Edge and API Security Lead
Job Description
Staff Security Engineer - Edge& API Security Lead
Summary:
Key member of the Security team, this role focuses on implementing and managing security controls for web applications, APIs, and edge infrastructure. The Lead Security Engineer will leverage Cloudflare platform and other edge security solutions to protect against DDoS attacks web application threats, bot attacks, API vulnerabilities andAI threats. Thisrole demands strongtechnical expertise in web application firewalls (WAF), DDoS mitigation, bot management, API security, and content delivery network (CDN) security, with the ability to architect and implement scalable protection mechanisms for internet facing applications and services.
EssentialDuties and Responsibilities
• Oversee the design, implementation, and management of Cloudflare security services (WAF, DDoS Protection, Bot Management, API Shield, Rate Limiting) to safeguard web applications and APIs.
• Establish and document security standards and best practices for edge security, CDN usage, and SSL/TLS management across the organization.
• Collaborate with application development, cloud engineering, and DevOps teamsto integrate security controls into all web applications and API gateways.
• Design and manage AI Gateways to optimize globaledge security and real-time observability.
• Lead the design andimplementation of Layer3/4 firewall tunneling strategy to secureand optimize hybridcloud connectivity.
• Drive the security assessment and hardening of edge security architectures, proactively identifying vulnerabilities in edge-side logic, global API endpoints, and WAF configurations.
• Oversee edgesecurity automation to deploy real-time custom mitigation logicand automated incident response.
Qualifications Expected for Position
• 6+ years of experience in information security with focus on application security, web security, or network security.
• 3+ years of experience with DDoS protection and mitigation strategies for application-layer and network-layer attacks.
• 2+ yearsof hands-on experience with web application firewalls (WAF), APIand AI gateways, including rule development, tuning, and attack mitigation.
• Strong understanding of web application security principles, OWASPTop 10, andcommon attack vectors.
• Experience withCDN platforms andedge security services for protecting internet-facing applications.
• Proficiency with HTTP/HTTPS protocols, SSL/TLS, DNS, and web application architectures.
• Experience analyzing web traffic patterns, logs, and security events to identify threats and tunesecurity controls.
PreferredQualifications
• Demonstrated success implementing WAF and edge security at scale in high trafficenvironments.
• Extensive experience with Cloudflare security tools, including Web Application Firewall (WAF) and DDoS Protection.
• Proficient in Cloudflare BotManagement to identify and block automated threats.
Job Description
• Skilled in implementing API Shield, API Gateways for secure API access and protection
• Knowledge of API security best practices including OAuth, JWT, APIauthentication/authorization, and schema validation.
• Experience with GraphQL security and protection mechanisms.
• Experience implementing security headers (CSP,HSTS, X-Frame-Options) andcookie security.
• Proficiency withscripting and automation for security rulemanagement (JavaScript, Python).
• Familiarity withInfrastructure as Codefor edge security configuration (Terraform, CloudFormation).
• Relevant certifications such as CISSP,CEH, GWAPT (GIACWeb Application Penetration Tester), OSCP, or cloud security certifications.
