Job Closed
This listing is no longer active.
Web Application Security Engineer
Location
Florida
Posted
147 days ago
Salary
$115K - $120K / year
Seniority
Senior
Job Description
Web Application Security Engineer
Ryder System, Inc.
• Lead the onboarding of web applications into a CDN, ensuring proper security policy integration and optimized delivery • Manage WAFs deployed on-premises, in the cloud, or in hybrid environments, including those co-managed with external service providers • Configure, maintain, and tune WAF rules to protect against web application threats, including OWASP Top Ten risks • Set up and execute DAST scans on web applications to identify vulnerabilities in runtime environments, validate WAF coverage, and provide actionable remediation guidance • Collaborate with development, infrastructure, and SOC/IR teams to ensure findings are triaged, addressed, and documented • Monitor application traffic and threat activity, leveraging automation and analytics to detect and respond to anomalies • Perform continuous testing and tuning of WAF policies based on threat intelligence, logs, and scan results • Contribute to incident response efforts related to application-layer attacks and vulnerabilities • Develop and maintain documentation related to WAF policies, scan results, application mappings, and remediation plans
Job Requirements
- Bachelor's degree in computer science, Information Security, or a related field
- 5 years or more experience with WAF technologies (Akamai Kona, Azure App Gateway, Cloudflare)
- 7 years or more experience with DAST tools such as Burp Suite and enterprise scanning platforms such as InsightAppSec
- 5 years or more Proficiency with applications, databases, web services, authentication and middleware servers
- 5 years or more Aptitude with one or more scripting languages (e.g., Python, PowerShell, Bash)
- 5 years or more Proven experience in diagnosing, isolating, resolving complex issues and recommending/implementing strategies to resolve problems
- 5 years or more Understanding of OWASP Top Ten, threats and vulnerabilities, and tactics used to compromise applications
- 5 years or more Skilled in analyzing logs to identify and interpret attack patterns accurately
- Hands-on experience with CDN platforms and integration of security policies within those services
- Advanced understanding of web application security, including common attack vectors and secure design principles
- Knowledge of CI/CD pipelines and integration of security testing tools
- Strong troubleshooting skills of web application client and server technologies, forward and reverse proxies, static content caching, DNS, etc
- Experience in risk management findings, vulnerability prioritization, threat modeling, and mitigation strategy
- CISSP, OSCP, OSWE, or other industry-leading certifications
Benefits
- comprehensive health and welfare benefits
- medical, prescription, dental, vision, life insurance and disability insurance options
- paid time off for vacation, illness, bereavement, family and parental leave
- tax-advantaged 401(k) retirement savings plan
Related Guides
Related Categories
Related Job Pages
More Application Engineer Jobs
SaaS Application Engineer
ShopwareMade in Germany, built for global leadership. The ecommerce platform that drives results.
• You improve the scalability, maintainability, and performance of our SaaS application • You design and develop features that expand the functionality and usability of our SaaS product • You work hands‑on with PHP (Symfony) and Shopware to identify and resolve bottlenecks • You continuously evolve our multi‑tenant SaaS stack on cloud infrastructure • You analyze and optimize containers used for the deployment and operation of Shopware • You implement and improve observability solutions (e.g., OpenTelemetry, Datadog) to gain better insights and increase reliability • You work closely with cross‑functional teams to align technical solutions with product goals • You analyze and resolve customer issues and ensure stable operation and high availability • You take ownership of services and drive improvements across the entire SaaS platform
Senior Applications Engineer – Control and Automation
Mainspring EnergyPowering the new energy landscape
• Design, configure, and maintain automation project files for complex energy projects. You will manage control implementation for customer specific applications such as grid-parallel operation, islanding transitions, blackstart coordination, and peak shaving • Create and modify Sequence of Operations (SOO) procedures to meet project specifications and requirements • Author Site Acceptance Testing (SAT) procedures to demonstrate the proper implementation and function of the system after deployment • Partner with the field commissioning team to support startup and testing activities. You will be the escalation point for complex control, networking, and integration issues through Commercial Operation • Serve as a technical advisor for internal teams building out code base improvements and expanded generator controls functionality • Ensure comprehensive documentation of control designs, IP addressing schemes, and logic modifications to facilitate a smooth handover to our Fleet Operations team for long-term maintenance • Anticipate and communicate project risks related to generator control deployment and contributes meaningful mitigation strategies
• Architect and implement secure AWS configurations (IAM roles/policies, encryption keys, VPC segmentation) • Embed security into CI/CD pipelines and repos using policy-as-code tools (pre-commit hooks, SAST/SCA, IDE tool integrations) • Secure container and orchestration environments (EKS, Kubernetes, Docker) per best practices • Conduct threat modeling sessions and risk‑driven design reviews early in development • Perform secure code reviews and static/dynamic analysis; oversee remediation with dev teams • Automate repetitive security tasks—vulnerability triage, code scanning, tool orchestration • Build and extend in-house AppSec automation frameworks or pentest tooling • Partner with security architecture and detection teams (SIEM tuning, logging, telemetry alignment) • Develop and enforce AppSec standards and patterns across product teams; iterate through feedback loops • Support regulatory or compliance assessments (PCI, CCPA, GLBA) as needed
• Lead, mentor, and manage a team of application engineers, Salesforce developers, and front-end developers. • Partner with Product Owners, Scrum Masters, and QA teams to plan and deliver product releases using Agile methodology. • Oversee sprint velocity, resource allocation to ensure on-time, on-budget delivery. • Direct development efforts across Salesforce (Sales, Service, and Commerce Cloud), including APEX, LWC, and API integrations. • Architect, design, and maintain headless and composable experiences leveraging Next.js, React, and Salesforce Commerce Cloud D2C. • Ensure seamless integration between Sitecore, Salesforce, and back-end .NET and Azure-based APIs. • Oversee CI/CD pipelines, infrastructure automation, and deployment processes through Azure DevOps. • Act as a key leader in Agile ceremonies (sprint planning, retrospectives, backlog grooming, etc.). • Manage project scope, risks, and dependencies; escalate issues proactively with solution-oriented recommendations. • Collaborate with business stakeholders, architects, and infrastructure teams to define and deliver enterprise-grade digital experiences.




