Administrateur Sécurité WAF
Job description
About the role
Citech is looking for an Administrateur Sécurité WAF to strengthen their security operations in Paris. This role centers on the administration and oversight of web application firewall systems that safeguard digital infrastructure from external threats and unauthorized access. The position requires a detail-oriented professional capable of managing WAF configurations, analyzing security alerts, and collaborating with cross-functional teams across the organization. The administrator will ensure that web applications remain protected against evolving threats and vulnerabilities while supporting the broader security goals of the company. The company values security excellence and provides a supportive environment for professional growth and development.
Key facts
What you'll do
- Configure and maintain web application firewall rules to block malicious traffic patterns and unauthorized access attempts.
- Monitor WAF logs and alerts continuously to detect potential security incidents in real time.
- Develop and update security policies that govern web application access control and protection mechanisms.
- Collaborate closely with development teams to integrate security measures into application deployment pipelines.
- Perform regular vulnerability assessments and adjust WAF settings to address identified risks promptly.
- Investigate security breaches and compile detailed reports on incident root causes and impact.
- Test WAF rule effectiveness through simulated attack scenarios and structured penetration exercises.
- Maintain comprehensive documentation of all WAF configurations, policies, and procedural changes over time.
- Coordinate with network and infrastructure teams to ensure a consistent and unified security posture.
- Provide guidance and training to junior staff members on WAF management best practices.
- Review and update WAF rule sets regularly to address newly discovered threat intelligence feeds.
- Participate in security reviews and contribute recommendations for improving overall application protection.
- Stay current with emerging web application threats and recommend proactive defensive measures.
- Engage in regular threat modeling sessions to identify and mitigate potential application risks.
Requirements
- Proven experience administering web application firewall solutions in a production or staging environment.
- Strong understanding of common web application vulnerabilities including SQL injection and cross-site scripting.
- Familiarity with security standards and compliance frameworks relevant to web application protection.
- Ability to analyze security logs and correlate events to identify potential threats accurately.
- Solid knowledge of HTTP protocol behavior, request methods, and web traffic patterns.
- Experience with scripting or automation to streamline repetitive WAF management tasks efficiently.
- Good communication skills for coordinating effectively with both technical and non-technical stakeholders.
- Degree or equivalent experience in information technology, computer science, or cybersecurity field.
- Demonstrated ability to work independently and manage multiple security priorities simultaneously.
- Experience with security monitoring platforms and SIEM tools is considered a plus.
- Knowledge of network security fundamentals including firewalls, proxies, and access control lists.
- Experience working in a regulated industry or environment with strict security requirements.
- Familiarity with cloud infrastructure platforms and their native security features is beneficial.
Nice to have
- Prior experience with cloud-based WAF services such as AWS WAF or Azure Front Door.
- Knowledge of additional security tools like intrusion detection or prevention systems.
- Familiarity with DevSecOps practices, CI/CD security integration workflows, and automated testing pipelines.
- Professional certifications in information security such as CISSP or CEH are valued.
- Background in application security testing, code review processes, and secure development lifecycle.
- Experience with API security and gateway protection solutions is a bonus.
- Knowledge of regulatory frameworks such as GDPR or PCI-DSS related to web security.
Skills & tools
- Web Application Firewall administration, rule configuration, and policy management.
- Security information and event monitoring platforms for threat detection.
- HTTP protocol analysis and web traffic inspection techniques.
- Scripting languages such as Python or Bash for automation of security tasks.
- Vulnerability scanning tools and penetration testing methodologies.
- Incident response procedures and forensic documentation practices.
- Network security fundamentals and traffic analysis capabilities.
- Understanding of encryption protocols and secure communication standards.
- Familiarity with API gateway security and rate limiting configurations.
Practical notes
- The role is based in Paris and requires on-site presence at the Citech office.
- This is a full-time position with standard business hours and occasional on-call responsibilities.
- The hiring process may include technical assessments and security-related interviews with the team.
- Candidates should be prepared to work with evolving threat landscapes and adapt quickly.
- The position reports to the security team lead and involves cross-department collaboration.
- Remote work is not available for this position as it requires on-site attendance.
- The compensation package and benefits details will be discussed during the interview process.
- The team operates within a fast-paced environment where attention to detail is essential.