Cox Enterprises · 19 hours ago
Lead Cybersecurity WAF Engineer
Cox Automotive is a leader in transforming the automotive industry through innovative technology. They are seeking a Lead Cybersecurity WAF Engineer to own and shape the strategy and standards for web application firewall protection across their public-facing applications, while collaborating with various teams to ensure robust security measures are in place.
AdvertisingBroadcastingDigital MediaTelecommunications
Responsibilities
Own and champion the enterprise WAF, shaping its strategy, patterns, and standards in partnership with the architecture team. We’re looking for someone who lives and breathes WAF and can elevate security for all public-facing sites and APIs
Analyze WAF rules to identify improvements and explain recommended changes to improve the protections the WAF provides
Collaborating with security architecture on long‑term WAF strategy, including technology standards, architectural patterns, and security roadmaps
Author and maintain runbooks, playbooks, and threat specific WAF tuning strategies. Lead the creation and continuous improvement of runbooks, playbooks, and automated detection/triggers
Perform cyber engineering trend analysis and reporting, defining and recommending tool, infrastructure and other improvements
Proposes and helps review plans and policies to improve the overall security environment
Participate in security events and incident response (e.g., botnet traffic spikes, Layer 7 attacks) to identify gaps in current design and propose solutions to prevent threats from reoccurring
Research and evaluate emerging security trends, threats, and technologies, and recommend appropriate solutions and enhancements
Partnering closely with AppSec, Cyber Defense, and Engineering teams for secure-by-default adoption
Qualification
Required
Bachelor's degree in a related discipline and 6 years' experience in a related field. The right candidate could also have a different combination, such as a master's degree and 4 years' experience; a Ph.D. and 1 year of experience; or 18 years' experience in a related field
At least 4 years focused on cybersecurity with at least 2 years managing enterprise WAF
Demonstrated expert level experience architecting, implementing, and operating enterprise WAF solutions across multiple environments
Must have deep knowledge of how network traffic routes between clients and servers across the internet (e.g., DNS, HTTP/S, CDN/edge routing)
Clearly articulate the objective of specific cybersecurity policies and procedures to technical and non-technical stakeholders
Proven experience leading technical initiatives and mentoring engineering teams
Excellent customer service skills, writing, and presentation skills
Develop a strong and productive working environment with key stakeholders and collaborate closely with other Cox entities' cybersecurity teams to implement cybersecurity best practices
Consultative nature to work through controversial or complex topics to employees, leaders, and/or senior leadership
Proficient in Python and Terraform
Creatively solving complex cybersecurity challenges while exhibiting solid, pragmatic business acumen
Experience utilizing Agile methodologies and DevSecOps
Initiating change and deploying solutions in Fortune 1000 companies
Knowledge of cybersecurity frameworks (e.g., ISO 27000, NIST, FFIEC) and industry relevant regulations that will guide architectural requirements (e.g., GDPR, FFIEC, GLBA)
Preferred
Knowledge of current cybersecurity and technology architectures such as zero trust, IaaS, PaaS, SaaS, virtualization, and containerization
A strong understanding of cloud containers and/or serverless platforms (e.g., EKS, ECS, Lambda, Fargate)
Experience with security testing tools such as Fortify, BurpSuite, and Wiz
Extensive technology knowledge and recognized expertise in several areas including .NET framework, Mono, Spring frameworks, Oracle, serverless, cloud patterns, cloud service and user authentication or similar
Experience with cloud infrastructure (AWS, GCP, or Azure) and services and on-premises infrastructure
Experience in the development and design of cybersecurity standard methodologies to all layers of the hosting and application stack in both cloud and on-premises environments
Knowledge of Identity and Access Management (IAM), cryptography / key management, secrets management, access controls and security protocols (e.g., multi-factor, SAML, OAuth, OIDC)
Experience with firewall, web application firewalls, and other edge services as well as deep understanding of DMZ and other network architectures
AWS Well-Architected Framework
Experience in national critical infrastructure industries (telecommunications, financial services, defense, government, etc.)
Big four consulting or Fortune 500 company experience
Relevant industry certification (e.g., CISSP, CEH, OSCP, Azure, AWS, CISM, CISA)
Benefits
Flexibility to take as much vacation with pay as they deem consistent with their duties, the company’s needs, and its obligations
Seven paid holidays throughout the calendar year
Up to 160 hours of paid wellness annually for their own wellness or that of family members
Bereavement leave
Time off to vote
Jury duty leave
Volunteer time off
Military leave
Parental leave
Health care insurance (medical, dental, vision)
Retirement planning (401(k))
Paid days off (sick leave, parental leave, flexible vacation/wellness days, and/or PTO)
Company
Cox Enterprises
Cox Enterprises is a communications, media, and automotive services company.
H1B Sponsorship
Cox Enterprises has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2023 (4)
2022 (7)
2021 (1)
2020 (3)
Funding
Current Stage
Late StageTotal Funding
$1.7M2014-12-15Grant· $1.7M
Leadership Team
Recent News
2026-01-07
Dayton Daily News
2025-12-11
Company data provided by crunchbase