×
Register Here to Apply for Jobs or Post Jobs. X

WAF Security Engineer

Job in Nottingham, Nottinghamshire, NG1, England, UK
Listing for: Lloyds Bank plc
Full Time position
Listed on 2026-09-05
Job specializations:
  • IT/Tech
    Systems Engineer, Cybersecurity, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 48987 - 55000 GBP Yearly GBP 48987.00 55000.00 YEAR
Job Description & How to Apply Below

End Date Thursday 01 October 2026 Salary Range £48,987 - £54,430 We support flexible working –  for more information on flexible working options Flexible Working Options Hybrid Working, Job Share

Job Description Summary .

Job Description

JOB TITLE:

WAF Security Engineer SALARY: £48,987 - £55,000 per annum

LOCATION:

Manchester, Leeds, Edinburgh

HOURS:

Full-time – 35 hours WORKING PATTERN:
Our work style is hybrid, which involves spending at least two days per week, or 40% of our time, at one of our office sites. Colleagues with disabilities can be supported with workplace adjustments including hybrid working expectations in line with our Flexibility Works policy.

What you’ll be doing… You’ll be a key engineer responsible for designing, implementing, evolving and maintaining our Web Application Firewall (WAF) platforms, protecting critical customer-facing services ’ll use modern engineering practices, including automation and secure-by-default design, to improve the resilience, performance and security of our edge, data centre and cloud environments. The role offers real scope to influence technical direction, raise engineering standards, and develop our WAF and wider Layer 7 security services.

Day to day, you’ll work with a high degree of autonomy and contribute technical influence across the team.

Your responsibilities will include:
  • Design, implement and continuously optimise WAF security controls, developing and tuning rules and policies to improve protection against emerging threats while minimising false positives and maintaining a seamless customer experience.
  • Engineer new WAF capabilities using Infrastructure as Code, CI/CD pipelines and policy-as-code approaches to deliver secure, repeatable and scalable outcomes.
  • Playing a key role in platform modernisation and service improvements, including refactoring, automation and the reduction of technical debt Driving observability and operational insight by improving monitoring, alerting and telemetry to strengthen platform reliability and incident response
  • Support the diagnosis and resolution of major incidents, partnering closely with Security Engineering, Network and Cloud teams.
  • Embed secure-by-design patterns and guardrails, ensuring controls are codified, consistent and easy for platform consumers to adopt.
  • Produce high-quality engineering documentation, including standards, patterns, platform guidance and runbooks, to enable self-service and repeatable delivery.
  • Participate in the on-call rota, helping to maintain the operational resilience of critical services, with additional compensation provided.
Why Join us?

If you think all banks are the same, you’re wrong. We’re a pioneering, fast-changing business that’s shaping finance as a force for good. If you’re after a role where you can have an impact and do the best work of your career, you’ve just found it In this role, you’ll have the chance to:
Shape the future of WAF and Web Application Security capabilities across Lloyds Banking Group. Contribute to engineering standards, patterns and guardrails used across multiple teams and platforms. Work alongside highly skilled engineers in a culture that values modern engineering, automation and continuous improvement. Continue to develop your knowledge in Layer 7 controls and modern engineering practices.

What we’re looking for?

A strong engineering mindset, with hands‑on experience of edge, on‑premises or cloud‑native WAF technologies. Solid understanding of networking and web fundamentals, including HTTP/S, DNS, TLS and platform security concepts. Experience in any of the following:
Application Security, API Security, Bot Protection, and Layer 7 DDoS mitigation. Strong automation and scripting skills (Python preferred), with practical experience using Infrastructure‑as‑Code tools (Terraform preferred) and modern CI/CD pipelines. Ability to contribute to complex technical investigations, diagnose issues under pressure and develop robust solutions. Confidence to influence engineering decisions and contribute to the team’s technical direction. And any experience of these would be great… Professional‑level cloud certifications and/or recognised security or…

Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary