WAF System Lead

BoehringerPRDOn-siteFull-timeSenior, 5–8 yearsListed 1 hour ago

Apply now

About this role

The Position

Join Boehringer Ingelheim's Cyber Intelligence & Security Operations Center (CISOC) as a Web Application Firewall (WAF) System Lead. In this role, you will serve as the technical owner and subject matter expert for the organization's Web Application Firewall service, ensuring the protection of critical web applications and digital assets. You will drive service strategy, governance, continuous improvement, and operational excellence while collaborating with global cybersecurity teams, application owners, infrastructure teams, and external vendors.

This position offers an opportunity to play a key role in strengthening BI's cybersecurity posture through the management and evolution of enterprise-grade WAF technologies and web application protection capabilities.

Duties & Responsibilities

As a member of the Cyber Intelligence & Security Operations Center (CISOC) team, the role will be responsible for the ownership, governance and continuous improvement of the Web Application Firewall service. The System Lead will act as the subject-matter expert for the WAF platform and coordinate with WAF Core operations, Cyber Response, Cyber Detection, application owners, infrastructure teams and the vendor.

- Own the WAF platform and service, including roadmap, lifecycle, architecture decisions, standards and service improvements.

- Act as the subject-matter expert and escalation point for complex WAF incidents, false positives, security events and operational requests.

- Define, approve and maintain operational runbooks, knowledge articles, support procedures and escalation paths for WAF Core L1 and L2 operations.

- Govern the onboarding, modification and offboarding of websites and use cases protected by the WAF.

- Oversee WAF security policies, signatures, DDoS and bot-protection settings, certificates, origin-server protection and exception handling.

- Coordinate vendor support cases, technical escalations, platform issues and product roadmap discussions.

- Provide functional training, onboarding guidance and mentoring to WAF administrators and operational teams.

- Ensure monitoring, audit and security logs are available to the relevant security teams and support incident investigation and detection use cases.

- Review privileged-access requests and ensure access is granted according to training, role and operational requirements.

- Follow BI processes and maintain the required service, operational and compliance documentation.

Requirements:

An ideal candidate will have

- Strong hands-on experience operating and governing enterprise Web Application Firewall services, preferably Imperva Cloud WAF and/or Imperva SecureSphere.

- Solid knowledge of HTTP/HTTPS, DNS, TLS certificates, reverse-proxy architectures, web application traffic and common web attacks.

- Experience with WAF policies, security rules, signatures, whitelisting, false-positive analysis, DDoS protection, bot management and troubleshooting.

- Experience managing incidents, service requests, changes, problems, access approvals and vendor support cases in an enterprise environment.

- Ability to define operating models, runbooks, standards, escalation processes and technical roadmaps.

- Working knowledge of ServiceNow or comparable service-management platforms and security monitoring or SIEM integrations.

- Automation or scripting experience using APIs, Python, Ansible, PowerShell or Bash.

- Strong analytical, problem-solving, stakeholder-management and communication skills.

- Excellent spoken and written English and experience working in an international, multicultural environment.

- Relevant web security, cloud, networking or vendor certifications are desirable but not mandatory.