CybersecurityJobs.io
← Back to all jobs

Job Description

Support enterprise application security in a hybrid role based in Reston, VA, focusing on WAF administration, container image security scanning, and SDLC/CI-CD security controls.

Responsibilities

  • Administer and enhance enterprise BIG-IP WAF capabilities, including building security policies, tuning rules, investigating false positives, troubleshooting application traffic issues, and maintaining web application protections
  • Design, implement, and operate application security controls across enterprise applications and supporting platforms
  • Perform container image security scanning and analyze vulnerabilities found in application and container images
  • Assess severity and business risk for container vulnerabilities and collaborate directly with development teams to prioritize and remediate findings
  • Partner with Development and DevOps teams to embed security controls into the SDLC and CI/CD pipelines
  • Design and operate web application and API security protections, including policy configuration, rule tuning, automation, and continuous improvement
  • Identify application security vulnerabilities, complete risk assessments, and recommend practical mitigation and remediation strategies
  • Develop and maintain application security policies, standards, procedures, and controls
  • Build and maintain security monitoring and telemetry for the application stack to improve proactive detection
  • Conduct technical investigations tied to application security incidents and vulnerabilities
  • Support container security activities, including image scanning, vulnerability risk assessments, and runtime security/hardening
  • Operate and support security technologies across cloud and/or on-premises environments
  • Troubleshoot security, application, and network-related issues and communicate findings and recommended actions clearly
  • Partner with senior IT stakeholders to interpret application security risks, priorities, and remediation needs

Requirements

  • 6–8 years of Application Security experience designing, implementing, and operating security controls in enterprise application environments
  • Hands-on BIG-IP WAF administration, including building WAF policies, configuring protections, tuning rules/policies, troubleshooting in production, reducing false positives, and maintaining WAF controls
  • Hands-on container image security/scanning, including reviewing scan results, evaluating vulnerabilities, determining risk and remediation priorities, and working directly with development teams
  • Experience with a container security/scanning platform (tool not critical). Relevant examples include Prisma Cloud, Wiz, Snyk, or comparable technologies
  • Strong web application security knowledge, including OWASP Top 10 vulnerabilities and practical application of security controls
  • Experience conducting web application security scans, vulnerability assessments, and/or penetration testing
  • Experience partnering directly with Development and DevOps teams to integrate security into the SDLC and CI/CD pipelines
  • Experience with authentication and authorization technologies such as OAuth and OpenID
  • Strong troubleshooting and communication skills, able to explain security risks and remediation requirements to both technical teams and senior IT stakeholders
  • Bachelor’s degree in Information Security, Computer Science, Computer/Electrical Engineering, or a related discipline, and/or equivalent relevant professional experience
  • Demonstrated production experience administering BIG-IP WAF, including building and tuning WAF policies
  • Demonstrated hands-on experience with container image scanning and vulnerability management
  • Experience personally reviewing container vulnerabilities and collaborating with developers on remediation
  • Experience integrating security practices and controls into CI/CD and secure software development processes
  • Experience operating cloud-based and/or on-premises security platforms
  • Ability to investigate and troubleshoot security and network-related issues using established security methodologies and best practices
  • Strong communicator who can work effectively with developers, DevOps engineers, operations teams, and senior IT stakeholders
  • Collaborative and approachable, able to influence remediation and security improvements while maintaining cross-functional relationships
  • Proof of eligibility to work in the United States

Technologies

  • BIG-IP WAF
  • OWASP Top 10
  • OAuth
  • OpenID
  • Prisma Cloud
  • Wiz
  • Snyk
  • CI/CD
  • SDLC

Benefits

  • 150-180K base salary + 7% Bonus

Location

  • Hybrid in Reston, VA 20190
  • 3 days on-site per week (Tues/Wed)

Similar Jobs