
Web Application Firewall Engineer, Cloud Security
Overview
You will own the deployment, tuning, and support of web application firewall controls across AWS and on-premise environments, protecting Ally's critical web assets at enterprise scale. You will join a team of security engineers within the Cyber Security Technology group, collaborating to sustain and monitor technical controls. This role sits in the Information Protection & Risk Management organization, giving you direct exposure to high-impact security initiatives. You will drive continuous improvement in WAF coverage and response, shaping how Ally defends against application-layer threats.
What You'll Do7
- 1Deploy and configure AWS WAF, CloudFront, and related services to protect production web applications.
- 2Tune WAF rules and policies to reduce false positives while blocking exploit attempts like SQL injection and XSS.
- 3Monitor WAF logs and metrics, analyzing traffic patterns to identify anomalies and attack campaigns.
- 4Collaborate with development teams to onboard new applications and integrate WAF into CI/CD pipelines.
- 5Lead incident response for web application attacks, including rule updates and mitigation strategies.
- 6Automate WAF rule management using Terraform, Python, and AWS CLI to streamline operations.
- 7Document security policies, runbooks, and architectural decisions for WAF infrastructure.
Requirements7
- 13+ years hands-on experience with AWS WAF, CloudFront, and ALB or API Gateway.
- 22+ years in a security engineering role focused on web application firewalls or network security.
- 3Strong understanding of OWASP Top 10 and common web attack vectors like SQLi, XSS, and CSRF.
- 4Experience with Terraform or CloudFormation for infrastructure as code.
- 5Proficiency in Python or Bash for automation and log analysis.
- 6Familiarity with SIEM tools and log aggregation platforms (e.g., Splunk).
- 7Relevant certifications such as AWS Solutions Architect – Associate or CEH are a plus.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Innova Solutions, Inc
VerifiedWeb Application Security Engineer, WAF & Bot Mitigation
You will own layer 7 web security controls for a global enterprise, configuring WAF, rate limiting, bot mitigation, and mTLS across internet-facing applications. You will work with a security engineering team to ensure secure operations, collaborating with developers and DevOps to integrate security into the CI/CD pipeline. This contract role offers hybrid work in Charlotte, Chandler, or Las Colinas and the chance to shape security posture for high-traffic web platforms.

TECHNEPTUNE CONSULTING INC
VerifiedAkamai WAF Security Engineer, Web Application Firewall
You will lead enterprise application onboarding and migration to Akamai WAF, managing and optimizing WAF policies across a large-scale environment. You will support AI/LLM and API security initiatives, working with cross-functional teams to enhance web application security. This role centers on hands-on technical ownership of security infrastructure, with direct impact on reducing risk and improving response times.
BaseCamp Consulting & Solutions
VerifiedWeb Developer Security Engineer
Lead security initiatives for web applications and APIs ensuring robust protection against threats. Own the vulnerability lifecycle from identification to remediation while driving automation for threat intelligence integration and incident response. Ensure compliance with NIST 800-53 FISMA FedRAMP standards. Collaborate with cross-functional teams to implement secure design patterns and maintain high security posture across SDLC.

QUANTUM TECHNOLOGIES LLC
VerifiedAWS Cloud Engineer, Application Security
You will own security for applications built and operated on AWS, embedding security across the entire SDLC from design to incident response. You will work with development teams to enforce secure coding and automate security checks in CI/CD pipelines. You will also manage runtime protection and respond to security incidents, collaborating with engineering and operations. This contract role in Dallas, TX offers 6+ months of work with potential extension, focusing on application security in a dynamic cloud environment.
AssetMark Financial Holdings, Inc.
VerifiedSecurity Engineer II - Cloud & IAM | AssetMark
You will own security operations for AssetMark's hybrid cloud environment, protecting AWS and Azure workloads and IAM infrastructure. You will work alongside engineering teams to embed security into the software development lifecycle, integrating CrowdStrike Falcon, Check Point Harmony, and Microsoft Defender. Your role focuses on incident response, vulnerability management, and threat modeling for key products. This position stands out for its hybrid schedule and direct impact on securing a leading advisor platform.

AI ASAP LLC
VerifiedAkamai with AI Engineer
Own secure internet-facing applications using Akamai WAF and lead migration efforts. Collaborate with cross-functional teams to transition workloads into monitoring alert and deny modes. Deliver results within a fast-paced environment.