Skip to main content
IS3 logo

F5 WAF Lead Engineer

IS3
7 days ago
Remote
Web Development

F5 WAF Lead Engineer

We are seeking an experienced F5 WAF Lead Engineer to own and drive the transformation of enterprise web application firewall security — moving from broad, generic rule sets to application-specific, tailored WAF policies across a large application portfolio. This is not a maintenance or administration role: the ideal candidate combines deep hands-on F5 WAF/XC expertise with the ability to set direction, define methodology, and build the automation and AI-assisted tooling needed to operate at scale. The engineer will work directly with client security leadership to define strategy and milestones, while remaining hands-on in building, tuning, and implementing policy.

Key Responsibilities

  • Define and lead the strategy for transitioning from broad WAF rules to per-application, tailored security policies across a large application portfolio.
  • Design and build an AI-assisted policy development workflow — using scan output, traffic data, and application configuration to recommend and generate tailored WAF policies at scale.
  • Evaluate, recommend, and implement F5 Distributed Cloud (XC) WAAP policies on an application-by-application basis.
  • Integrate findings from vulnerability and penetration testing tools into the policy development process.
  • Partner directly with client cybersecurity leadership to define deliverables, direction, and rollout milestones.
  • Establish repeatable methodology and documentation so the practice can scale as volume grows and the team expands.
  • Support and mentor additional team members as the engagement scales.
  • Troubleshoot complex WAF policy, traffic, and security issues across cloud-hosted environments.
  • Support incident response and root cause analysis for WAF/application security events.
  • Coordinate change management and production deployment windows for policy rollouts. Required Qualifications
  • 5+ years of experience in web application firewall engineering, with strong hands-on expertise in F5 Distributed Cloud (XC) WAAP.
  • Demonstrated experience designing and implementing custom, per-application WAF policies (not just baseline/default rule sets).
  • Experience conducting web application vulnerability assessment and remediation.
  • Strong understanding of OWASP Top 10 and emerging web application threats.
  • Experience leveraging AI/automation tooling to scale security operations (policy generation, evaluation, or triage).
  • Ability to operate as both a strategic lead (defining direction, engaging client stakeholders) and a hands-on implementer.
  • Experience with F5 Silverline and/or BIG-IP ASM/Advanced WAF (prior-generation context).
  • Familiarity with cloud-hosted application architectures.
  • Excellent communication skills — able to present strategy and status to client security leadership. Preferred Qualifications
  • Experience integrating SAST/SCA/DAST/pen-test tooling into WAF policy workflows.
  • F5 Certified Technology Specialist (CTS) or equivalent.
  • Experience with regulated environments (PCI, SOX, HIPAA).
  • Knowledge of Zero Trust and API security frameworks.
  • Familiarity with automation/scripting (Python, REST APIs, Terraform) for policy-as-code workflows.
  • Prior experience leading or scaling a security engineering practice/team.

Technical Skills

F5 Technologies: F5 Distributed Cloud (XC) WAAP, F5 Silverline, BIG-IP ASM/Advanced WAF (legacy context)

Security: Web Application Firewall (WAF) policy design, OWASP Top 10, AI-assisted security tooling, application security, API security, vulnerability assessment, threat mitigation