Ernst & Young

Cyber SDC - Web Application Firewall (WAF) Operations Solution Engineer- Senior- Location Open

Ernst & Young$104K — $192K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, IT, Cybersecurity, or related field preferred.
  • 3-5 years of experience focused on WAF management in web application security operations.
  • Hands-on experience with WAF solutions, specifically Cloudflare and Imperva, is required.
  • Proficiency in Terraform for infrastructure automation is preferred.
  • Strong understanding of web application protocols, security principles, and best practices.
  • Familiarity with ITIL processes and incident management ticketing systems is beneficial.
  • Relevant certifications like CISSP or Security+ are desirable.

Responsibilities

  • Configure, manage, and optimize WAF solutions for web applications.
  • Provide ongoing operational coverage of web application firewalls to ensure efficiency.
  • Monitor application traffic and security events to identify potential threats and vulnerabilities.
  • Conduct root cause analysis and remediation for security incidents.
  • Collaborate with incident response teams to address security incidents promptly.
  • Develop and maintain WAF policies, rules, and documentation adhering to best practices.
  • Stay updated on emerging threats and security technologies to improve security posture.

Benefits

  • Access to continuous training and mentorship for career growth in cybersecurity.
  • Flexible working environment with a hybrid model.
  • Comprehensive compensation and benefits package, including health coverage and retirement plans.
  • Flexible vacation policy tailored to individual needs and well-being.
  • Paid time off for designated holidays, breaks, and personal circumstances.
Full Job Description
Location: Anywhere in Country

As a WAF Operations Solution Engineer, you will be responsible for implementing and managing Web Application Firewall (WAF) solutions to protect client applications from cyber threats. You will work within a team of cybersecurity professionals to establish effective security measures that safeguard web applications and data.

JOB SUMMARY:

In the role of WAF Operations Solution Engineer, you will configure and provide ongoing operational coverage of web application firewalls to maintain optimal performance and security for client applications. The primary purpose of this role is to assist with change requests and support problem resolution to uphold the integrity of web applications. You will actively monitor application traffic, analyze security events, and respond to incidents to mitigate risks effectively. Additionally, you will collaborate with cross-functional teams to enhance the overall security posture of web applications, leveraging your experience with various WAF solutions to implement and automate security measures.

KEY RESPONSIBILITIES:
  • Configure, manage, and optimize WAF solutions to establish effective security controls for web applications.
  • Provide ongoing operational coverage of web application firewalls, ensuring they function correctly and efficiently.
  • Monitor application traffic and security events to identify potential threats and vulnerabilities.
  • Conduct thorough analysis of security incidents, including root cause analysis and remediation efforts.
  • Collaborate with incident response teams to investigate and respond to security incidents in a timely manner.
  • Develop and maintain WAF policies, rules, and documentation to align with best practices and compliance requirements.
  • Provide support for security audits and assessments, promoting adherence to security standards and policies.
  • Stay current with emerging threats, vulnerabilities, and security technologies to enhance the organization's security posture.
  • Utilize various WAF solutions, including Cloudflare and Imperva, for implementation and management, ensuring optimal configuration and performance.
  • Leverage Terraform for infrastructure as code (IaC) to automate the deployment and management of WAF solutions.
  • Mentor junior engineers and provide guidance on WAF management and incident response processes.


QUALIFICATIONS:
  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or a related field preferred.
  • 3-5 years of experience in web application security operations, with a focus on WAF management.
  • Hands-on experience with WAF solutions such as Cloudflare and Imperva is required.
  • Proficiency in using Terraform for infrastructure automation is preferred.
  • Strong understanding of web application protocols, security principles, and best practices.
  • Familiarity with ITIL processes and ticketing systems for incident management.
  • Relevant certifications (e.g., CISSP, Security+) are a plus.
  • Excellent analytical, problem-solving, and communication skills.
  • Ability to work independently and collaboratively in a fast-paced environment.


WHAT WE OFFER:

At EY, we are committed to your professional development and career growth. You will have access to continuous training and mentorship, enabling you to enhance your skills and advance your career in cybersecurity. Join us in building a more secure and trusted working world.

What we offer you
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more.
  • We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $104,800 to $192,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $125,800 to $218,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Are you ready to shape your future with confidence? Apply today.

EY accepts applications for this position on an on-going basis.

For those living in California, please click here for additional information.

EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.

About Ernst & Young

Ernst & Young (EY) is a multinational professional services firm that provides audit, tax, consulting, and advisory services to clients in a wide range of industries. The firm was founded in 1989 through the merger of Ernst & Whinney and Arthur Young & Co., and has since grown to become one of the largest professional services firms in the world. EY is committed to building a better working world by helping its clients solve their toughest challenges, and by creating a positive impact on the communities it serves.
Learn more about Ernst & Young
Size
300,000 employees
Industry
Founded
1989

Similar Jobs

More Jobs at Ernst & Young

More Information Technology Jobs

Find similar Cyber SDC - Web Application Firewall (WAF) Operations Solution Engineer- Senior- Location Open jobs: