Source Job

US Unlimited PTO

  • Drive enterprise standard WAF solution security strategy and champion best practices.
  • Design, engineer, and maintain Web Application Firewall solutions to protect enterprise applications.
  • Develop and enforce WAF policies to align with organizational security standards.

OWASP Python PowerShell

20 jobs similar to Senior Web Application Firewall (WAF) Engineer

Jobs ranked by similarity.

$130,000–$186,000/yr
US

  • Create, manage, and maintain the application security strategy and roadmap.
  • Develop, execute, and track the performance of security measures to protect Alma’s data, applications, and systems.
  • Build and provide high-quality application security documentation and training to engineers.

Alma simplifies access to high-quality, affordable mental health care by making it easy and financially rewarding for therapists to accept insurance. Alma has over 20,000 therapists in their growing network and was named one of Inc’s Best Workplaces in 2022 and 2023.

$94,000–$178,500/yr
US

  • Serve as a cloud security technical expert to develop and execute cloud security policies and procedures.
  • Collaborate with cloud technology teams across the enterprise to ensure the integrity and security of our digital assets in AWS/Azure IaaS environments.
  • Demonstrate high proficiency across a wide range of cloud security technologies to establish guardrails to prevent or automatically remediate common security misconfigurations.

AbbVie discovers and delivers innovative medicines and solutions that solve serious health issues today and addresses the medical challenges of tomorrow. It strives to have a remarkable impact on people's lives across several key therapeutic areas.

$140,000–$175,000/yr
US 3w PTO

  • Drive and enable proactive identification, analysis, and remediation of security vulnerabilities.
  • Respond to manage pen testing and bug bounty programs.
  • Work in partnership with Software Architecture, Risk/Compliance, the SRE team, and other partners, to integrate security capabilities into the SDLC.

Subsplash builds The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. They are a family-owned and operated company of 290+ mission-driven people.

US Canada Unlimited PTO

  • Own and lead the delivery of large, multi-quarter Application Security and Engineering initiatives.
  • Improve existing complex application security architectures and provide guidance for securing AI-based workflows.
  • Proactively identify emerging industry threats and act as Incident Commander for large-scale security incidents.

Wrapbook provides a unified payroll platform that seamlessly connects your entire team in one place. It empowers production teams to manage projects, pay cast and crew, track expenses, and generate data-driven insights. With a growing team of 250+ people across the USA and Canada, Wrapbook is backed by top-tier investors and has raised $130M.

US

  • Own vulnerability management, SIEM tuning and monitoring, incident response, and threat investigation.
  • Maintain secure baseline configurations based on industry standards.
  • Oversee AWS security controls and enforce cloud security guardrails.

Jobgether posts this position on behalf of a partner company. They use an AI-powered matching process to ensure applications are reviewed quickly and fairly.

$149,500–$169,202/yr
US

  • Design, build, and maintain security tools, scripts, and automations.
  • Partner with Engineering teams to manage and drive remediation of security vulnerabilities.
  • Evaluate and prioritize security risks based on industry standards and business context.

Weedmaps is a global leader in the cannabis industry. They are dedicated to transparency, education, and community, serving cannabis to consumers and businesses in the U.S. and worldwide.

$120,000–$160,000/yr
US Unlimited PTO 12w maternity

  • Own and lead Impiricus’s security architecture across AWS.
  • Design and implement application and infrastructure security controls across the SDLC.
  • Build and operate detection and response capabilities, including logging, monitoring, and alerting.

Impiricus is an AI-powered HCP Engagement Engine transforming how life sciences companies support physicians. They ethically connect HCPs to pharma resources and are known for their unique access to a large network of HCP advisors.

South America

  • Hands-on DevSecOps engineer securing ThriveCart's e-commerce platform infrastructure.
  • Implement security automation, maintain monitoring systems, and enable engineering teams with security tooling.
  • Ensure high availability, providing security tooling/dashboards and aiding developers with findings.

ThriveCart is the leading no-code sales platform for digital course creators, coaches, entrepreneurs, and online businesses looking to boost revenue, drive conversions, and scale audiences. ThriveCart powers over 65,000 businesses and 12 million enrolled students, generating over $2 billion in annual sales.

US

  • Lead execution of the enterprise information security program.
  • Oversee threat detection/response, vulnerability management, and incident response processes.
  • Partner with Engineering and Infrastructure teams to secure cloud environments and CI/CD pipelines.

bswift transforms benefits administration, making it simpler and smarter. They serve thousands of companies and millions of people nationwide, reducing administrative burdens and freeing HR teams to focus on creating thriving, people-first workplaces.

US

  • Optimize cloud infrastructure and manage governance, risk, and compliance.
  • Expand cloud architecture and implement scalable solutions.
  • Ensure high availability, security, and performance across AWS environments.

Rubris provides transformational legal technology and solutions for complex business and legal processes in the mass tort industry. Their data solutions streamline and automate processes to improve efficiency while delivering unprecedented insights and analytics.

$154,000–$247,000/yr
US Canada

  • Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  • Bring security best practices to the software development lifecycle.
  • Work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, with trust, transparency and creativity as their core values.

$181,125–$258,750/yr
US Unlimited PTO

  • Drive security of systems at scale and influence security strategy.
  • Integrate security into our SDLC with a shift-left approach.
  • Build a culture where security empowers developers through best practices.

Boulevard provides a client experience platform for appointment-based, self-care businesses, empowering customers to enhance client experiences. They are a team that values diverse backgrounds and believes in equal opportunity, fostering an inclusive culture where employees can excel.

$130,000–$140,000/yr
US UK

  • Design, deploy, and manage security tools and infrastructure to detect and prevent threats across cloud (AWS and GCP), corporate, and product environments.
  • Work collaboratively with engineering and product teams to integrate security into the SDLC (Secure Software Development Life Cycle) via threat modeling, code reviews, and automated testing.
  • Conduct security assessments, penetration testing, and vulnerability management to identify and remediate risks in our applications and services.

Acorns is a financial wellness app helping people and families save and invest money for the long term. Since 2014, Acorns has grown into a global company with multiple life-stage products serving the needs of kids, teens, adults, and parents.

Global 1w paternity

  • Security analysis of internal and third-party applications.
  • Vulnerability assessment in web applications and APIs.
  • Review of SAST/DAST scan findings and support in remediation.

Netrix Global provides the people, processes, and technology needed to run and scale modern, data-driven businesses that are always on and always secure. They work with clients of all sizes and specialize in solutions for healthcare, manufacturing, government, education, financial services, and legal industries.

US

  • Design and implement next-generation firewall and web security proxy solutions.
  • Engineer and support Cisco routing and switching infrastructure.
  • Monitor security platforms for threats and implement mitigation strategies.

GovCIO transforms government IT with innovative services and solutions. They foster a collaborative team environment where employees can make a positive impact.

US Canada

  • Manage identity & access security, administer and secure Windows Active Directory, Azure Entra ID and SSO configurations.
  • Secure cloud infrastructure by protecting and monitoring infrastructure hosted in AWS and GCP.
  • Lead endpoint protection & threat detection; manage Microsoft Defender XDR for endpoint security; monitor alerts, investigate incidents, and lead incident response efforts.

Backcountry's mission is to connect people to their passions through their online stores. They aim to supply customers with premium outdoor products, shopping experience, personalized Gearhead expertise and inspirational content.

$200,000–$260,000/yr
US

  • Mentor and develop security engineers and analysts.
  • Define and own the security strategy and roadmap.
  • Lead and scale the security function across vulnerability management.

Attentive is the AI marketing platform for 1:1 personalization redefining the way brands and people connect. They combine technology with human expertise to build authentic customer relationships, partnering with more than 8,000 customers across 70+ industries.

US

  • Design and automate Azure security controls.
  • Build “secure‑by‑default” CI/CD and tooling.
  • Lead incident response and ensure compliance with HIPAA, SOC 2, and HITRUST.

IntusCare is dedicated to providing a HIPAA-compliant healthcare platform for vulnerable elderly populations. As a fast-growing startup, they are scaling to support hundreds of customers and prioritize security.

US

  • Work alongside DevOps and engineering teams to ensure our platforms, repositories and CI/CD pipelines are secure by default while remaining easy to build, test, and deploy against
  • Identify security risks through tools, audits, and monitoring, and drive them to resolution — whether that means changing a policy, updating infrastructure, or improving a pipeline
  • Take ownership of the security posture across multiple AWS accounts and continuously improve it over time

Versaterm is a global public safety solutions company helping agencies transform how they serve their communities. Since 1977, they’ve been building an ecosystem of intuitive tools designed for public safety agencies, forensic labs, court systems, schools and other institutions.

US

  • Design, build, and evolve our AWS cloud infrastructure, with a focus on reliability, scalability, and security.
  • Own and improve CI/CD pipelines to support fast, safe, and repeatable deployments.
  • Build and maintain ETL pipelines that ingest data from third-party vendors and internal systems into our data warehouse.

AnswersNow is a venture-backed digital health company delivering virtual autism care to families, with a mission to empower and enhance the lives of those affected by autism by making personalized therapy more accessible. They are a fully-remote team that operates with trust, autonomy, and respect, embracing team members from all backgrounds, experiences, and identities.