LA International Computer Consultants Ltd

Job Vacancy Cyber_WAF & Application Security SME

England

LA International Computer Consultants Ltd

Job position

Fixed term
As soon as possible
365 months
< 2 years experience
Remote
England, United Kingdom
Published on 12/09/2025

Share this job

**REMOTE**
Key Responsibilities:

* Identification and crafting of complex custom WAF rules & features to mitigate MVP and security posture gaps.
* Crafting efficacy testing for baseline & custom rules and features and integrating testing in the automation pipelines.
* Providing SME support for other security testing such as WAF PoCs, new features and solutions
* Providing WAF focused SME support and advice on Web & API based attack methodologies, evasions and mitigation techniques.
* Providing DevSecOps SME & pipeline build support for the automation works
* Monitor and review all tuning requests.
* Conduct detailed log analysis to identify false positives and optimize WAF rules for improved accuracy and performance.
* Create and maintain comprehensive documentation for WAF tuning, tuning procedures, policies, and configurations.
* Develop, test, and recommend WAF policies and rules tailored to specific applications and environments.
* Proactively assist with identifying false positives.
* Collaborate with cross-functional teams to ensure seamless integration of WAF solutions into existing security infrastructure.
* Provide recommendations for WAF configuration based on best practices and security requirements.
* Perform regular assessments and audits of WAF configurations to ensure optimal security posture and compliance with industry standards.
* Stay updated with the latest web security threats, vulnerabilities, and trends to continually enhance WAF effectiveness.

Key Accountabilities:

* Conduct detailed analyses and technical evaluations of various Web Application Firewall (WAF) solution rulesets and functionalities to confirm adherence to agreed baselines and to maximize detection of web, API, and other traffic-based security threats.
* Create custom rules and features where needed to augment WAF solutions to be able to meet the agree baseline.
* Identify and mitigate technical circumventions and evasions of WAF solutions.
* Develop and implement testing packages to assess the efficacy of various initiatives, including WAF Proofs of Concept, managed and custom rules, new features, and solutions.
* Facilitate the automation of efficacy testing procedures and their integration into Continuous Integration/Continuous Deployment (CI/CD) pipelines.
* Contribute to DevSecOps and pipeline construction project
* Ensuring timely and accurate review and action on all WAF tuning requests.
* Conducting thorough log analyses to effectively identify and mitigate false positives, ensuring optimized WAF rules.
* Maintaining comprehensive and up-to-date documentation for all WAF tuning procedures, policies, and configurations.
* Developing and recommending tailored WAF policies and rules for various applications and environments.
* Proactively identifying and addressing false positives to enhance overall WAF accuracy.
* Collaborating effectively with cross-functional teams to integrate WAF solutions seamlessly into existing security infrastructure.
* Providing expert recommendations for WAF configurations based on best practices and current security requirements.
* Performing regular assessments and audits of WAF configurations to maintain optimal security posture and compliance with industry standards.
* Staying informed about the latest web security threats, vulnerabilities, and trends to ensure continuous enhancement of WAF effectiveness.

Ideal Candidate Profile:

* Extensive experience in WAF management, tuning, and engineering, with a strong understanding of web application security principles.
* Proven track record of proactively identifying and mitigating false positives to optimize WAF performance.
* Background in SOC or CSIRT and AppSec or Ethical Hacking, demonstrating hands-on experience for the key responsibilities.
* Proficiency in log analysis tools and techniques, with the ability to identify patterns and anomalies in web traffic.
* Experience with tools such as Splunk, Wireshark, or custom scripts to process and analyze logs.
* Experience with at least three major WAF solutions (e.g., Akamai, F5, AWS, GCP) and an understanding of their unique configurations and capabilities.
* Strong analytical and problem-solving skills, with a keen attention to detail.
* Excellent communication skills, capable of articulating complex security concepts to technical and non-technical stakeholders.
* Ability to develop, test, and recommend WAF policies and rules tailored to specific applications and environments.
* Experience collaborating with cross-functional teams to integrate WAF solutions into existing security infrastructure.
* Competence in maintaining comprehensive documentation for WAF tuning procedures, policies, and configurations.
* Extensive experience in configuring WAF solutions to align with best practices and security requirements.
* A proactive, detail-oriented individual who thrives in a dynamic, fast-paced environment and stays updated with the latest web security threats and trends."


LA International is a HMG approved ICT Recruitment and Project Solutions Consultancy, operating globally from the largest single site in the UK as an IT Consultancy or as an Employment Business & Agency depending upon the precise nature of the work, for security cleared jobs or non-clearance vacancies, LA International welcome applications from all sections of the community and from people with diverse experience and backgrounds.

Award Winning LA International, winner of the Recruiter Awards for Excellence, Best IT Recruitment Company, Best Public Sector Recruitment Company and overall Gold Award winner, has now secured the most prestigious business award that any business can receive, The Queens Award for Enterprise: International Trade, for the second consecutive period.

Stoke-on-Trent, United Kingdom
100 - 249 employees
Recruitment agency
Whether you’re aiming for your next contract or permanent role, we connect you to opportunities across the digital and technology landscape in both public and private sectors. With eight specialist Divisions and a single-site team of highly experienced consultants, you get personalised support backed by deep sector expertise. Already security-cleared? Our in-house Security Vetting Department can transfer your clearance quickly and smoothly. New to cleared environments? Our Enhanced Government Security Accreditation allows us to sponsor new clearances, opening doors to career-defining roles. Operating across 90 countries and 5 continents, and supporting candidates for over 40 years, we don’t just help you find a job, we help you build a career.

Apply to this job!

Find your next job from +1,000 jobs!

  • Manage your visibility

    Salary, remote work... Define all the criteria that are important to you.

  • Get discovered

    Recruiters come directly to look for their future hires in our CV library.

  • Join a community

    Connect with like-minded tech and IT professionals on a daily basis through our forum.

Cyber_WAF & Application Security SME

LA International Computer Consultants Ltd

Connecting Tech-Talent

Free-Work, THE platform for all IT professionals.

Free-workers
Resources
About
Recruiters area
2025 © Free-Work / AGSI SAS
Follow us