Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this WAF Engineering Lead role.
Rezi rewrites your resume against WTW's job description. Free.

Tailor your resume to this WAF Engineering Lead role.
Rezi rewrites your resume against WTW's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the WAF Engineering Lead posting at WTW — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the WAF Engineering Lead posting at WTW — free, in seconds.
About the Role
The WAF Engineering Lead role is intended to maximize the operational performance of WTW services and maintain a strong secure posture. The role is accountable for BAU support of issues, controlling policy & compliance and supporting change activities. This role ensures the technical success of WAF services within the WTW environment in a Tier 3 capacity and management of direct reports.
Responsibilities
- Perform analysis and tuning of WAF policies to minimize false positives and false negatives while maintaining an appropriate security posture.
- Design, implement, maintain and optimize WAF policies across multi-cloud environments.
- Lead the investigation and mitigation of web application attacks, including OWASP Top 10 threats, bot attacks, credential stuffing, scraping, Layer 7 DDoS attacks and other web-based threats.
- Develop, maintain and enhance custom WAF rules, managed rule exclusions, rate-limiting policies and bot protection controls.
- Support transition of WAF policies from Detection mode to Prevention/Block mode through structured analysis, tuning, testing and stakeholder engagement.
- Analyze attack patterns, logs and telemetry to identify emerging threats and implement effective mitigations.
- Work closely with application owners, development teams and security stakeholders to ensure secure onboarding and operation of internet-facing applications.
- Provide subject matter expertise for web application security, secure application delivery and WAF best practices.
- Provide technical leadership to Audit & Compliance, Capacity Management, Lifecycle Management, Vulnerability Management and Risk Management Functions.
- Provide leadership during major incidents and drive to quick resolutions.
- Provide line management for direct reports.
- Act as a point of escalation for areas of accountability.
- Coach team members proactively, raising the team’s overall technical acumen.
- Restore service and complete root cause analysis of all incidents, driving actions to mitigate the root cause and remove risk of reoccurrence.
- Participate on the Technical Design Authority forum.
- Implement changes/POCs to the environment in a controlled manner, with implementation and test plans.