
Web Application Security Engineer, WAF & Bot Mitigation
Overview
You will own layer 7 web security controls for a global enterprise, configuring WAF, rate limiting, bot mitigation, and mTLS across internet-facing applications. You will work with a security engineering team to ensure secure operations, collaborating with developers and DevOps to integrate security into the CI/CD pipeline. This contract role offers hybrid work in Charlotte, Chandler, or Las Colinas and the chance to shape security posture for high-traffic web platforms.
What You'll Do7
- 1Configure WAF rules to block malicious traffic and enforce application-specific policies.
- 2Implement rate limiting and bot mitigation strategies to protect APIs and web endpoints.
- 3Manage client lists, geolocation blocking, and mTLS authentication for critical services.
- 4Maintain and renew SSL certificates for internet-facing applications.
- 5Monitor security logs and respond to incidents by tuning WAF and bot rules.
- 6Collaborate with development teams to fix vulnerabilities and harden web applications.
- 7Document security configurations and runbooks for operational handoff.
Requirements7
- 13+ years in web application security engineering, with focus on WAF and bot mitigation.
- 2Hands-on experience with AWS WAF, Cloudflare, or Akamai.
- 3Proficiency in TLS/SSL certificates, mTLS, and HTTP/HTTPS protocols.
- 4Knowledge of OWASP Top 10 and common web vulnerabilities.
- 5Experience with API security and rate limiting in production environments.
- 6Strong scripting skills in Python or Bash for automation.
- 7CISSP or AWS Certified Security preferred.
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Exl Neo Technologies
VerifiedWeb Application Firewall Engineer, Cloud Security
You will own the deployment, tuning, and support of web application firewall controls across AWS and on-premise environments, protecting Ally's critical web assets at enterprise scale. You will join a team of security engineers within the Cyber Security Technology group, collaborating to sustain and monitor technical controls. This role sits in the Information Protection & Risk Management organization, giving you direct exposure to high-impact security initiatives. You will drive continuous improvement in WAF coverage and response, shaping how Ally defends against application-layer threats.

TECHNEPTUNE CONSULTING INC
VerifiedAkamai WAF Security Engineer, Web Application Firewall
You will lead enterprise application onboarding and migration to Akamai WAF, managing and optimizing WAF policies across a large-scale environment. You will support AI/LLM and API security initiatives, working with cross-functional teams to enhance web application security. This role centers on hands-on technical ownership of security infrastructure, with direct impact on reducing risk and improving response times.
BaseCamp Consulting & Solutions
VerifiedWeb Developer Security Engineer
Lead security initiatives for web applications and APIs ensuring robust protection against threats. Own the vulnerability lifecycle from identification to remediation while driving automation for threat intelligence integration and incident response. Ensure compliance with NIST 800-53 FISMA FedRAMP standards. Collaborate with cross-functional teams to implement secure design patterns and maintain high security posture across SDLC.

QUANTUM TECHNOLOGIES LLC
VerifiedAWS Cloud Engineer, Application Security
You will own security for applications built and operated on AWS, embedding security across the entire SDLC from design to incident response. You will work with development teams to enforce secure coding and automate security checks in CI/CD pipelines. You will also manage runtime protection and respond to security incidents, collaborating with engineering and operations. This contract role in Dallas, TX offers 6+ months of work with potential extension, focusing on application security in a dynamic cloud environment.

Motion Recruitment Partners, LLC
VerifiedPrincipal Application Security Engineer
You will own application security for a major financial services firm with over 150 years of market presence, hardening Java and .NET applications across a global portfolio. You will lead security reviews, threat modeling, and code analysis while partnering with DevOps to embed security into CI/CD pipelines. This hybrid role in Charlotte, NC offers direct impact on high-velocity releases and access to cutting-edge cloud infrastructure.
Bright Vision Technologies
VerifiedApplication Security Engineer Bright Vision Technologies
Lead security integration across software development lifecycles for a remote full-time role at Bright Vision Technologies. Own security practices while collaborating with engineering teams to build resilient applications. Drive measurable risk reduction through proactive threat mitigation and secure coding standards.