our company's WAF Copilot takes a freshly disclosed CVE and produces a validated, provider-specific WAF rule - researching the vulnerability, deriving the attack surface, composing the rule, then attacking its own output with an independent bypass judge and a false-positive prober before a human is offered a deploy.
As WAF Security Specialist you are the ground truth the Copilot is measured against - the person who can look at a generated rule and say this blocks the PoC but not the four obvious variants, this will trip on legitimate multipart uploads, this is 340 WCUs of nothing because the managed ruleset already catches it, this can't be anchored tightly enough to live in a global Web ACL.
You'll be shipping rules for real customers - and you'll do it through our AI harness, and help optimize it.
In practice that means driving the harness on live work: feeding it a vulnerability, judging what comes back, tightening the match, and validating it against real exploit traffic until it's something you'd put your name on.
Sometimes you'll write the expression yourself - the CVE with no public PoC, the emerging threat you have to reason out of a patch diff, the customer who needs coverage this afternoon. Most of the time you'll be applying expert judgment at every step of a generated rule's life, which is a different and harder skill than authoring from a blank page.
Because you'll be the harness's heaviest user, you'll also be the reason it gets better. You'll see exactly where it breaks down - the research step that missed the real sink, the composer that over-broadened, the judge that passed a rule it shouldn't have - and turn that into validations, analyses, and evals that go back into the agent. You'll work side by side with the Copilot & AI team so the agent stops making the mistake, instead of you catching it again next month. That feedback loop is the core of this role.
All of it rests on knowing where WAFs actually break: normalization and encoding evasion, parameter pollution, body-inspection size limits, oversize-content handling, rule precedence, and the gap between "the rule matched in staging" and "the rule holds against a motivated attacker." An AI can propose a rule. Knowing whether to trust it is the job.
What You'll Do
Create - Produce production WAF rules across providers for high-impact CVEs and customer findings - driving the Copilot harness on most of them, writing the expression yourself on the hard ones (no public PoC, exploitable path reasoned out of a patch diff, urgent customer coverage). Your rules ship, and they set the bar generated rules are measured against.
**Optimize -**Tighten generated rules for real production constraints: WCU and rule-capacity budgets, latency, provider expression limits, and the anchoring required for a rule that fires against all traffic behind a shared Web ACL - not just the vulnerable app.
Validate - Own the adversarial pass. Build exploit variants the PoC doesn't cover, hunt bypasses in our own rules, and run the false-positive side seriously - verifying against how the legitimate client actually behaves on the wire, not against an assumption.
Requirements: Deep, hands-on WAF expertise across multiple major providers - you've written, tuned, and operated real rules in production on several of: AWS WAFv2, Cloudflare, F5, Imperva, Akamai, Azure, GCP, Fortinet, ModSecurity/CRS. Not "managed a WAF vendor relationship" - written the rules.
You know the caveats cold. Body-inspection limits and oversize handling, text transformations and normalization order, encoding and unicode evasion, parameter pollution, chunked and multipart edge cases, rule precedence and evaluation order, WCU/capacity economics, and how each provider's expression language quietly differs from the others.
This position is open to all candidates.