Senior WAF Security Specialist
Create and validate production WAF rules for high-impact vulnerabilities and customer findings. Use an AI-assisted workflow, identify bypasses and false positives, and improve the evaluation systems that make generated rules safer and more effective.
תחומי אחריות
- Create production WAF rules for high-impact CVEs and customer findings
- Use an AI harness to generate, assess, refine, and validate WAF rules
- Write custom expressions for vulnerabilities without public proof-of-concept exploits
- Optimize rules for capacity, latency, expression limits, and shared Web ACL traffic
- Build exploit variants, test bypasses, and verify false-positive behavior
- Monitor deployed rules for hit patterns, coverage drift, and false-positive signals
- Maintain regression tests, golden CVE datasets, and scoring rubrics for Copilot releases
- Determine which vulnerabilities are suitable for WAF mitigation and manage ruleset coverage
- Provide feedback and evaluations that improve the security AI agent
דרישות
- Deep hands-on experience writing, tuning, and operating WAF rules across multiple major providers
- Strong application security, vulnerability research, or offensive security background
- Ability to analyze advisories, build proof-of-concept exploits, and derive attack variants
- Knowledge of WAF normalization, encoding evasion, parameter pollution, body-size limits, rule precedence, and provider-specific expression constraints
- Understanding of false-positive risks and production traffic behavior
- Programming ability in Python or a similar language for automation and data analysis
יתרון
- Experience with virtual patching or vulnerability mitigation
- Experience on a WAF vendor rules or research team
- Hands-on experience with LLMs and agentic tooling