WAF / Akamai Security Engineer
allianceitNew York (NY)
About the role
WAF / Akamai Security Engineer
Location: NYC, NY or Alpharetta, GA – onsite 3 days a week
Job Description1. WAF Onboarding & Application Migration· Lead onboarding of internet-facing applications to Akamai WAF.· Work with application, DNS, load balancer, proxy, firewall, and QA teams to migrate applications into monitor/alert mode and ultimately deny mode.· Coordinate testing, rollout plans, traffic cutovers, validation, and rollback procedures.2. WAF Policy Tuning & False Positive Analysis· Analyze production traffic and WAF events to identify false positives.· Tune security policies to reduce business impact while maintaining strong protection.· Review blocked requests, investigate application behavior, and create narrowly scoped exceptions when justified.3. AI, LLM & API Security Support· Troubleshoot AI- and LLM-related traffic that triggers WAF protections, such as SQL injection controls.· Work with application teams and vendors to design compensating controls, header-based attestation mechanisms, and API-specific protections.· Evaluate emerging Akamai AI security capabilities, including AI-powered detections, Firewall for AI, bot identification, and agentic AI protections.4. Security Event Monitoring & Threat Analysis· Review WAF, Bot Manager, DDoS, Client Reputation, and API Security events.· Analyze attack patterns and determine whether activity is malicious or legitimate.· Recommend policy improvements and mitigations based on observed threats.5. Quarterly Security Reviews & Platform Upgrades· Conduct structured reviews of applications protected by Akamai.· Evaluate opportunities to move applications from monitoring to mitigation mode.· Perform quarterly WAF upgrades, policy reviews, and security-control tuning to keep protections aligned with current threat intelligence.6. Incident Response & Troubleshooting· Assist with production incidents where application behavior changes after WAF enablement.· Investigate latency issues, traffic-routing problems, load-balancer interactions, client IP handling, surge queue events, and application outages.· Coordinate with Akamai engineering resources and internal teams to identify root causes and corrective actions.7. Security Architecture & Design Consulting· Advise application teams on secure web architectures, OWASP protections, API security, bot mitigation, client reputation controls, and DDoS protection.· Provide guidance on best practices for onboarding, secure application design, and remediation of web vulnerabilities.8. Program Management & Stakeholder Engagement· Partner with application owners, infrastructure teams, auditors, risk managers, and security leadership.· Track onboarding progress, risks, dependencies, and remediation activities through program governance and ticketing systems.· Present status updates, metrics, risks, and remediation plans to senior management.9. Operational Metrics & Reporting· Produce dashboards and reporting covering:o WAF adoptiono Deny-mode coverageo Bot mitigation effectivenesso API discoveryo Security exceptionso Attack activity· Measure onboarding progress, control effectiveness, and risk reduction across the organization.10. Vendor Liaison & Technology Roadmap Guidance· Act as the primary interface between the enterprise and Akamai.· Engage Akamai product teams on product defects, enhancement requests, AI roadmap discussions, policy recommendations, and complex troubleshooting.· Evaluate new Akamai capabilities and coordinate pilot deployments where appropriate. Mandatory Experience· 5+ years of Akamai experience· Akamai Kona Site Defender· Akamai Bot Manager· Akamai API Security· OWASP Top 10· Incident response experience Preferred Experience· AI/LLM security· Akamai Firewall for AI· Enterprise-scale migration experience· Financial services experience
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
