Role: - Network Security Engineer F5/WAF
Location:- Dallas TX (Hybrid 2 days WFO)
Duration:- 6 months extendable contract
Shift Timing:- 10 am 8 pm CST (Thu Sun)
We are looking for an experienced Network Security Engineer with strong hands-on experience in Web Application Firewall (WAF) technologies to join the network security team in Dallas, TX.
The ideal candidate will have strong expertise in F5 BIG-IP WAF/ASM or Imperva WAF, along with a solid understanding of network security, application security, load balancing, HTTP/HTTPS, SSL/TLS, DNS, TCP/IP and enterprise network architecture. This role will be responsible for implementing, managing, troubleshooting, tuning and maintaining WAF and network security technologies supporting business-critical applications.
Must-Have Skills
- Hands-on experience with Web Application Firewall (WAF)
- Strong experience with F5 BIG-IP WAF/ASM/Advanced WAF OR Imperva WAF
- Experience creating, configuring and tuning WAF security policies
- Strong understanding of OWASP Top 10 and common web/application attacks
- Hands-on experience with F5 BIG-IP LTM is highly preferred
- Strong understanding of HTTP/HTTPS, TCP/IP, DNS and SSL/TLS
- Experience with load balancing, reverse proxy and application traffic flows
- Experience troubleshooting production WAF/network security issues
- Experience analyzing WAF logs, security events and false positives
- Ability to work with application, network, infrastructure and security teams
Key Responsibilities
- Design, implement, configure and maintain enterprise WAF solutions.
- Administer and support F5 BIG-IP WAF/ASM/Advanced WAF or Imperva WAF environments.
- Develop and maintain WAF security policies for enterprise applications.
- Perform WAF policy tuning, signature management, exception handling and false-positive analysis.
- Monitor WAF events and investigate suspicious or malicious application traffic.
- Protect applications against OWASP Top 10, API attacks, SQL injection, cross-site scripting and other application-layer threats.
- Support application onboarding and migration onto WAF platforms.
- Configure and troubleshoot F5 BIG-IP components including Virtual Servers, Pools, Nodes, Profiles, Health Monitors and SNAT.
- Troubleshoot HTTP/HTTPS, SSL/TLS, DNS and application connectivity issues.
- Analyze network traffic using packet captures and tools such as Wireshark/tcpdump.
- Participate in incident, problem and change management activities.
- Perform WAF/F5 software upgrades, patches, configuration changes and health checks.
- Work with application teams to identify and resolve WAF-related application issues.
- Collaborate with SOC, Network Engineering, Infrastructure and Application teams during security incidents.
- Work with vendors/OEM support for complex technical issues and escalations.
- Maintain technical documentation, SOPs, configuration standards and operational procedures.
- Participate in production support and on-call activities as required.
Required Technical Skills
WAF / Application Security
- F5 BIG-IP ASM / Advanced WAF
- OR Imperva WAF
- WAF policy creation and tuning
- WAF signatures and exceptions
- OWASP Top 10
- Application security
- API security
Networking
- TCP/IP
- HTTP/HTTPS
- DNS
- SSL/TLS
- Routing and switching fundamentals
- Load balancing
- Reverse proxy
- NAT/SNAT
F5 Technologies Preferred
- F5 BIG-IP LTM
- Virtual Servers
- Pools & Nodes
- iRules
- Health Monitors
- SSL Profiles
- HTTP Profiles
- Persistence
- High Availability / Device Service Clustering
- Configuration synchronization
Troubleshooting & Security
- Wireshark
- tcpdump
- WAF/security event analysis
- Vulnerability remediation
- Incident and problem management
- Root Cause Analysis
Preferred Skills
- Experience with Palo Alto, Fortinet or Cisco firewalls
- Experience with DDoS protection
- Experience with CDN technologies such as Cloudflare or Akamai
- Experience with AWS/Azure/Google Cloud Platform networking or cloud security
- Experience with SIEM tools such as Splunk, QRadar or Microsoft Sentinel
- Python, Bash or PowerShell scripting
- F5 REST API / automation
- Ansible or Terraform
- Experience in large-scale enterprise environments
Education & Certifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or related field, or equivalent experience.
- F5 Certified BIG-IP Administrator / F5 Certified Technology Specialist is a plus.
- CCNA/CCNP Security, PCNSE, CISSP or other relevant security certifications are a plus.
Experience
- 5+ years of experience in Network Security, Application Security or Network Engineering.
- 3+ years of hands-on experience working with WAF technologies.
- Strong hands-on experience with F5 WAF/ASM or Imperva WAF is mandatory.
- Experience supporting enterprise production environments.
- Strong troubleshooting and communication skills.
Ideal Candidate Profile
The ideal candidate is a hands-on Network Security Engineer who has worked extensively with F5 WAF/ASM or Imperva WAF, understands application traffic and network security, and can independently troubleshoot WAF, SSL/TLS, HTTP/HTTPS and load-balancing issues in a large enterprise environment.