Web Application Firewall Manager

Deloitte

  • Sydney, NSW Melbourne, VIC
  • Permanent
  • Full-time
  • 13 days ago
Job Requisition ID: 35718
  • Work in a highly innovative and transformative business
  • Mentoring, growth and training - receive support and coaching to progress your career
  • Preventive and supportive mental health initiatives
Deloitte Global is the engine of the Deloitte network. Our professionals reach across disciplines and borders to develop and lead global initiatives. We deliver strategic programs and services that unite our organization.What will your typical day look like?The Firewall Manager is responsible for the operations that fall under the Web Application Firewall Service in the APAC region and reports directly to the Service Owner. The candidate will have a strong background in cybersecurity and understanding of web application security practices. The individual will oversee and manage the deployment, configuration, and maintenance of our web application firewall systems for Global customers. This role requires expertise in collaborating with other teams, leadership to address/remediate identified security issues as well as provide status to leadership at multiple levels.Key Role Responsibilities:
  • Web Application Firewall Management: Oversea the deploy, configuration, tracking and maintenance of web application firewall systems to protect our web applications against potential threats and vulnerabilities.
  • Manage a team of WAF engineers that provide regional operational support to application owners.
  • Lead status updates, workshops, meetings, and report to senior leadership.
  • Manage and support WAF Security Incident Response: Monitor and analyze security events, alerts, and logs generated by the web application firewall systems. Investigate and respond to potential security incidents, working closely with the Security Operations Center (SOC) and Cybersecurity teams.
  • Oversee Detection and Analysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks within the WAF. Provides investigation findings to relevant business units to help improve information security posture.
  • Oversee Vulnerability Assessment: Utilize WAF data to identify potential vulnerabilities and recommend appropriate remediation measures to customers.
  • Create Documentation and Reporting: Maintain accurate documentation of WAF configurations, policies, and procedures. Prepare reports and metrics related to web application security, including trends, incident summaries, and mitigation strategies, as needed.
  • Collaboration and Training: Collaborate with cross-functional teams to ensure effective communication, knowledge sharing, and alignment of security objectives. Provide training and daily guidance to staff members on WAF best practices and security awareness.
  • Collaborate with key stakeholders and senior leaders such as CISOs, CIOs and directors within Cybersecurity, Engineering, and Development teams to create specific use cases to address business needs and security requirements.
  • Serve on teams and task groups for projects/initiatives within the business unit and/or across the organization.
About the team
Deloitte Technology works at the forefront of technology development and processes to support and protect Deloitte around the world. In this truly global environment, we operate not in "what is" but rather "what can be" to help Deloitte deliver and connect with its clients, its communities, and one another in ways not previously conceived.Enough about us, let's talk about you.
You are someone with:
  • Bachelor's Degree/University Degree and/or Undergraduate Diploma in Information Security, Information Technology, Computer Science, Engineering or equivalent years in experience
  • 10+ years with minimum 2 years into network security, 2 years in WAF experience and at least 2 years leading teams.
  • Strong knowledge of web application security concepts, OWASP Top 10 vulnerabilities, and related mitigation techniques.
  • Strong technical background with Akamai or Radware Web Application Firewall (WAF) technologies and bot mitigation security policies.
  • Proficiency in deploying and managing web application firewalls, preferably with experience in AKAMAI and RADWARE or similar tools.
  • Understanding of API security issues and API authentication.
  • Previous experience in a Security Operations Center (SOC) or performing cybersecurity analysis is highly desirable. Prior experience working with Splunk for security event management, log analysis, and threat detection.
  • Good understanding of information security principles and policy enforcement.
  • Solid comprehension of HTTP protocol and demonstrated ability to troubleshoot using HTTP logs
  • Strong technical background in web development and familiarity with potential attack vectors/methods
  • Understanding of DNS, Networks, Firewalls, SSL Certificates
Preferred:
  • Knowledge of Web Application Firewall technologies (Akamai and Radware)
  • Ethical hacking
  • ServiceNow experience
  • Technical documentation experience
  • Familiarity with cloud security services, concepts, and best practices
  • CISSP, CISM, CISA, GIAC or other security certifications are desired
  • Bi-lingual (Japanese a plus)
Why Deloitte?At Deloitte, we focus our energy on interesting and impactful work. We're always learning, innovating and setting the standard; making a positive difference to our clients and our society. We put coaching at the heart of what we do, helping our people grow their careers in any direction - whether it be up, moving into something new, or even moving across the world.We embrace diversity, equity and inclusion. We have a diverse collection of people from different backgrounds, with different experiences, gender identities, abilities and thinking styles. What binds us together is a shared commitment to value everyone's perspective and to cultivate inclusion; so that our work environment is a safe space we can all belong.We prioritise flexibility and choice. At Deloitte, you get trust on Day 1. We know our people get their best work done when they're in control of where and how they work, designing their work week around their client, team and personal commitments.We help you live and work well. To support your personal and professional life, we offer a range of , including retail discounts, wellbeing leave, paid volunteering days, twelve flexible working options, market-leading parental leave and return to work support package.Next Steps
Sound like the sort of role for you? Apply now.By applying for this job, you'll be assessed against the Deloitte Talent Standards. We've designed these standards so that you can grow in your career, and we can provide our clients with a consistent and exceptional Deloitte employee experience globally. The preferred candidate will be subject to background screening by Deloitte or by their external third-party provider.

Deloitte