×
Register Here to Apply for Jobs or Post Jobs. X

WAF Engineering Lead

Job in New York, New York County, New York, 10261, USA
Listing for: Willis Towers Watson
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 120000 - 160000 USD Yearly USD 120000.00 160000.00 YEAR
Job Description & How to Apply Below

Description

The WAF Engineering Leadrole is intended to maximise the operational performance of WTW service sand maintain a strong secure posture. The role is accountable for BAU support of issues, controlling policy & compliance and supporting change activities. This role ensures the technical success of WAF services within the WTW environment in a Tier 3 capacity and management of direct reports.

The Role

  • Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining an appropriate security posture.
  • Design, implement, maintain and optimise WAF policies across multi-cloud environments.
  • Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.
  • Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.
  • Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement.
  • Analyse attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.
  • Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications.
  • Provide subject matter expertise for web application security, secure application delivery and WAF best practices.
  • Provide technical leadership to Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.
  • Provide leadership during major incidents and drive to quick resolutions.
  • Provide line management for direct reports
  • Point of escalation for areas of accountability
  • Coach team members on a proactive basis, raising the team’s overall technical acumen.
  • Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.
  • Participate on the Technical Design Authority forum
  • Implement changes/POCs to the environment in a controlled manner, with implementation and test plans.
Qualifications

The Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Technology strongly preferred, or relevant industry experience in related field.
  • Minimum 5 years’ leadership experience (direct reports) in similar role
  • Minimum 5 years’ experience in IT or Telecoms industry. Financial Services experience preferred.
  • Minimum 5 years’ Azure WAF/Network management experience
  • Minimum 5 years’ Network Security experience. Azure Firewall, Palo Alto Firewall/VPN, Cisco would be advantageous.
  • Demonstrable experience investigating, analysing and resolving WAF false positives and false negatives.
  • Strong experience implementing WAF solutions in Detection mode and transitioning policies to Prevention/Block mode through appropriate tuning and validation.
  • Proven experience developing and maintaining custom WAF rules, rule exclusions, rate limiting controls and attack mitigation policies, rather than solely relying on out-of-the-box managed rules.
  • Extensive knowledge of web application attack vectors, including OWASP Top 10 vulnerabilities, SQL Injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), bot attacks, credential stuffing and API abuse.
  • Hands-on experience with attack mitigation, threat analysis and creation of bespoke security controls based on observed attack patterns.
  • Strong understanding of bot protection technologies, managed rule sets, policy tuning and wider web application security best practices.
  • Experience with Azure Front Door WAF and Azure Application Gateway WAF in enterprise-scale environments.
  • Experience working…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary