1 день назад
Web Service Protection Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Web Service Protection Engineer (Cybersecurity): Building and operating protection metrics, alerting pipelines, and edge security controls for high-volume web services serving millions of daily requests with an accent on traffic analysis, WAF policies, rate limiting, and hybrid cloud infrastructure. Focus on identifying scraping, abuse, DDoS, and attack patterns, tuning mitigation rules, and responding to incidents across cloud and on-premises environments.
Location: Full-time onsite at NCBI in Bethesda, Maryland, United States
Company
provides professional services and technology support for the National Center for Biotechnology Information at the National Institutes of Health.
What you will do
- Develop protection metrics, dashboards, and alerting pipelines for network and application-layer anomalies.
- Analyze logs and traffic patterns across millions of daily requests to identify overuse, scraping, abuse, DDoS activity, and attacks.
- Operate and tune cloud-based edge security controls, including security policies, WAF capabilities, rate limiting, and adaptive protection rules.
- Apply traffic mitigation strategies while minimizing disruption to legitimate users.
- Monitor incidents, triage threats, resolve issues, and escalate actionable findings to development or systems administration teams.
- Extend protection consistently across cloud and on-premises infrastructure.
Requirements
- Strong understanding of high-volume web service architecture, traffic flows, bottlenecks, abuse vectors, load balancers, and edge routing.
- Hands-on experience with a major cloud provider’s security and networking stack, including global load balancing, traffic management, edge security policies, WAF, log querying, and metric-driven alerting.
- Solid knowledge of HTTP/HTTPS internals, headers, TLS behavior, connection patterns, traffic analysis, and fingerprinting.
- Experience analyzing network- and application-layer signals, including address-based, organizational, and transport-layer fingerprints.
- Familiarity with web server platforms, log formats, configuration, access control, and rate-limiting rules.
- Ability to work across hybrid cloud and on-premises infrastructure environments.
Nice to have
- Experience with advanced abuse mitigation, traffic redirection, and challenge-response mechanisms.
- Scripting or automation experience with Python, Bash, or similar tools for log parsing and rule generation.
- Experience protecting high-traffic government or research platforms.
- Knowledge of behavioral bot detection, fingerprinting, headless browser detection, and evolving scraper and attacker techniques.
Culture & Benefits
- Medical, dental, and vision coverage.
- 401(k) plan with employer contribution.
- Paid holidays and vacation.
- Tuition reimbursement.
- Professional, high-performing, technology-focused work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
20 часов назад
Response Engineer - CMDC (Cybersecurity)
5 часов назад
Cybersecurity Engineer (SIEM)
19 часов назад
Senior Professional Services Engineer (Application Security)
21 час назад
Cybersecurity Engineer
80 000 - 100 000$
2 дня назад
DevSecOps Security Engineer (AWS)
21 час назад