Sr. Waf Security Engineer

Warner Bros Discovery Warner Bros Discovery · Media · Atlanta, GA +3 · Technology

This role is for a Senior WAF Security Engineer responsible for implementing, configuring, and maintaining WAF and DDoS protections, performing log analysis, contributing to automation efforts, identifying security vulnerabilities, and participating in incident response. The role requires expertise in WAF platforms, rule writing, HTTP/S protocols, OWASP Top 10, and API security models, with experience in cloud environments and scripting.

What you'd actually do

  1. Implement, configure, and maintain enterprise-grade WAF and DDoS protections across a large portfolio of properties.
  2. Develop and fine-tune custom firewall rules, bot mitigation controls, and DDoS mitigation security policies.
  3. Perform log analysis to identify malicious traffic patterns, false positives, and opportunities for tuning.
  4. Contribute to automation efforts (infrastructure as code, CI/CD integrations, scripts) to deploy and maintain security configurations.
  5. Identify security vulnerabilities and guide developers and engineers in addressing these issues

Skills

Required

  • WAF/DDoS solutions
  • WAF rule writing
  • HTTP/S protocols
  • OWASP Top 10
  • API security models
  • log analysis tools
  • scripting (Python, Bash, PowerShell)
  • automation frameworks
  • Cloud Providers (AWS, GCP, Azure)

Nice to have

  • Security certifications (CISSP, CISM, CISA, SANS)
  • infrastructure-as-code (Terraform, CloudFormation)
  • CDN integrations
  • API Security frameworks
  • DDoS mitigation at scale

What the JD emphasized

  • direct hands-on work in WAF/DDoS solutions
  • writing/modifying WAF rules
  • HTTP/S protocols
  • OWASP Top 10
  • API security models