עדיין מחפשים עבודה במנועי חיפוש? הגיע הזמן להשתדרג!
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
What You'll Do:
Create - Produce production WAF rules across providers for high-impact CVEs and customer findings - driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL - not just the vulnerable app.
Validate - Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously - verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Monitor - Watch deployed rules in production: false-positive signals, hit patterns, coverage drift as managed rulesets shift underneath us, and the log→block promotion decision. Retire what no longer earns its capacity.
Make it reproducible - Turn every finding into a regression test. Build and curate the golden CVE datasets and scoring rubrics that gate whether a new Copilot version ships.
Set the coverage line. Judge which CVEs are genuinely WAF-mitigatable and which aren't, and make the call on what enters and leaves our managed rulesets - with the reasoning written down.
Deep, hands-on WAF expertise across multiple major providers - you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" - written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
Strong security research background - application security, vulnerability research, or offensive security. You can read an advisory, build the PoC, derive the variants nobody published, and explain exactly which request component carries the exploit primitive.
A real feel for the false-positive tradeoff. You've had to defend a blocking decision to someone whose production traffic you broke, and you know why "block everything suspicious" is not a security posture.
Comfortable in code. Enough Python (or similar) to automate replay, build variant generators, and query exploit and traffic data yourself rather than waiting on someone.
Fast under pressure, systematic afterward. You can get a solid rule out the door when a customer needs one today - and your instinct once it ships is to build the check that catches the whole class, not just the instance you fixed.
Advantage: virtual patching / vulnerability-mitigation experience, or time on a WAF vendor's rules or research team.
Advantage: hands-on with LLMs and agentic tooling - you'll be shaping an AI system's output, and it helps to understand how it fails.
במקום לעבור לבד על אלפי מודעות, Jobify מנתחת את קורות החיים שלך ומציגה לך רק משרות שבאמת מתאימות לך.
מעל 80,000 משרות • 4,000 חדשות ביום
חינם. בלי פרסומות. בלי אותיות קטנות.
אונליין
תל אביב - יפו