←  العودة إلى كل الوظائف

Expert Engineer/Application & End Point Security

Etisalat E&

قطاع: Telecommunications

📍 دبي، الإمارات
💼 دوام كامل
🕒 نُشرت قبل 4 أيام

وصف الوظيفة

Role Overview

Expert Engineer/Application & End Point Security at Etisalat E&. This role is responsible for the implementation, configuration, monitoring, and maintenance of Web Application Firewalls (WAF) deployed for internal and external customers.

Role Purpose

Protect web applications from cyber threats and vulnerabilities by deploying, configuring, and maintaining WAF solutions. Work closely with Cybersecurity teams to ensure effective defense against OWASP Top 10 attacks and other security risks while minimizing operational impact and false positives.

Key Responsibilities

WAF Deployment & Configuration

  • Perform end-to-end provisioning of web applications on WAF including requirements gathering, defining the scope of protection, and creating tailored web security profiles based on web application architecture.
  • Deploy and configure dedicated WAF instances based on special project requirements and create customized security policies for protected web applications.
  • Integrate all WAF deployments with security controls including SIEM, PAM, RSA, and Solarwinds.

Security Policy & Tuning

  • Fine-tune new security policies via rigorous testing of all web application flows to ensure maximum suppression of false positives for effective SOC monitoring.
  • Fine-tune attack logs for existing web applications by identifying false positives and updating security profiles accordingly for effective monitoring.
  • Evaluate all exceptions and whitelistings for any security impact on web applications before placing them on WAF.
  • Plan and perform security enhancements on security profiles of existing web applications protected by WAF, ensuring minimal impact on live traffic.
  • Apply compensatory security controls on WAF for protected web applications if they cannot be fixed on the application end.

Monitoring & Maintenance

  • Regularly monitor WAF system resources including CPU, memory, and disk utilization to ensure they remain within threshold ranges and raise flags in a timely manner.
  • Identify unusual activity and attacks by monitoring administrative and security alerts via regular reports.
  • Perform regular backup restoration test drills for all WAF deployments.
  • Ensure periodic backups to remote backup servers are properly configured and running successfully as per schedule.
  • Keep track of web application certificates' expiry on WAF and update them in time to avoid impact to users.

Upgrades & Patching

  • Evaluate, plan, test, and execute WAF upgrades to latest recommended stable versions for all WAF deployments after extensive bug-scrubbing and careful analysis of all changes to ensure no impact on protected applications.
  • Ensure all WAF deployments are running up-to-date and vendor-supported operating system versions.
  • Implement corrective measures and remediation actions to address newly discovered security vulnerabilities on WAF.

Compliance & Assessment

  • Conduct regular security assessments and audits to ensure the effectiveness of WAF configurations and policies.
  • Monitor licenses and vendor contract expiry of all WAF deployments and communicate with stakeholders accordingly.
  • Maintain proper and updated documentation related to WAF high-level design (HLD), low-level design (LLD), configurations, security policies, applications status, and owner information for all WAF deployments.

Incident Support & Stakeholder Management

  • Support the SOC and Incident Response team by providing required attack logs from WAF for incidents under investigation.
  • Highlight operational challenges and current issues on all WAF deployments.
  • Effectively communicate and collaborate with different stakeholders for new WAF deployments and troubleshooting of operational issues.

Qualifications & Experience

  • Minimum 6 years' experience related to WAF administration and web application security.
  • Bachelor's degree in Computer Science, Information Technology, or related field.
  • Certified Ethical Hacker (CEH) or similar certifications preferred.
  • Must have expertise in WAF F5 troubleshooting.
  • In-depth understanding of web application security principles, including OWASP Top 10 vulnerabilities and common attack vectors.
  • Strong knowledge of network protocols, firewall technologies, and web server platforms.

Skills & Competencies

  • Experience with scripting languages preferred for automation and customization of WAF configurations.
  • Excellent analytical and problem-solving skills with the ability to prioritize and troubleshoot complex security issues.
  • Effective communication skills with the ability to collaborate with cross-functional teams and articulate technical concepts to non-technical stakeholders.

الباحثون عن هذه الوظيفة بحثوا أيضاً عن

الإبلاغ عن هذه الوظيفة

⚡ تقدّم سريع

أنشئ حسابك وارفع سيرتك الذاتية للتقدّم إلى — يستغرق أقل من دقيقة.

✨ احصل على تقرير تقييم مجاني بالذكاء الاصطناعي لسيرتك الذاتية فور التسجيل.