Overview
In this role you design, evolve and operate WAF platforms to protect customer-facing services at scale. You will advance modern, automated, secure-by-default infrastructure across edge, data center and cloud environments. You’ll influence technical direction, uplift engineering standards and develop Layer 7 security services. You work with cross-functional teams to improve resilience, performance and incident response, with a strong autonomous operating style and visible impact.
Pay / Benefits
- Generous pension contribution up to 15%
- Annual bonus (subject to Group performance)
- Share schemes including free shares
- Discounted shopping benefits
- 28 days’ holiday plus bank holidays
- Wellbeing initiatives and parental leave policies
Responsibilities
- Design, implement and evolve WAF capabilities using Infrastructure-as-Code, CI/CD pipelines and policy-as-code
- Lead platform modernization and service improvements including refactoring, automation and debt reduction
- Enhance observability with monitoring, alerts and telemetry to improve reliability and incident response
- Support major incident diagnostics in collaboration with Security Engineering, Networks and Cloud teams
- Embed secure-by-design patterns and guardrails and codify controls for easy consumer adoption
- Create high-quality engineering documentation, standards, patterns and runbooks for self-service and repeatability
- Participate in on-call duty to bolster operational resilience of critical services
Key requirements
- Hands-on experience with edge, on-prem and cloud-native WAF technologies
- Strong automation and scripting skills (Python preferred)
- Practical experience with Infrastructure-as-Code tools (Terraform preferred) and modern CI/CD pipelines
- Solid understanding of networking and web fundamentals (HTTP/S, DNS, TLS) and security concepts
- Ability to lead complex technical investigations and guide robust solutions under pressure
- Confidence to influence engineering decisions and contribute to strategic technical direction
- Knowledge of Application Security, API Security, Bot Protection and Layer 7 DDoS (nice to have)
- Professional-level cloud certifications or security/network engineering accreditations (nice to have)
- Strong collaboration with cross-functional teams
- Problem-solving under pressure
- Ability to influence and communicate complex technical concepts
- WAF technologies (edge/on-prem/cloud)
- Python scripting
- Terraform (IaC)
…
