Application Delivery-WAF Content Security Engineer
Malomatia Doha, Qatar
IT Services and IT Consulting · 1,001-5,000 employees
About the role
The engineer will manage end-to-end application delivery, global traffic management, and WAF security across F5 and FortiWeb platforms. They are also responsible for infrastructure automation, SSL/TLS lifecycle management, and file-based threat triage using OPSWAT.
What they look for
Requirements
Candidates must have a bachelor's degree in computer science or a related field and at least 8 years of experience with F5 BIG-IP or FortiWeb. Proficiency in infrastructure-as-code tools like Terraform and Ansible is required, along with a strong understanding of Layer 4-7 traffic management.
Full description
Own end-to-end application delivery, global traffic management, Web Application Firewall (WAF), and content/file threat protection across F5 BIG-IP (LTM & Advanced WAF), F5 GTM, FortiWeb WAF, and OPSWAT. Responsible for traffic steering, SSL/TLS lifecycle, high availability, API/bot protection, file-based threat triage, and automation of infrastructure delivery.
Responsibilities
- Configure and manage F5 BIG-IP LTM: virtual servers, pools, health monitors, persistence profiles, and traffic steering.
- Administer F5 GTM for global DNS-based load balancing, south-north traffic steering, private DNS integration, and pool/health monitor management.
- Own SSL/TLS lifecycle across the app delivery stack: offloading, certificate management, SSL profiles, and TLS hardening on F5 and FortiWeb tiers.
- Design and maintain High Availability: device clustering, config sync, failover, and resiliency across F5 platforms.
- Manage Web Application Protection: OWASP Top 10 profiles, custom security policies, signature management, API protection, bot mitigation, rate limiting, and IP intelligence (F5 Advanced WAF, FortiWeb).
- Tune attack detection policies, manage signature updates, and reduce false positives across WAF platforms; build custom attack signatures where required.
- Lead BIG-IP and FortiWeb appliance/VE deployment, provisioning, TMOS/firmware upgrades, hotfixes, backup/restore, and configuration lifecycle management.
- Integrate FortiWeb with OCI Load Balancer and other cloud LB services for L7 inspection.
- Manage OPSWAT file scanning platform for Data-in-Transit and Data-at-Rest content inspection; triage, analyze, and action file scan results, including false-positive review.
- Maintain scanning policies and workflows to support secure file transfer and content-handling processes across the organization.
- Drive Infrastructure Automation using REST API, AS3, Terraform, and Ansible for automated configuration deployment.
- Perform health/performance monitoring, logging, analytics, and root-cause analysis; own vulnerability assessment, hardening, and patch compliance for all app-delivery and content-security assets.
Qualifications
Required Qualifications & Experience
- Bachelor’s degree in computer science, Information Security, or related field.
- 8+ years' experience with F5 BIG-IP (LTM/GTM/Advanced WAF) and/or FortiWeb in enterprise production environments.
- Experience with content disarm & reconstruction (CDR) / multi-scanning platforms (OPSWAT or equivalent) is highly desirable.
- Working knowledge of infrastructure-as-code and automation (Terraform, Ansible, REST API/AS3).
- Certifications preferred: F5 Certified BIG-IP Administrator (F5-CA), F5 301a/302 (Advanced WAF), NSE 6 (FortiWeb).
- Strong understanding of DNS, SSL/TLS, Layer 4–7 traffic management, and file-based threat triage.
Similar roles
-
Cybersecurity Engineer
Odyssey Systems Consulting Group, Ltd. Hanscom AFB, Massachusetts, United States · $175K–$185K/yr
-
IT Auditor Cybersecurity and Tech Controls
coni+partner AG Zurich, Zurich, Switzerland
-
Senior Cybersecurity Presales Consultant
SNSIN Chennai, Tamil Nadu, India
-
Security Engineer
Zensar Hyderabad, Telangana, India
-
Cybersecurity Ops Analyst Senior
SAIC Oak Ridge, Tennessee, United States
-
Fire & Security Engineer
Securitas Wakefield, England, United Kingdom