
Application Security Engineer
Posted Aug 7

Posted Aug 7
This is a fully remote position, open to applicants in United States.
• Deploy, configure, and sustain web application firewall systems.
• Set up and configure Zero Trust Proxy systems, which include identity gates, policies, and connectors.
• Monitor and assess security events, alerts, and logs.
• Investigate and respond to potential security incidents in collaboration with the SOC and cybersecurity teams.
• Develop and maintain detection rules, alerts, and reports utilizing logs.
• Provide investigation results to business units.
• Integrate web application firewalls with CDNs such as Akamai and Radware.
• Leverage WAF data to identify vulnerabilities and suggest remediation strategies.
• Maintain documentation for WAF configurations, policies, and procedures.
• Prepare web application security reports and metrics.
• Communicate security details to application and engineering teams.
• Collaborate with cross-functional teams to achieve security objectives and facilitate knowledge sharing.
• Advise application teams on application security best practices and promote security awareness.
• Implement automation processes using Python, Terraform, AI, and cloud-native concepts across AWS, Azure, and Google Cloud.
• 4+ years of professional experience, including at least 2 years in network security and 2 years in application security.
• Deep understanding of web application security concepts and OWASP Top 10 vulnerabilities.
• Familiarity with OAuth, SAML, and OIDC authentication and authorization flows.
• Experience with WAF, Zero Trust Network Access, APIs, and cloud security policies.
• Knowledge of API security concerns and API authentication.
• Prior experience with SOC operations, cybersecurity analysis, log analysis, and threat detection is highly preferred.
• Knowledge of information security principles and enforcement of policies.
• Strong grasp of HTTP and troubleshooting using HTTP logs.
• Background in web development and awareness of attack vectors and methodologies.
• Familiarity with authentication, DNS, networks, firewalls, and SSL certificates.
• Experience with WAF technologies, especially Akamai.
• Understanding of Zero Trust frameworks and technologies.
• Experience in integrating Zero Trust with WAF.
• Familiarity with AWS, Azure, and GCP cloud security services and best practices.
• Proficient in infrastructure as code with Terraform and automation through Python.
• Ethical hacking experience.
• Experience with ServiceNow.
• Technical documentation experience.
• Security certifications such as CISSP, CISM, CISA, GIAC, or others are preferred.
• Comfortable using AI tools.
• A Bachelor's Degree or equivalent in Information Security, Information Technology, Computer Science, Engineering, or related field.
• Exceptional written and verbal communication and presentation skills.
• Strong critical thinking, problem-solving, and technical troubleshooting skills.
• Ability to thrive in a dynamic, evolving environment.
• Capability to manage multiple tasks and meet tight deadlines.
• Excellent analytical skills with strong attention to detail and accuracy.
• Experience working in complex, fast-paced technology or information security settings within large enterprises.
• Bilingual abilities are an advantage.
• Approximately 8 Month Contract (with potential extensions).
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.