Web Application Firewall Engineer @ Deloitte

2 weeks ago


Sydney, New South Wales, Australia Cyber Crime Full time
  • Work in a highly innovative and transformative business
  • Mentoring, growth and training – receive support and coaching to progress your career
  • Preventive and supportive mental health initiatives

Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.

What will your typical day look like?

The Web Application Engineer candidate will have a strong background in cybersecurity and understanding of web application security practices. The primary responsibility of the WAF Engineer will be to ensure the effective deployment, configuration, and maintenance of our web application firewall systems for Global customers. This role requires expertise in Web Application Firewalls as well as experience with alerts and detections and data log analysis.

Key Role Responsibilities:

  • Web Application Firewall Management: Deploy, configure, and maintain web application firewall systems to protect our web applications against potential threats and vulnerabilities.
  • WAF Security Incident Response : Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and Cybersecurity teams.
  • Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks within the WAF. Provides investigation findings to relevant business units to help improve information security posture.
  • CDN Integration: Collaborate with the infrastructure and application teams to integrate the web application firewall with CDNs such Akamai and Radware, ensuring seamless traffic management and content delivery.
  • Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers.
  • Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed.
  • Collaboration and Training: Collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide training and guidance to other team members on WAF best practices and security awareness, as needed.
  • Collaborate with key stakeholders within Cybersecurity, Engineering, and Development teams to create specific use cases to address business needs and security requirements.

About the team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.

Enough about us, let's talk about you.
You are someone with:

  • Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience
  • 4+ years experience with minimum 2 years into network security and 2 years in WAF
  • Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques.
  • Strong technical background with Akamai or Radware Web Application Firewall (WAF) technologies and bot mitigation security policies.
  • Proficiency in deploying and managing web application firewalls, preferably with experience in AKAMAI and RADWARE or similar tools.
  • Understanding of API security issues and API authentication.
  • Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis is highly desirable. Prior experience working with Splunk for security event management, log analysis, and threat detection.
  • Good understanding of information security principles and policy enforcement.
  • Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs
  • Strong technical background in web development and familiarity with potential attack vectors/methods
  • Understanding of DNS, Networks, Firewalls, SSL Certificates

Preferred:

  • Knowledge of Web Application Firewall technologies (Akamai and Radware)
  • Ethical hacking
  • ServiceNow experience
  • Technical documentation experience
  • Familiarity with cloud security services, concepts, and best practices
  • CISSP, CISM, CISA, GIAC or other security certifications

At Deloitte, we focus our energy on interesting and impactful work.We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We putcoaching at the heart of what we do, helping our people grow their careers in any direction – whether it be up, moving into something new, or even moving across the world.

We embrace diversity, equity and inclusion. We have a diverse collection of people from differentbackgrounds, with different experiences, gender identities, abilitiesandthinking styles. What binds us together is a shared commitment tovalueeveryone'sperspectiveand to cultivate inclusion; so that our work environment is a safe space we can all belong.

We prioritise flexibility and choice.At Deloitte, you get trust on Day 1.We know our people get their best work done when they're in control of where and how they work, designing their work week around their client, team and personal commitments.

We help you live and work well.To support your personal and professional life, we offer a range ofperks and benefits , including retail discounts, wellbeingleave, paid volunteering days, twelveflexible working options, market-leading parental leave and return to work support package.

Next Steps

Sound like the sort of role for you? Apply now.

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Sydney, New South Wales, Australia Cyber Crime Full time

    Work in a highly innovative and transformative business Mentoring, growth and training – receive support and coaching to progress your career Preventive and supportive mental health initiatives Deloitte Global is the engine of the Deloitte network.Our professionals reach across disciplines and borders to develop and lead global initiatives.We deliver...


  • Sydney, New South Wales, Australia Deloitte Australia Full time

    Job Requisition ID: 31236 About our team The A&A Analytic Solutions team is at the heart of the Audit & Assurance Digital Strategy across Deloitte Asia Pacific. Our team of data technologists (Artificial Intelligence / Machine Learning / Deep Learning), designers, developers and management consultants coupled with our proprietary data platform powers the...


  • Sydney, New South Wales, Australia Deloitte Australia Full time

    Job Requisition ID: 31236 About our team The A&A Analytic Solutions team is at the heart of the Audit & Assurance Digital Strategy across Deloitte Asia Pacific. Our team of data technologists (Artificial Intelligence / Machine Learning / Deep Learning), designers, developers and management consultants coupled with our proprietary data platform powers the...


  • Sydney, New South Wales, Australia Talent Web Full time

    Title:- Cyber Security SpecialistLocation:- SydneyLength:- Permanent Salary:- $170 to $180k PackageLeading Australian wealth management business requires a hands-on permanent Cybersecurity Specialist for there Sydney CBD office. Your role will see you help uplift the Cybersecurity maturity along with complying with APRA's regulatory requirements. Day to day...


  • Sydney, New South Wales, Australia Bluefin Resources Full time

    Senior Network Engineers- Edge firewall transformation project A leading bank in Sydney is seeking multiple Senior Network Engineers for a major Edge firewall transformation project across multiple datacentres and a replacement of their F5's.Roles are both contract and permanent with a very strong pipeline of project work.Design build and implementation...


  • Sydney, New South Wales, Australia Bluefin Resources Full time

    Senior Network Engineers- Edge firewall transformation projectA leading bank in Sydney is seeking multiple Senior Network Engineers for a major Edge firewall transformation project across multiple datacentres and a replacement of their F5's.Roles are both contract and permanent with a very strong pipeline of project work.Design build and implementation...


  • Sydney, New South Wales, Australia Deloitte Australia Full time

    Job Requisition ID: 31231 In Finance Assurance, we are specialists in finance function transformation, CFO advisory services, accounting change, financial management, transaction accounting advice, and specialised finance outsourcing. To put it simply, we help our clients make their finance functions more efficient and effective. You will be working as part...


  • Sydney, New South Wales, Australia Cloudflare Full time

    Available Location: Remote, Australia, or Sydney, AustraliaAbout the role:Cloudflare provides advisory and hands-on-keyboard implementation and migration services for enterprise customers.As a Professional Services Consultant for Application Security and Performance, you are an individual contributor working in the post-sales landscape, responsible for the...


  • Sydney, New South Wales, Australia CloudFlare Full time

    Available Location: Remote, Australia, or Sydney, AustraliaAbout the role:Cloudflare provides advisory and hands-on-keyboard implementation and migration services for enterprise customers. As a Professional Services Consultant for Application Security and Performance, you are an individual contributor working in the post-sales landscape, responsible for the...


  • Sydney, New South Wales, Australia Talent Web Full time

    Are you a Mid - Senior Software Engineer looking to take the next step up in your career? If so, then working with one of Australia's fastest growing, revenue generated start-ups could be the next step for you In the vibrant world of a startup, every day is a new adventure. Here, innovation and agility go hand-in-hand, with every team member playing a...

  • IT Audit

    2 weeks ago


    Sydney, New South Wales, Australia Deloitte Australia Full time

    Job Requisition ID: 31234In the Audit & Assurance division, the Technology and Controls Team (TaCT) provides specialist review to the existing IT controls safeguarding corporate assets and cross-checks whether the IT controls are in line with the business. We bring our IT and accounting skills to empower clients with a crystal-clear understanding of their...

  • IT Audit

    3 weeks ago


    Sydney, New South Wales, Australia Deloitte Australia Full time

    Job Requisition ID: 31234In the Audit & Assurance division, the Technology and Controls Team (TaCT) provides specialist review to the existing IT controls safeguarding corporate assets and cross-checks whether the IT controls are in line with the business. We bring our IT and accounting skills to empower clients with a crystal-clear understanding of their...

  • Azure Cloud Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Talent Web Full time

    Title:- Senior Azure Cloud EngineerLength:- Permanent Location:- North ShoreROLE PURPOSE:This key role will help drive the cloud strategy while remaining very technical and hands-on. IT is a collaborative agile environment where skills, attitude, and cultural fit are all extremely important. You will work within the Infrastructure and Cloud team to deliver...


  • Sydney, New South Wales, Australia REAL TIME AUSTRALIA Full time

    Local to Sydney / Hybrid setup (WFH +2 days onsite - Sydney CBD 2000) Min. 12 months contract (strong potential for perm conversion) $456/day (incl. super + laptop + training) Build your career with 1 of the World's leading Cloud Software company & be a key contributor for their highly collaborative & multi-talented Tech Support organisation Client &...

  • Devops Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Apps Mav Full time

    Location: SydneyWe are looking for a talented and passionate AWS certified Dev Ops Engineer to help build and manage a world-class Saa S apps infrastructure.You'll use your knowledge of Linux and software development as you help ensure the reliability and performance of a large and diverse tech stack.You will directly engage with development teams to provide...

  • System Engineer

    2 weeks ago


    Sydney, New South Wales, Australia ignite Full time

    We are seeking a driven and skilled System Engineer for our client, a multi-national company - that designs, develops and manufactures complex systems for the aerospace, defence, transportation, and security sectors. Reporting to the Engineering manager – you will be responsible for supporting the planning and coordination of program hardware integration...

  • Senior Cyber Engineer

    2 weeks ago


    Sydney, New South Wales, Australia EFinancialCareers Ltd. Full time

    Senior Cyber Engineer - Edge Security Commonwealth Bank of Australia Sydney, Australia Senior Cyber Engineer - Edge Security Commonwealth Bank of Australia Sydney, Australia Posted 2 days ago Permanent Competitive Opportunity to grow and develop your technical skills as we grow our team A critical function within the Commonwealth Bank Cyber Security Centre...


  • Sydney, New South Wales, Australia Hpr Full time

    HPR is a leading provider of high-performance and ultra-low latency electronic trading and capital markets infrastructure solutions offered as a managed service.Our cutting-edge technology is used by tier-1 financial institutions to monitor and execute trades rapidly and efficiently.Due to our exciting and rapid growth, HPR is searching for a Senior...

  • DevOps Engineer

    2 weeks ago


    Sydney, New South Wales, Australia Apps Mav Full time

    Location: SydneyWe are looking for a talented and passionate AWS certified DevOps Engineer to help build and manage a world-class SaaS apps infrastructure. You'll use your knowledge of Linux and software development as you help ensure the reliability and performance of a large and diverse tech stack. You will directly engage with development teams to provide...


  • Sydney, New South Wales, Australia Firesoft People Full time

    Application Support Engineer We are a leading technology company specializing in cutting-edge solutions for businesses across various industries. With our commitment to innovation and excellence, we have established ourselves as a trusted partner for our clients' IT needs. Our team consists of dedicated professionals who work collaboratively to deliver...