Web Application Firewall Engineer

Hok Consulting Technical Recruitment — Poland · Posted ~2 hours ago

Contract Hybrid

Skills

Web Application Firewall (WAF) WAF configuration WAF penetration testing Security testing Threat analysis Security policy tuning SQL Injection testing XSS testing API security testing OWASP Top 10 False-positive/true-positive analysis WAF rule optimization GoTestWAF WAF SQL Injection XSS API security

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a security-focused engineering team to strengthen protection for web applications and APIs. You will test WAF defenses against common and advanced attack scenarios, identify weaknesses and bypass techniques, tune security policies, analyze detection quality, and support secure application and API onboarding. Experience with automated WAF validation tools and OWASP-based security testing is valuable.

Highlights

Long-term hybrid contract focused on advanced web and API security, including WAF penetration testing, threat analysis, policy optimization, and protection against application-layer attacks.

Description

Job Title: Web Application Firewall Engineer Duration: long-term contract Location: Poland Based Hybrid We are looking for a Web Application Firewall Engineer to strengthen web application and API security through WAF configuration, security testing, threat analysis, and policy tuning. The role will focus on identifying WAF weaknesses, testing attack scenarios and bypass techniques, and improving protection against application-layer threats. Key Responsibilities Test protection against SQL Injection, XSS, API attacks, OWASP Top 10, and other attack categories.Perform WAF penetration testing and security assessments.Configure and tune WAF security policies, Identify and analyse WAF weaknesses, misconfigurations, and bypass techniques.Analyse true positives and false positives and optimise WAF rules accordingly.Use automated tools such as GoTestWAF to validate WAF security controls.Support application and API onboarding and security policy implementation. Required Skills Good knowledge of WAF bypass, penetration testing, SQL Injection, XSS, OWASP, and attack techniques.Experience with GoTestWAF or similar security testing tools.Good Python or scripting/coding skills for security automation.Strong understanding of HTTP/HTTPS, APIs, web applications, and application security.