F5 WAF Lead Engineer
REMOTE
6 months
We are seeking an experienced F5 WAF Lead Engineer to own and drive the transformation of enterprise web application firewall security moving from broad, generic rule sets to application-specific, tailored WAF policies across a large application portfolio. This is not a maintenance or administration role: the ideal candidate combines deep hands-on F5 WAF/XC expertise with the ability to set direction, define methodology, and build the automation and AI-assisted tooling needed to operate at scale. The engineer will work directly with client security leadership to define strategy and milestones, while remaining hands-on in building, tuning, and implementing policy.
Key Responsibilities
- Define and lead the strategy for transitioning from broad WAF rules to per-application, tailored security policies across a large application portfolio.
- Design and build an AI-assisted policy development workflow using scan output, traffic data, and application configuration to recommend and generate tailored WAF policies at scale.
- Evaluate, recommend, and implement F5 Distributed Cloud (XC) WAAP policies on an application-by-application basis.
- Integrate findings from vulnerability and penetration testing tools into the policy development process.
- Partner directly with client cybersecurity leadership to define deliverables, direction, and rollout milestones.
- Establish repeatable methodology and documentation so the practice can scale as volume grows and the team expands.
- Support and mentor additional team members as the engagement scales.
- Troubleshoot complex WAF policy, traffic, and security issues across cloud-hosted environments.
- Support incident response and root cause analysis for WAF/application security events.
- Coordinate change management and production deployment windows for policy rollouts. Required Qualifications
- 5+ years of experience in web application firewall engineering, with strong hands-on expertise in F5 Distributed Cloud (XC) WAAP.
- Demonstrated experience designing and implementing custom, per-application WAF policies (not just baseline/default rule sets).
- Experience conducting web application vulnerability assessment and remediation.
- Strong understanding of OWASP Top 10 and emerging web application threats.
- Experience leveraging AI/automation tooling to scale security operations (policy generation, evaluation, or triage).
- Ability to operate as both a strategic lead (defining direction, engaging client stakeholders) and a hands-on implementer.
- Experience with F5 Silverline and/or BIG-IP ASM/Advanced WAF (prior-generation context).
- Familiarity with cloud-hosted application architectures.
- Excellent communication skills able to present strategy and status to client security leadership. Preferred Qualifications
- Experience integrating SAST/SCA/DAST/pen-test tooling into WAF policy workflows.
- F5 Certified Technology Specialist (CTS) or equivalent.
- Experience with regulated environments (PCI, SOX, HIPAA).
- Knowledge of Zero Trust and API security frameworks.
- Familiarity with automation/scripting (Python, REST APIs, Terraform) for policy-as-code workflows.
- Prior experience leading or scaling a security engineering practice/team.
Technical Skills
F5 Technologies: F5 Distributed Cloud (XC) WAAP, F5 Silverline, BIG-IP ASM/Advanced WAF (legacy context)
Security: Web Application Firewall (WAF) policy design, OWASP Top 10, AI-assisted security tooling, application security, API security, vulnerability assessment, threat mitigation
Thanks,
Vinod.