Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Web App Firewall Specialist image - Rise Careers
Job details

Web App Firewall Specialist

Job Description

IMPORTANT NOTE: CANDIDATES WITH A PERMANENT COMPUTER SPECIALIST (SOFTWARE) OR COMPARABLE CIVIL SERVICE TITLE WITH SIMILAR DUTIES/RESPONSIBILITES ARE ENCOURAGED TO APPLY. PLEASE INCLUDE YOUR EMPLOYEE IDENTIFICATION NUMBER (EIN) WHEN APPLYING AND INDICATE IN YOUR COVER LETTER YOUR PERMANENT CIVIL SERVICE TITLE.

The NYC Department of Finance (DOF) is responsible for administering the tax revenue laws of the city fairly, efficiently, and transparently to instill public confidence and encourage compliance while providing exceptional customer service.

DOF's Information Technology (FIT) Division designs, builds, and supports all facets of DOF’s computer systems, including hardware, software, applications, infrastructure, telephone, and data security. FIT delivers and administers tax-related payment programs for the City of New York by providing the information technology solutions needed to achieve its mission of collecting revenue while ensuring an efficient and improved customer experience. FIT is also responsible for the systems and websites which enable citywide payments, land records, property assessment, parking adjudications, customer service, and the Sheriff’s public safety work.

DOF is currently seeking a highly talented and experienced Web Application Firewall (WAF) and Web Application API Protection Specialist, preferably with a solid background in Akamai WAF and WAAP solutions, to join our Cybersecurity team. They should also have a strong understanding of web application security principles, OWASP Top 10, and common attack vectors such as SQL injection, XSS, and DDOS.

The WAF Security Specialist's responsibilities will include but not be limited to the following:
- Ensuring the security, performance, and availability of critical applications by utilizing a cloud-based WAF platform to prevent attacks and mitigate security risks.
- Managing, configuring, and optimizing WAF solutions to protect the organization's web applications from a wide range of online threats.
- Deploy and configure WAF and WAAP to protect web applications, APIs, and other critical services. Customize security rules to fit specific application needs and business requirements, such as preventing SQL injection attacks and cross-site scripting and ensuring compliance with industry regulations.
- Regularly optimize WAF and WAAP policies to reduce false positives and ensure application security. Maintain and update custom security rules to reflect evolving Cyber threats.
- WAF and WAAP detects security incidents, such as attacks and policy violations. Investigate and escalate these incidents with the IT and security teams. Collaborate to troubleshoot issues and escalate immediately if needed. Examples of policy violations may include unauthorized access attempts or data breaches.
- Use analytics and reporting tools to monitor traffic, identify trends, and detect security events. Provide detailed reports on WAF and WAAP performances, attack trends, and incidents to management and security teams.
- Work with vulnerability management teams to identify and remediate security vulnerabilities in web applications. Implement and enforce security policies within WAF to block known attack patterns.
- Work closely with the development, DevOps, and network operations team to ensure the successful integration of WAF and WAAP into the broader infrastructure. This involves actively participating in secure software development practices and contributing to the CI/CD pipelines to ensure continuous security.
- Threat Intelligence & Research: Stay updated on emerging threats such as phishing scams and malware attacks, as well as web application security trends like cross-site scripting and SQL injection and WAF and WAAP feature enhancements. Implement regular security audits and penetration testing to defend against new attack vectors and vulnerabilities.
- Documenting troubleshooting steps for common security issues, such as SQL injection and cross-site scripting, in Web Application Firewall configuration and Web Application API Protection. Creating security guidelines and best practices for the organization.

Additional Information:
The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.

COMPUTER SPECIALIST (SOFTWARE) - 13632

Qualifications

(1) A baccalaureate degree from an accredited college, including or supplemented by twenty-four (24) semester credits in computer science or a related computer field and two (2) years of satisfactory full-time software experience in designing, programming, debugging, maintaining, implementing, and enhancing computer software applications, systems programming, systems analysis and design, data communication software, or database design and programming, including one year in a project leader capacity or as a major contributor on a complex project; or
(2) A four-year high school diploma or its educational equivalent and six (6) years of full-time satisfactory software experience as described in “1" above, including one year in a project leader capacity or as a major contributor on a complex project; or
(3) A satisfactory combination of education and experience that is equivalent to (1) or (2) above. College education may be substituted for up to two years of the required experience in (2) above on the basis that sixty (60) semester credits from an accredited college is equated to one year of experience. A masters degree in computer science or a related computer field may be substituted for one year of the required experience in (1) or (2) above. However, all candidates must have a four year high school diploma or its educational equivalent, plus at least one (1) year of satisfactory full-time software experience in a project leader capacity or as a major contributor on a complex project.
NOTE: In order to have your experience accepted as Project Leader or Major Contributor experience, you must explain in detail how your experience qualifies you as a project leader or as a major contributor. Experience in computer operations, technical support, quality assurance (QA), hardware installation, help desk, or as an end user will not be accepted for meeting the minimum qualification
requirements.
Special Note
To be eligible for placement in Assignment Level IV, in addition to the Qualification Requirements stated above, individuals must have one year of satisfactory experience in a project leader capacity or as a major contributor on a complex project in data administration, database management systems, operating systems, data communications systems, capacity planning, and/or on-line applications programming.

Additional Information

The City of New York is an inclusive equal opportunity employer committed to recruiting and retaining a diverse workforce and providing a work environment that is free from discrimination and harassment based upon any legally protected status or protected characteristic, including but not limited to an individual's sex, race, color, ethnicity, national origin, age, religion, disability, sexual orientation, veteran status, gender identity, or pregnancy.

Average salary estimate

$85000 / YEARLY (est.)
min
max
$70000K
$100000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Web App Firewall Specialist, City of New York

Join the NYC Department of Finance as a Web App Firewall Specialist and be part of an essential mission to protect the city’s digital landscape! At DOF, you'll find yourself immersed in a dynamic team within the Information Technology (FIT) Division, where the responsibility for securing tax-related payment systems rests in your capable hands. Your primary focus will be on managing and optimizing cloud-based WAF platforms, including Akamai solutions, to safeguard various web applications and APIs from emerging cyber threats and attack techniques like SQL injections and cross-site scripting. This is your chance to ensure the performance and availability of critical applications while collaborating closely with development, DevOps, and network operations teams to embed security into every layer of our services. You'll need to take the lead on configuring security rules, managing incident detection and response, and utilizing analytics to monitor traffic and identify potential threats. To thrive in this role, bring your comprehensive understanding of web application security principles as well as your ability to ensure compliance with industry regulations. If you're passionate about enhancing the security landscape for NYC and have a knack for troubleshooting in a fast-paced environment, we invite you to apply and join us in delivering exceptional technology solutions to our city.

Frequently Asked Questions (FAQs) for Web App Firewall Specialist Role at City of New York
What are the key responsibilities of the Web App Firewall Specialist at the NYC Department of Finance?

The Web App Firewall Specialist at the NYC Department of Finance will be responsible for managing the security, performance, and availability of web applications by utilizing cloud-based WAF platforms. This includes configuring and optimizing security rules, monitoring incidents, troubleshooting issues, and collaborating with various teams to ensure seamless integration of WAF into existing systems.

Join Rise to see the full answer
What qualifications are required to apply for the Web App Firewall Specialist position at the NYC Department of Finance?

To apply for the Web App Firewall Specialist position at the NYC Department of Finance, candidates should possess a bachelor’s degree with coursework in computer science and two years of software experience, or a combination of education and equivalent software experience. Specific familiarity with WAF solutions and cyber security principles is essential.

Join Rise to see the full answer
How does the Web App Firewall Specialist contribute to the security of web applications at the NYC Department of Finance?

The Web App Firewall Specialist enhances the security of web applications at the NYC Department of Finance by deploying and configuring WAF and WAAP solutions to block various online threats. Their role includes customizing security rules and regularly optimizing WAF policies to avoid false positives and ensure comprehensive application security.

Join Rise to see the full answer
What tools or technologies should a Web App Firewall Specialist be familiar with at the NYC Department of Finance?

A Web App Firewall Specialist at the NYC Department of Finance should be familiar with Akamai WAF solutions, web application security concepts, OWASP Top 10 vulnerabilities, and various security monitoring tools. Knowledge of vulnerability management and experience with analytics software is also highly valuable.

Join Rise to see the full answer
What opportunities for professional growth does the NYC Department of Finance offer to a Web App Firewall Specialist?

The NYC Department of Finance offers a range of professional growth opportunities for a Web App Firewall Specialist, including participation in secure software development practices, continual learning in emerging security technologies, and the chance to contribute to critical projects that protect key applications and services in New York City.

Join Rise to see the full answer
Common Interview Questions for Web App Firewall Specialist
Can you explain what a Web App Firewall (WAF) is and its importance?

A Web App Firewall (WAF) is a security tool designed to protect web applications from common attacks such as SQL injection, XSS, and DDoS. In your answer, emphasize the WAF's role in monitoring HTTP traffic, filtering harmful data, and ensuring data integrity—crucial for organizations like the NYC Department of Finance that manage sensitive information.

Join Rise to see the full answer
What experience do you have with configuring security rules in a WAF?

Share specific examples of your experience in creating and managing security rules tailored to specific applications. Talk about the balance between security and usability, as well as any frameworks or methodologies you've utilized, which would resonate with the needs of the NYC Department of Finance.

Join Rise to see the full answer
How do you stay updated on the latest web application security threats?

Discuss your strategies for staying informed, such as subscribing to industry news, attending webinars, or participating in professional networks. Highlight specific resources or communities focused on cybersecurity that would be relevant for someone in a role at the NYC Department of Finance.

Join Rise to see the full answer
What steps would you take if you detected a security incident?

Outline a clear incident response plan, addressing how you'd investigate the issue, escalate it if necessary, and cooperate with other IT and security teams to resolve it. Sharing experiences where you successfully mitigated an incident will showcase your problem-solving skills.

Join Rise to see the full answer
What is the OWASP Top 10, and why is it important?

The OWASP Top 10 is a list of the most critical web application security risks. Explain its significance in categorizing and prioritizing vulnerabilities to help organizations like the NYC Department of Finance focus their resources on preventing the most detrimental attacks.

Join Rise to see the full answer
How do you approach optimizing WAF policies to reduce false positives?

Discuss your methods for analyzing traffic patterns, tuning the WAF settings, and employing a continuous feedback loop for improvements. Specific examples of achieving this balance while working with security products will strengthen your response.

Join Rise to see the full answer
Can you describe your experience working with development and DevOps teams?

Illustrate how you've collaborated with development and DevOps teams to integrate security practices into CI/CD pipelines. Highlight the importance of a cooperative environment to ensure security measures are effectively applied without hampering development speed.

Join Rise to see the full answer
What reporting tools have you used to monitor WAF performance?

Share your familiarity with various analytics tools that help visualize security incidents and traffic trends. Emphasize how these insights drive security policy adjustments, a critical function within the NYC Department of Finance’s operations.

Join Rise to see the full answer
What is your approach to documenting security guidelines?

Detail how you create comprehensive documentation that covers troubleshooting steps and best practices for securing web applications. This is particularly vital in a complex environment like the NYC Department of Finance, where clarity and consistency in security protocols are key.

Join Rise to see the full answer
Why do you want to work as a Web App Firewall Specialist at the NYC Department of Finance?

Tailor your response to reflect your admiration for the mission of DOF and its role in tax equity and public service. Highlight your passion for cybersecurity and how the position aligns with your professional goals, emphasizing your desire to contribute to the safety of New York City’s digital initiatives.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Neo Group Remote No location specified
Posted 4 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 2 days ago
Photo of the Rise User
Atlan Remote No location specified
Posted 5 days ago
Posted 3 days ago
Photo of the Rise User
Onbe Remote Conshohocken, Pennsylvania, United States
Posted 4 days ago
Ignite IT Hybrid No location specified
Posted 11 days ago

Our Mission To work to eliminate ageism and ensure the dignity and quality-of-life of New York City’s diverse older adults, and for the support of their caregivers through service, advocacy, and education. Strategic Goals To foster independence...

3504 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 19, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Columbus just viewed Strategy and Corporate Development Intern at SoundCloud
Photo of the Rise User
Someone from OH, Milford just viewed Visual Designer (Contract to Hire) at Abridge
Photo of the Rise User
Someone from OH, Dublin just viewed User Researcher III at Fearless
Photo of the Rise User
Someone from OH, Dublin just viewed Senior UX Designer at Nox Health
Photo of the Rise User
Someone from OH, Dublin just viewed US Product Designer at Praxent
Photo of the Rise User
19 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Solon just viewed QA Analyst at Two Circles
Photo of the Rise User
Someone from OH, Cincinnati just viewed Shift Lead - Downtown Cincinnati at DoorDash USA
Photo of the Rise User
Someone from OH, Cleveland just viewed Getinge is hiring: UI/UX Developer in Streetsboro at Getinge
Photo of the Rise User
Someone from OH, Loveland just viewed Inside Sales Co-Op at VEGA Americas
B
Someone from OH, Painesville just viewed Administrative Assistant at BlkVision Media
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Customer Support (Automotive) at Publicis Groupe
Photo of the Rise User
Someone from OH, Columbus just viewed Event Campaign Manager at Smartling
H
Someone from OH, Chesterland just viewed Client Success Manager at HR Force International
Photo of the Rise User
Someone from OH, Dublin just viewed Junior PMO Analyst at Rentokil Initial Group
Photo of the Rise User
Someone from OH, Doylestown just viewed Associate Sub-editor at Third Bridge
Photo of the Rise User
Someone from OH, Pickerington just viewed Layout Artist at Powerhouse Animation Studios
Photo of the Rise User
Someone from OH, Cortland just viewed Exploring Post-Grad Rotational Programs at Evonik at Evonik
B
Someone from OH, Powell just viewed Salesforce Admin (Part Time) at Bullpen Talent