HTTP/HTTPSTLS/SSLDNSTCP/IPREST APIsAkamai App & API Protector
Full Job Posting
Responsibilities
Configure, maintain, and support Web Application Firewall (WAF) protections using Akamai App & API Protector and related security technologies.
Monitor and investigate web security events involving: OWASP Top 10 vulnerabilities API attacks Bot traffic Credential stuffing DDoS attacks Layer 7 attacks Other suspicious or malicious web traffic
OWASP Top 10 vulnerabilities
API attacks
Bot traffic
Credential stuffing
DDoS attacks
Layer 7 attacks
Other suspicious or malicious web traffic
Assist with WAF policy tuning to reduce false positives while maintaining appropriate security protections.
Review application traffic and security logs to identify attack patterns, application behavior, and potential security concerns.
Support senior engineers during complex security investigations and production incidents.
Configure and maintain CDN and edge security configurations supporting internet-facing applications.
Work with Akamai technologies including: Property Manager Edge Hostnames Cloudlets DNS integrations Origin connectivity Caching and delivery configurations
Property Manager
Edge Hostnames
Cloudlets
DNS integrations
Origin connectivity
Caching and delivery configurations
Troubleshoot common CDN and web application issues involving: HTTP response codes Cache behavior DNS Routing Origin connectivity TLS/SSL Application availability
HTTP response codes
Cache behavior
DNS
Routing
TLS/SSL
Application availability
Support the onboarding of new websites and APIs onto the enterprise WAF/CDN platform.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Support the lifecycle management of public TLS certificates, including: Request validation Issuance Deployment Renewal Revocation Replacement
Request validation
Issuance
Deployment
Renewal
Revocation
Replacement
Monitor certificate inventories and upcoming expiration dates.
Coordinate certificate changes and renewals with application owners and other technical teams.
Validate certificates after deployment and troubleshoot common certificate, trust chain, DNS validation, and TLS issues.
Maintain accurate certificate ownership and lifecycle documentation.
Escalate certificate risks or renewal issues before they can impact production applications.
Monitor and investigate WAF alerts, application issues, and security events.
Analyze HTTP requests, response codes, headers, WAF logs, CDN logs, and other available telemetry to assist with troubleshooting and investigations.
Participate in incident response activities involving WAF, CDN, DDoS, certificates, and internet-facing applications.
Assist with troubleshooting customer-impacting production issues and determining whether issues originate from the security/CDN layer or another application component.
Implement approved mitigations and validate application functionality following security changes.
Follow established incident management, escalation, and change management processes.
Participate in the team's on-call rotation supporting globally distributed applications and services.
Identify repetitive operational activities that could benefit from automation.
Develop and maintain basic scripts and tools using technologies such as Python, PowerShell, Bash, or REST APIs.
Assist with improving security monitoring, reporting, inventory management, and operational dashboards.
Contribute to automation and standardization of application onboarding, WAF configuration, and certificate management processes.
Learn and adopt Infrastructure-as-Code and API-driven security management practices where appropriate.
Work closely with: Software Engineering Cloud Engineering Networking Infrastructure IAM Enterprise Architecture Compliance Security Operations
Software Engineering
Cloud Engineering
Networking
Infrastructure
IAM
Enterprise Architecture
Compliance
Security Operations
Partner with application teams during WAF/CDN onboarding, troubleshooting, security changes, and certificate activities.
Participate in technical discussions and architecture reviews alongside senior engineers.
Create and maintain technical documentation, troubleshooting guides, operational procedures, and runbooks.
Share knowledge and lessons learned with other members of the team.
Identify opportunities to improve existing processes and operational practices.
Follow established security standards, change management procedures, and operational processes.
Support PCI DSS and internal audit activities by gathering technical evidence and documentation.
Assist with periodic security reviews and control assessments.
Maintain accurate documentation for WAF configurations, certificates, application ownership, exceptions, and operational processes.
Support remediation activities identified through audits, vulnerability assessments, penetration testing, and security reviews.
Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or equivalent education and/or professional experience.
2–4+ years of experience in cybersecurity, networking, infrastructure, cloud engineering, application support, or a related technical field.
Foundational understanding of: HTTP/HTTPS TLS/SSL DNS TCP/IP Web applications REST APIs Reverse proxies and CDN concepts
HTTP/HTTPS
TLS/SSL
DNS
TCP/IP
Web applications
REST APIs
Reverse proxies and CDN concepts
Familiarity with Web Application Firewall technologies or web application security concepts.
Familiarity with common web security threats and the OWASP Top 10.
Experience troubleshooting technical issues using logs and other diagnostic information.
Ability to analyze technical problems and follow issues through resolution.
Strong written and verbal communication skills.
Ability and willingness to learn new security technologies and platforms.
Hands-on experience with Akamai or similar WAF/CDN platforms.
Experience with Akamai technologies such as: App & API Protector Property Manager Certificate Manager Edge DNS Cloudlets Bot Manager
App & API Protector
Property Manager
Certificate Manager
Edge DNS
Cloudlets
Bot Manager
Experience with public TLS certificate management.
Experience working with cloud environments such as AWS, Azure, or GCP.
Experience with SIEM or log analysis platforms such as Splunk, Sentinel, or similar technologies.
Basic scripting experience with Python, PowerShell, or Bash.
Experience working with REST APIs.
Familiarity with Git, Infrastructure-as-Code, or other DevOps practices.
Security certifications such as Security+, GSEC, Akamai certifications, or equivalent technical certifications.
Salary Range: $106,600 to $146,500 annually + bonus eligibility. This is the expected salary range for this position. Ultimately, in determining pay, we’ll consider the successful candidate’s location, experience, and other job-related factors.