Vsolutions Technologies is seeking an Azure Web Application Firewall (WAF) & Cyber Security Tools Engineer to support their Technical Security Solutions Operations. This role involves managing and optimizing web application security firewalls and associated security tools, with a focus on administering WAF solutions and supporting enterprise security controls.
Responsibilities:
- Administer and maintain Azure Front Door WAF and Azure Application Gateway WAF policies, rulesets, exclusions, and custom signatures to protect web applications against OWASP Top 10 and emerging threats
- Build and maintain Terraform modules for Azure Front Door and Application Gateway WAF resources, ensuring version-controlled deployments
- Operate CI/CD pipelines for GitHub-based deployments, including branching strategies, environment promotion, and rollback procedures
- Provide operational support for additional security tools, including Proofpoint, Digital Guardian, Windows Certificate Services, Silverfort, Calico, F5 ASM, Rapid7 Nexpose, and Qualys
- Assist in troubleshooting, performance tuning, and implementing updates or enhancements across supported platforms
Requirements:
- Hands-on administration of Azure Front Door WAF and Azure Application Gateway WAF (policy authoring, tuning, exclusions, custom rules)
- Terraform expertise for Azure resources and GitHub deployments
- Proven ability to use code to configure Azure firewalls/WAFs
- Scripting skills to automate configuration, validations, and operational tasks (PowerShell, Bash, or Python)
- Strong understanding of web application security (OWASP Top 10, bot protection, API protection, TLS, header-based controls) and secure DevOps practices
- 5+ years in application security, cloud security, or network security engineering roles
- Demonstrated success operating Azure WAF (Azure Front Door and/or Application Gateway)
- Experience with F5 ASM Web application Firewall and ASM policy tuning
- Exposure to Calico, Proofpoint email security, Netskope, Digital Guardian, Silverfort, and vulnerability management tools