L3 Security Engineer – WAF DDOS
Job Summary
We are seeking an experienced L3 Security Engineer with hands-on expertise in F5 Web Application Firewall (WAF) solutions. The candidate will be responsible for monitoring, administration, troubleshooting, policy support, and operational maintenance of enterprise web application security infrastructure.
Key Responsibilities
· Manage and support F5 WAF infrastructure and web application security solutions.
· Monitor WAF alerts, web traffic, and security events.
· Configure and maintain WAF security policies, signatures, and profiles.
· Support onboarding of web applications into the WAF environment.
· Perform policy tuning and optimization to reduce false positives.
· Analyze suspicious web traffic and investigate security incidents.
· Support SSL certificate installation and management.
· Generate operational, security, and compliance reports.
Security Operations
· Monitor web application security incidents and suspicious activities.
· Support SOC and Incident Response teams during investigations.
· Perform log analysis and event correlation.
· Escalate critical security incidents to L3/security teams.
· Ensure WAF policies align with organizational security standards.
Platform Support & Troubleshooting
· Troubleshoot WAF policy, connectivity, and application access issues.
· Support installation, patching, upgrades, and maintenance activities.
· Monitor F5 device health, storage, and performance.
· Coordinate with application, server, and network teams for issue resolution.
· Perform backup and restoration support activities.
Compliance & Governance
· Support compliance requirements related to web application security.
· Maintain audit logs and WAF monitoring reports.
· Support audits related to ISO 27001, PCI-DSS, and internal security controls.
· Ensure proper documentation and evidence collection for audit requirements.
Required Skills
· Hands-on experience with F5 WAF / F5 ASM solutions.
· Knowledge of web application security concepts and OWASP Top 10 vulnerabilities.
· Experience with WAF policy management, signatures, and rule tuning.
· Understanding of HTTP/HTTPS, SSL/TLS, DNS, TCP/IP, and load balancing concepts.
· Experience troubleshooting web application access and security issues.
· Basic Windows/Linux administration knowledge.
· Strong troubleshooting and analytical skills.
Preferred Certifications
· F5 Certified Administrator (F5-CA)
· F5 ASM/WAF Certification
Experience & Qualification
· 5-7 years of cybersecurity or WAF administration/support experience.
· Minimum 2+ years of hands-on F5 WAF support experience.
· Bachelor’s degree in Computer Science, Information Security, or related field.
Good to Have
· Experience with SIEM platforms such as Splunk, QRadar, or Microsoft Sentinel.
· Knowledge of PowerShell, Python, or Bash scripting.
· Exposure to cloud environments such as AWS, Azure, or GCP.
· Understanding of compliance frameworks and audit requirements.
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.