Application Delivery-WAF Content Security Engineer
Malomatia
Visa & sponsorship
- Employers in Qatar sponsor the residence visa by default, and nothing in the posting says otherwise.
Job description
Own end-to-end application delivery, global traffic management, Web Application Firewall (WAF), and content/file threat protection across F5 BIG-IP (LTM & Advanced WAF), F5 GTM, FortiWeb WAF, and OPSWAT. Responsible for traffic steering, SSL/TLS lifecycle, high availability, API/bot protection, file-based threat triage, and automation of infrastructure delivery.
-
Configure and manage F5 BIG-IP LTM: virtual servers, pools, health monitors, persistence profiles, and traffic steering.
-
Administer F5 GTM for global DNS-based load balancing, south-north traffic steering, private DNS integration, and pool/health monitor management.
-
Own SSL/TLS lifecycle across the app delivery stack: offloading, certificate management, SSL profiles, and TLS hardening on F5 and FortiWeb tiers.
-
Design and maintain High Availability: device clustering, config sync, failover, and resiliency across F5 platforms.
-
Manage Web Application Protection: OWASP Top 10 profiles, custom security policies, signature management, API protection, bot mitigation, rate limiting, and IP intelligence (F5 Advanced WAF, FortiWeb).
-
Tune attack detection policies, manage signature updates, and reduce false positives across WAF platforms; build custom attack signatures where required.
-
Lead BIG-IP and FortiWeb appliance/VE deployment, provisioning, TMOS/firmware upgrades, hotfixes, backup/restore, and configuration lifecycle management.
-
Integrate FortiWeb with OCI Load Balancer and other cloud LB services for L7 inspection.
-
Manage OPSWAT file scanning platform for Data-in-Transit and Data-at-Rest content inspection; triage, analyze, and action file scan results, including false-positive review.
-
Maintain scanning policies and workflows to support secure file transfer and content-handling processes across the organization.
-
Drive Infrastructure Automation using REST API, AS3, Terraform, and Ansible for automated configuration deployment.
-
Perform health/performance monitoring, logging, analytics, and root-cause analysis; own vulnerability assessment, hardening, and patch compliance for all app-delivery and content-security assets.
Required Qualifications & Experience
-
Bachelorโs degree in computer science, Information Security, or related field.
-
8+ years' experience with F5 BIG-IP (LTM/GTM/Advanced WAF) and/or FortiWeb in enterprise production environments.
-
Experience with content disarm & reconstruction (CDR) / multi-scanning platforms (OPSWAT or equivalent) is highly desirable.
-
Working knowledge of infrastructure-as-code and automation (Terraform, Ansible, REST API/AS3).
-
Certifications preferred: F5 Certified BIG-IP Administrator (F5-CA), F5 301a/302 (Advanced WAF), NSE 6 (FortiWeb).
-
Strong understanding of DNS, SSL/TLS, Layer 4โ7 traffic management, and file-based threat triage.