and effective collaboration with development and DevOps teams. You will be instrumental in assessing, building, transitioning, and operating our security solutions, ensuring robust protection and continuous improvement.
This is an opportunity to contribute to a better working world by building trust through assurance and helping clients grow, transform, and operate using data and technology. We value diverse teams and unique perspectives to tackle complex global issues.
You will conduct comprehensive security assessments of web applications, API endpoints, and ingress traffic architectures, analyzing current WAF policies and identifying coverage gaps against the OWASP Top 10 and API Security Top 10. Collaborate with development teams to threat-model new applications and define WAF integration requirements, while also auditing SSL/TLS configurations.
Deploy, configure, and manage enterprise WAF solutions, designing and implementing both negative and positive security models. Configure advanced bot mitigation, rate limiting, and API security layers. Integrate WAF infrastructure with CI/CD pipelines for automated policy deployment.
Safely transition WAF policies from monitoring to blocking mode, minimizing false positives and coordinating User Acceptance Testing. Produce detailed "As-Built" documentation and conduct knowledge transfer sessions.
Serve as the senior technical escalation point for complex security incidents and DDoS attacks. Perform continuous rule tuning, signature optimization, and exception handling. Monitor WAF performance and ensure seamless log ingestion for forensic investigation. Manage ITIL-based change management activities and coordinate with CAB for compliant implementation.
We are looking for a candidate with 3-5 years of specialized experience in web application security, WAF administration, or application delivery controller management. Deep, hands-on expertise with leading WAF platforms such as Cloudflare, Akamai, Imperva, F5 Advanced WAF, or AWS/Azure WAF is essential.
A comprehensive understanding of the OWASP Top 10, API Top 10, and common web attack vectors like SQL injection, XSS, and RCE is required. A solid grasp of HTTP/HTTPS protocols, RESTful APIs, JSON/XML payloads, DNS, SSL/TLS, and reverse proxy architectures is also necessary.
Familiarity with automation tools, Python or Bash scripting, and Infrastructure as Code (Terraform/CloudFormation) for policy management is important. While not strictly required, industry certifications like CAP, CISSP, CCSP, or vendor-specific WAF/Cloud security credentials are highly preferred. Excellent stakeholder management, the ability to bridge security and developer needs, and strong analytical problem-solving skills are key.
EY Global Delivery Services ( EY GDS)
Management Consulting