Overview
Skills
Job Details
Job Summary:
We are seeking a skilled Web Application Security Engineer with hands-on expertise in Akamai security solutions to join our cybersecurity team. You will be responsible for securing our web applications and APIs using Akamai's platform and implementing best practices in web application security, threat detection, and mitigation.
Key Responsibilities:
Design, implement, and manage Akamai Web Application Firewall (WAF), Bot Manager, and Edge DNS solutions.
Monitor and analyze real-time traffic patterns, security alerts, and logs to detect threats and anomalies.
Collaborate with development and DevOps teams to ensure secure application deployment pipelines.
Create and maintain custom WAF rules, bot control policies, and rate-limiting strategies.
Respond to and investigate security incidents affecting web applications and services.
Participate in vulnerability assessments, penetration testing, and security reviews.
Ensure compliance with industry standards (OWASP Top 10, PCI-DSS, GDPR, etc.)
Generate and maintain security documentation, runbooks, and reporting dashboards.
Act as SME (Subject Matter Expert) for Akamai tools and train internal stakeholders.
Required Skills & Qualifications:
Bachelor's degree in Computer Science, Cybersecurity, or related field
3 5+ years of experience in Web Application Security, Cloud Security, or DevSecOps
Strong hands-on experience with Akamai platform components:
Web Application Firewall (WAF)
Bot Manager
Kona Site Defender
Edge DNS / Fast DNS
Akamai Control Center & APIs
Solid understanding of:
HTTP/S, TLS, DNS, CDNs, and Web proxies
OWASP Top 10, CVE/CWE, web application attack vectors
Security event management tools (e.g., Splunk, ELK)
Familiarity with scripting (Python, Bash) and automation tools (e.g., Terraform, Ansible) is a plus
Experience working in Agile/DevOps environments
Preferred Qualifications:
Akamai certifications (e.g., Akamai Certified Security Architect)
Experience with cloud platforms (AWS, Azure, Google Cloud Platform)
Knowledge of Zero Trust architecture
Previous experience in incident response or SOC operations