NineTech
WAF Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
WAF Engineer
Location: Remote
Rate: £550 Inside IR35
6 Month Contract
The Role
We are seeking an experienced WAF / WAAP Security Engineer / SME to play a key role in enhancing and strengthening our Web Application Firewall (WAF) and Web Application & API Protection (WAAP) capabilities across multiple solutions and applications.
This is a hands-on technical role focused on designing, developing, testing and implementing advanced WAF/WAAP security controls to protect web applications and APIs against evolving and sophisticated cyber threats.
The successful candidate will bring strong ethical hacking, web/API security, WAF engineering, security testing, coding and DevSecOps experience, with responsibility across the full WAF/WAAP use-case lifecycle.
Key Responsibilities
- Develop, enhance and maintain complex custom WAF/WAAP rules and features, addressing MVP requirements and security posture gaps.
- Own and support the full WAF/WAAP use-case lifecycle, including:
- Baseline lifecycle management
- Tiered baseline design
- Baseline and rule tuning
- Emergency rule updates
- WAF/WAAP incident management
- Consolidation feasibility study
- Conduct detailed technical evaluations of WAF/WAAP rulesets to assess the detection and prevention of web and API security threats.
- Identify WAF weaknesses, bypasses and evasion techniques through ethical hacking and security testing.
- Reverse-engineer attacker tactics and techniques to develop effective mitigation and detection rules.
- Design and develop automated testing mechanisms for baseline and custom WAF rules and features.
- Integrate WAF/security testing into CI/CD and automation pipelines, supporting DevSecOps and DevOps objectives.
- Provide SME support for security testing activities, including WAF Proofs of Concept (PoCs), technical assessments and solution evaluations.
- Provide specialist advice on web/API attack methodologies, exploitation, evasions and mitigation techniques.
- Support incident investigations and provide rapid WAF rule changes in response to emerging threats and vulnerabilities.
- Work closely with Security, Application, Engineering, DevOps and DevSecOps teams to embed effective security controls.
- Maintain accurate technical documentation, test evidence and reports to support traceability, governance and compliance.
- Keep the EPS Management team informed of emerging web/API threats and vulnerabilities, providing clear recommendations and countermeasures.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Key Skills & Experience
- 8+ years’ experience in cybersecurity, application security, WAF engineering or a related discipline.
- Strong hands-on experience with WAF / WAAP technologies.
- Proven experience developing, testing and tuning complex WAF rules and policies.
- Strong understanding of web application and API security, including OWASP-based attack techniques.
- Solid ethical hacking / penetration testing background.
- Experience identifying and exploiting WAF bypass and evasion techniques.
- Strong coding/scripting skills for security testing and automation.
- Experience integrating security testing into CI/CD pipelines and DevSecOps environments.
- Experience with WAF baselines, rule tuning, emergency changes and security incident management.
- Experience supporting WAF PoCs and technical evaluations.
- Strong analytical and problem-solving skills with the ability to translate offensive security findings into practical defensive controls.
- Excellent communication skills and the ability to operate effectively as a WAF/WAAP SME.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Experience across multiple WAF/WAAP platforms or vendors.
- Strong API security and automated security testing experience.
- Experience with WAF/WAAP platform rationalisation or consolidation assessments.
- Relevant security certifications such as OSCP, CREST, GWAPT, CEH or equivalent.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location