WAF Adversarial Engineer

Mindlance
  • Seattle, WA
  • $71.42 Per Hour
  • Quick Apply
30+ days ago

Job Description

Reason: Increase Capacity
Department: 890 - Start-up Web App Firewall
Job Category: Engineering
Job Title: WAF Adversarial Engineer
Duties:
Run adversarial test campaigns against Adobe's WAF stack (Akamai, AWS WAF, Fastly, and Cloudflare) after each rule update cycle.
Target encoding evasion, HTTP parsing differentials between WAF and origin, request smuggling, chunked encoding manipulation, multipart boundary abuse, Unicode normalization gaps, and logic layer bypasses.
Build and maintain a versioned WAF bypass library, organized by vulnerability class (SQLi, XSS, SSRF, path traversal, SSTI, etc.), validated against staging and production WAF configurations, and updated as platforms and rules evolve.
Conduct adversarial testing of API endpoints behind the WAF, including business logic abuse, BOLA/BFLA, mass assignment, and parameter manipulation. Document explicitly which classes of attack the WAF can and cannot reliably cover.
Triage complex false positive investigations that cannot be resolved through log analysis alone — reproduce the ambiguous traffic from the attacker side and recommend targeted rule adjustments.
Produce concise validation reports that translate offensive findings into testable rule candidates the team can refine and deploy. Each deliverable is a reproducer plus a rule recommendation, not a "bypass confirmed" note.
Provide adversarial perspective during active edge incidents — likely attacker behavior, blind spots, next probable moves.
Operate as the continuous validation function for the WAF program, integrated with the team's rule update cadence rather than running standalone pentest engagements.

Skills:
Demonstrated WAF bypass experience against at least two commercial WAF platforms (Akamai, AWS WAF, Fastly, or Cloudflare).
Deep working knowledge of HTTP protocol edge cases that affect WAF inspection: request smuggling primitives, chunked transfer encoding abuse, multipart boundary manipulation, Unicode normalization differentials, and header injection patterns.
Web application penetration testing track record with WAF-specific scope. OSCP, BSCP, OSWE, or a portfolio of disclosed bypasses, conference talks, or prior validation engagements against WAF-protected assets. Tool-running alone does not qualify. - Proven ability to translate offensive findings into defensive artifacts — reproducer plus rule candidate, not just a finding.
Strong scripting in Python or Go for building test harnesses, payload generators, and replay tooling.
Comfortable working in CI/CD pipelines and cloud environments (AWS or Azure). Plug into existing infrastructure rather than build it.Preferred:
API-specific attack surface depth: GraphQL injection, BOLA/BFLA, mass assignment.
Akamai platform internals: KRS / ASE rule engine, custom Lua / EdgeWorkers exposure.
Bot evasion at the behavioral layer: headless browser fingerprinting bypass, behavioral mimicry.
Familiarity with edge-layer LLM/GenAI guardrails (OWASP LLM Top 10, prompt injection mitigation at the WAF tier).
Public security research, CVE disclosures, or conference talks demonstrating original bypass work.

Keywords:
Education: Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related technical field, or equivalent demonstrated experience.


“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”

Numbers & Facts

LocationSeattle, WA
Salary$71.42 Per Hour

Skills

  • (XSS) Cross Site Scriptingunmatched
  • ASEunmatched
  • Adobe Product Familyunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Cadenceunmatched
  • Campaignsunmatched
  • Cloud Computingunmatched
  • Computer Engineeringunmatched
  • Computer Scienceunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Firewallsunmatched
  • HTTP (HyperText Transport Protocol)unmatched
  • Information/Data Security (InfoSec)unmatched
  • Injectionsunmatched
  • Internet Applicationunmatched
  • Luaunmatched
  • Machine Toolunmatched
  • Microsoft Windows Azureunmatched
  • Organizational Skillsunmatched
  • Python Programming/Scripting Languageunmatched
  • Scripting (Scripting Languages)unmatched
  • Startupunmatched
  • Test Harnessunmatched
  • Testingunmatched
  • Theater Productionunmatched
  • Unicodeunmatched
  • Web Browsersunmatched
  • Wheel/Front-End Loaderunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder