L
Web Security Engineer
Tirana, Tirana County, Albania · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 1 day ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
We are seeking a dedicated Web Security Engineer to provide specialized technical support in securing internet-facing applications and services. This role is critical in defending web applications, APIs, and online digital platforms from cyber threats, while aiding business projects and ongoing security operations.
Primary Responsibilities
- Develop, apply, and maintain security controls specific to web environments.
- Administer and fine-tune policies related to Web Application Firewalls (WAF).
- Investigate and address web-based cyberattacks such as OWASP Top 10 vulnerabilities, automated bot attacks, DDoS incidents, credential stuffing, and scraping.
- Analyze security alerts and incidents affecting websites, APIs, and customer-facing platforms.
- Conduct security architecture reviews and evaluate proposed web application changes.
- Assist with onboarding and configuration of Content Delivery Networks (CDNs) and associated security features.
- Create and enhance security rules, detection mechanisms, and automated protective measures.
- Collaborate with application teams to resolve discovered vulnerabilities.
- Perform security assessments and suggest improvements for reducing risks.
- Support incident response actions concerning web security breaches.
Required Skills and Knowledge
- Comprehensive understanding of web application security principles and practices.
- Proficiency with Web Application Firewalls (WAF).
- Experience with CDN platforms such as Cloudflare, Akamai, or equivalent.
- Expertise in API security.
- Strong knowledge of HTTP/HTTPS protocols.
- Fundamental networking concepts including TCP/IP, DNS, load balancing, and reverse proxies.
- Ability to analyze web attack trends and interpret security log data.
- Familiarity with the OWASP Top 10 vulnerabilities and principles of secure software development.
- Competence in diagnosing intricate web security issues.
Preferred Additional Skills
- Experience with Cloudflare Enterprise services.
- Knowledge of Terraform and Infrastructure as Code techniques.
- Familiarity with Azure DevOps or continuous integration/continuous deployment (CI/CD) workflows.
- Basic scripting ability in Python, PowerShell, or Bash.
Working Conditions
- Operate primarily during standard business hours.
- Participate in on-call rotations for critical incident management and platform outage responses.
Skills
How they work
Teamwork & Collaboration
Problem Solving
Attention to Detail
Work Ethic