WAF Engineering Lead

WTWNew York, NY
$120,000 - $160,000

About The Position

The WAF Engineering Lead role is intended to maximise the operational performance of WTW services and maintain a strong secure posture. The role is accountable for BAU support of issues, controlling policy & compliance and supporting change activities. This role ensures the technical success of WAF services within the WTW environment in a Tier 3 capacity and management of direct reports.

Requirements

  • Tier 3 capacity for WAF services
  • Management of direct reports
  • Technical leadership
  • Subject matter expertise for web application security, secure application delivery and WAF best practices
  • Experience with OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.
  • Experience developing, maintaining and enhancing custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.
  • Experience supporting transition of WAF policies from Detection mode to Prevention/Block mode.
  • Experience analysing attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.
  • Experience working closely with application owners, development teams and security stakeholders.
  • Experience in Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.
  • Experience providing leadership during major incidents.
  • Experience coaching team members.
  • Experience restoring service and completing root cause analysis of all incidents.
  • Experience participating on the Technical Design Authority forum.
  • Experience implementing changes/POCs to the environment in a controlled manner, with implementation and test plans.

Responsibilities

  • Perform analysis and tuning of WAF policies to minimise false positives and false negatives while maintaining an appropriate security posture.
  • Design, implement, maintain and optimise WAF policies across multi-cloud environments.
  • Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.
  • Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.
  • Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement.
  • Analyse attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.
  • Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications.
  • Provide subject matter expertise for web application security, secure application delivery and WAF best practices.
  • Provide technical leadership to Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.
  • Provide leadership during major incidents and drive to quick resolutions.
  • Provide line management for direct reports
  • Point of escalation for areas of accountability
  • Coach team members on a proactive basis, raising the team’s overall technical acumen.
  • Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.
  • Participate on the Technical Design Authority forum
  • Implement changes/POCs to the environment in a controlled manner, with implementation and test plans.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service