עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
About Miggo
We're Miggo — a cybersecurity startup on a mission to stop app-layer breaches before they happen. Founded in 2023 and backed by top-tier cyber VCs, we're building the world's first Application Detection & Response (ADR) platform. Why? Because 80% of cyber attacks target the app layer, and current tools just don't cut it. Miggo brings visibility into how apps actually behave at runtime, spotting risky flows and shutting down threats in real time.
We're closing the patch gap: showing security teams what's reachable, what's exploitable, and what's being attacked right now — and delivering targeted mitigations when a patch isn't ready.
At Miggo, We Live By Four Core Values
- We make it customer-focused — user needs are our north star.
- We make it happen — driven by execution and a can-do mindset.
- We make it better — always pushing boundaries and learning fast.
- We make it together — one team, thriving on collaboration and diverse perspectives.
Miggo's WAF Copilot takes a freshly disclosed CVE and produces a validated, provider-specific WAF rule — researching the vulnerability, deriving the attack surface, composing the rule, then attacking its own output with an independent bypass judge and a false-positive prober before a human is offered a deploy.
As WAF Security Specialist you are the ground truth the Copilot is measured against — the person who can look at a generated rule and say this blocks the PoC but not the four obvious variants, this will trip on legitimate multipart uploads, this is 340 WCUs of nothing because the managed ruleset already catches it, this can't be anchored tightly enough to live in a global Web ACL.
You'll be shipping rules for real customers — and you'll do it through our AI harness, and help optimize it.
In practice that means driving the harness on live work: feeding it a vulnerability, judging what comes back, tightening the match, and validating it against real exploit traffic until it's something you'd put your name on.
Sometimes you'll write the expression yourself — the CVE with no public PoC, the emerging threat you have to reason out of a patch diff, the customer who needs coverage this afternoon. Most of the time you'll be applying expert judgment at every step of a generated rule's life, which is a different and harder skill than authoring from a blank page.
Because you'll be the harness's heaviest user, you'll also be the reason it gets better. You'll see exactly where it breaks down — the research step that missed the real sink, the composer that over-broadened, the judge that passed a rule it shouldn't have — and turn that into validations, analyses, and evals that go back into the agent. You'll work side by side with the Copilot & AI team so the agent stops making the mistake, instead of you catching it again next month. That feedback loop is the core of this role.
All of it rests on knowing where WAFs actually break: normalization and encoding evasion, parameter pollution, body-inspection size limits, oversize-content handling, rule precedence, and the gap between "the rule matched in staging" and "the rule holds against a motivated attacker." An AI can propose a rule. Knowing whether to trust it is the job.
What You'll Do
- Create - Produce production WAF rules across providers for high-impact CVEs and customer findings — driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
- **Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL — not just the vulnerable app.
- Validate - Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously — verifying against how the legitimate client actually behaves on the wire, not against an assumption.
- Monitor - Watch deployed rules in production: false-positive signals, hit patterns, coverage drift as managed rulesets shift underneath us, and the log→block promotion decision. Retire what no longer earns its capacity.
- Make it reproducible - Turn every finding into a regression test. Build and curate the golden CVE datasets and scoring rubrics that gate whether a new Copilot version ships.
- Set the coverage line. Judge which CVEs are genuinely WAF-mitigatable and which aren't, and make the call on what enters and leaves our managed rulesets — with the reasoning written down.
- Deep, hands-on WAF expertise across multiple major providers — you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" — written the rules.
- You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
- Strong security research background — application security, vulnerability research, or offensive security. You can read an advisory, build the PoC, derive the variants nobody published, and explain exactly which request component carries the exploit primitive.
- A real feel for the false-positive tradeoff. You've had to defend a blocking decision to someone whose production traffic you broke, and you know why "block everything suspicious" is not a security posture.
- Comfortable in code. Enough Python (or similar) to automate replay, build variant generators, and query exploit and traffic data yourself rather than waiting on someone.
- Fast under pressure, systematic afterward. You can get a solid rule out the door when a customer needs one today — and your instinct once it ships is to build the check that catches the whole class, not just the instance you fixed.
- Advantage: virtual patching / vulnerability-mitigation experience, or time on a WAF vendor's rules or research team.
- Advantage: hands-on with LLMs and agentic tooling — you'll be shaping an AI system's output, and it helps to understand how it fails.
You'll do the craft work you're actually good at — writing rules against hard vulnerabilities, under real time pressure, for customers who feel the difference. What's unusual is that here it compounds: every rule you write and every bypass you find makes an AI system permanently better at something an expert used to do by hand, across every customer and every future CVE. You get the individual save and the leverage over the whole fleet.
You'll have real authority over what we ship and what we refuse to ship, direct access to the engineers building the agent, and a rare seat at the point where security research and AI actually meet in production.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.