Application Security Engineer (SOC/CSIRT /WAF/Firewall/Appsec)

Application Security Engineer (SOC/CSIRT /WAF/Firewall/Appsec)

Posted 4 days ago by GIOS Technology

£63 Per hour
Undetermined
Remote
England, United Kingdom

Summary: The Application Security Engineer role focuses on enhancing security measures within a remote setting, requiring occasional office visits. Candidates should possess extensive experience in SOC, CSIRT, or Threat/Forensics roles, with a strong grasp of web application security and WAF management. The position demands proficiency in log analysis tools and the ability to communicate complex security concepts effectively. Ideal candidates will also have experience in AppSec, DevSecOps, or Ethical Hacking.

Key Responsibilities:

  • Analyze security logs to differentiate between true and false positives.
  • Manage, tune, and engineer Web Application Firewalls (WAFs).
  • Utilize log analysis tools such as Splunk and Wireshark.
  • Communicate complex security concepts to technical and non-technical stakeholders.
  • Demonstrate expertise in web application attacks and OWASP Top 10.

Key Skills:

  • Experience in SOC, CSIRT, or Threat/Forensics roles.
  • Proficiency with WAF vendors (e.g., Akamai, F5, AWS, GCP).
  • Knowledge of AppSec, DevSecOps, or Ethical Hacking.
  • Strong communication skills.
  • Security engineering skills.

Salary (Rate): £62.50/hr

City: undetermined

Country: United Kingdom

Working Arrangements: remote

IR35 Status: undetermined

Seniority Level: undetermined

Industry: IT

Detailed Description From Employer:

We are hiring for Application Security Engineer (SOC/CSIRT /WAF/Firewall/Appsec) Location : Remote with Occasional Office Visits Proven experience in a SOC, CSIRT, or Threat/Forensics role, with expertise in analyzing security logs to quickly distinguish between true and false positives. A strong understanding of web application attacks, the OWASP Top 10, and common evasion techniques. Ideally, you'll have experience in AppSec, DevSecOps, or Ethical Hacking. Extensive experience managing, tuning, and engineering WAFs, with hands-on proficiency with at least three major WAF vendors (e.g., Akamai, F5, AWS, GCP). Proficiency with log analysis tools like Splunk and Wireshark. Security engineering skills are a bonus. Excellent communication skills to articulate complex security concepts to both technical and non-technical stakeholders. Key Skills : Application Security Engineer (SOC/CSIRT /WAF/Firewall/Appsec / SIEM / Splunk)