Engineer - Application Delivery & Security

منذ 3 أيام

Doha Qatar, DA Malomatia دوام كامل
Own end-to-end application delivery, global traffic management, Web Application Firewall (WAF), and content/file threat protection across F5 BIG-IP (LTM & Advanced WAF), F5 GTM, FortiWeb WAF, and OPSWAT. Responsible for traffic steering, SSL/TLS lifecycle, high availability, API/bot protection, file-based threat triage, and automation of infrastructure delivery.
- Configure and manage F5 BIG-IP LTM: virtual servers, pools, health monitors, persistence profiles, and traffic steering.
- Administer F5 GTM for global DNS-based load balancing, south-north traffic steering, private DNS integration, and pool/health monitor management.
- Own SSL/TLS lifecycle across the app delivery stack: offloading, certificate management, SSL profiles, and TLS hardening on F5 and FortiWeb tiers.
- Design and maintain High Availability: device clustering, config sync, failover, and resiliency across F5 platforms.
- Manage Web Application Protection: OWASP Top 10 profiles, custom security policies, signature management, API protection, bot mitigation, rate limiting, and IP intelligence (F5 Advanced WAF, FortiWeb).
- Tune attack detection policies, manage signature updates, and reduce false positives across WAF platforms; build custom attack signatures where required.
- Lead BIG-IP and FortiWeb appliance/VE deployment, provisioning, TMOS/firmware upgrades, hotfixes, backup/restore, and configuration lifecycle management.
- Integrate FortiWeb with OCI Load Balancer and other cloud LB services for L7 inspection.
- Manage OPSWAT file scanning platform for Data-in-Transit and Data-at-Rest content inspection; triage, analyze, and action file scan results, including false-positive review.
- Maintain scanning policies and workflows to support secure file transfer and content-handling processes across the organization.
- Drive Infrastructure Automation using REST API, AS3, Terraform, and Ansible for automated configuration deployment.
- Perform health/performance monitoring, logging, analytics, and root-cause analysis; own vulnerability assessment, hardening, and patch compliance for all app-delivery and content-security assets.
- Bachelor’s degree in computer science, Information Security, or related field.
- 8+ years' experience with F5 BIG-IP (LTM/GTM/Advanced WAF) and/or FortiWeb in enterprise production environments.
- Experience with content disarm & reconstruction (CDR) / multi-scanning platforms (OPSWAT or equivalent) is highly desirable.
- Working knowledge of infrastructure-as-code and automation (Terraform, Ansible, REST API/AS3).
- Certifications preferred: F5 Certified BIG-IP Administrator (F5-CA), F5 301a/302 (Advanced WAF), NSE 6 (FortiWeb).
- Strong understanding of DNS, SSL/TLS, Layer 4–7 traffic management, and file-based threat triage. ## Technical Skills Matrix Load Balancing
- LTM Configuration & Traffic Management —Virtual Servers, Pools, Health Monitors, Persistence, Traffic Steering
- SSL/TLS Management —SSL Offloading, Certificate Management, SSL Profiles, TLS Hardening
- High Availability —Device Clustering, Config Sync, Failover, Resiliency Management
- Global Traffic Management (F5 GTM) —DNS/GSLB, Global Load Balancing, Site Failover, Health Monitoring
- South-North Traffic Steering —Load balancing for south-north traffic flows
- Private DNS Integration —Private DNS management via F5 GTM
- OCI LB Integration (FortiWeb) —OCI Load Balancer integration with FortiWeb for L7 inspection WAF
- Web Application Protection —OWASP Top 10 Protection, Security Policies, Signature Management
- API & Bot Protection —API Security, Bot Mitigation, Rate Limiting, IP Intelligence
- Attack Detection & Policy Tuning —Attack Signature Updates, False Positive Tuning, Custom Policies/Signatures
- FortiWeb WAF — OWASP Top 10 —OWASP Top 10 protection profiles
- Bot Detection & Mitigation —Bot detection, geo-blocking, IP reputation management (FortiWeb)
- SSL/TLS Offloading (FortiWeb) —SSL/TLS offloading, deep inspection, OCI LB integration NVA Management
- Deployment & Lifecycle —BIG-IP / FortiWeb appliance / VE deployment, provisioning & lifecycle
- Patch & Operations —TMOS/firmware upgrades, hotfixes, backup/restore, config management Content Security
- OPSWAT File Scanning Management —File scanning for Data-in-Transit and Data-at-Rest
- Triage & Analysis —Triage and analysis of file scan results, false-positive review Security Operations
- Vulnerability Remediation —Vulnerability assessment, hardening, patch & security compliance Monitoring & Logs
- Monitoring & Troubleshooting —Health/performance monitoring, logging, analytics, RCA Automation
- Infrastructure Automation —REST API, AS3, Terraform, Ansible, automated configuration deployment