AGÕæÈ˰ټÒÀÖ

Onsite
Full Time
Save Job

Job Type

Full Time

Job Details

Job Description

Candidate will develop, support, tune and deploy security solutions across Visa.

Ìý

Essential Functions:

  • WebÌýApplication Security: Engineering, deployment, and operations of security solutions, including Web Application Firewalls, as well as integration of those platforms with other solutions as required.Ìý

  • Security Software Development: Scripting and Development inÌýPython, ShellÌýscripting and development in other languages.

  • Engineers, configures, deploys, and maintains Web Application Firewall solutionsÌý

  • Develops scripts for manipulation of multiple data repositories to support analysts

  • Develops alerts/reports to meet the requirements of key stakeholdersÌý

  • Develops automation for security tools management and workflow integrationÌý

  • Collaboration with key stakeholders within Cybersecurity Engineering teams to develop specific use cases to address web and application security requirements

  • Creates WAF rules to mitigate threats and implement security best practicesÌý

  • Develop and enhance SIEM content for CybersecurityÌýteams,ÌýincludingÌýcorrelations, enrichments, dashboards, reports, and alerts that appropriately illustrate and characterize web application attacks and mitigation mechanismsÌý

Ìý

Application Security:Ìý

  • Knowledge of SSDLC processes, procedures, and tools

  • Knowledge of open source and commercial application security tools and frameworks, including but not limited to Kali Web application testing toolsÌý

  • Experience in exploiting web apps and web services security vulnerabilities including cross-site scripting, cross-site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks

  • Excellent understanding of OWASP Risks, Vulnerabilities and Mitigation MechanismsÌý

  • Strong experience with Web Application Firewall management and rulesÌý

  • Excellent understanding of common network and web protocolsÌý

  • Excellent understanding of DDoS, Bot, and ATO techniques and mitigation mechanismsÌý

Cyber Defense and Incident Response:Ìý

  • Solid understanding of events, related fields in log records and alerts reported by various data sources such as Windows/Unix systems, IDS/IPS, AV, HIDS/HIPS, WAFs, firewalls, and web proxiesÌý

  • Prior experience or support of Security Operations and Incident Response

  • Excellent understanding of Cyber Security Operations and Incident Response processesÌý

Infrastructure management and support:Ìý

  • System administration experience with Windows and Unix serversÌý

  • Experience working in a large enterprise environmentÌý

  • Experience integrating solutions in a multi-vendor environmentÌý

  • Familiarity with Atlassian JIRAÌý

Ìý

This is a hybrid position. Hybrid employees can alternate time between both remote and office. Employees in hybrid roles are expected to work from the office 2-3 set days a week (determined by leadership/site), with a general guidepost of being in the office 50% or more of the time based on business needs.


Qualifications

Basic Qualifications:
�5+ years of relevant work experience with a Bachelor’s Degree or at least 2 years of work experience with an Advanced degree (e.g. Masters, MBA, JD, MD) or 0 years of work experience with a PhD, OR 8+ years of relevant work experience.

Preferred Qualifications:
� 6 or more years of work experience with a Bachelor’s Degree or 4 or more years of relevant experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or up to 3 years of relevant experience with a PhD
� Experience with one or more: Akamai, AWS Cloudfront, Cloudflare, or other CDN solutions
� Experience with one or more of the following: Imperva WAF, F5 WAF, and CDN Firewall
� Experience with API Security solutions such as Imperva API Anywhere, Cloudflare API Shield, or other similar solutions.
� Web Application Firewall Experience (Must have), Experience with one or more of the following:
- SecDevOps Experience:
� Expertise in one or more of the following: Python, Perl, shell scripting, C++, Java, Java Script
� Excellent experience in creating Regular Expressions for security polices and rules
� Experience in maintaining and enhancing infrastructure as code with one or more of the following: CloudFormation, Terraform, Chef, Puppet, Jenkins, CodeDeploy
� Experience with using knowledge management and code repositories with Github, Gitlab, Jira, and Confluence
� Experience with Lambda, API Gateway
� Experience with API Security solutions such as Imperva API Anywhere, Cloudflare API
Shield, or other similar solutions.


Additional Information

Visa is an EEO Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with EEOC guidelines and applicable local law.


Mission
We're connecting diverse talent to big career moves. Meeting people who boost your career is hard - yet networking is key to growth and economic empowerment. We’re here to support you - within your current workplace or somewhere new. Upskill, join daily virtual events, apply to roles (it’s free!).
Are you hiring? Join our platform for diversifiying your team
Sr. Cybersecurity Engineer - Web Application Firewall
Save Job