WAF Adversarial Engineer
SGA Corp
Software Guidance & Assistance, Inc., (SGA), is searching for a WAF Adversarial Engineer for a contract assignment with one of our premier SaaS clients in Seattle, WA. Will also consider remote candidates residing in PST.
Responsibilities:- Run adversarial test campaigns against our WAF stack (Akamai, AWS WAF, Fastly, and Cloudflare) after each rule update cycle.
- Target encoding evasion, parsing differentials between WAF and origin, request smuggling, chunked encoding manipulation, multipart boundary abuse, Unicode normalization gaps, and logic layer bypasses.
- Build and maintain a versioned WAF bypass library, organized by vulnerability class (SQLi, XSS, SSRF, path traversal, SSTI, etc.), validated against staging and production WAF configurations, and updated as platforms and rules evolve.
- Conduct adversarial testing of API endpoints behind the WAF, including business logic abuse, BOLA/BFLA, mass assignment, and parameter manipulation. Document explicitly which classes of attack the WAF can and cannot reliably cover.
- Triage complex false positive investigations that cannot be resolved through log analysis alone - reproduce the ambiguous traffic from the attacker side and recommend targeted rule adjustments.
- Produce concise validation reports that translate offensive findings into testable rule candidates the team can refine and deploy. Each deliverable is a reproducer plus a rule recommendation, not a "bypass confirmed " note.
- Provide adversarial perspective during active edge incidents - likely attacker behavior, blind spots, next probable moves.
- Operate as the continuous validation function for the WAF program, integrated with the team's rule update cadence rather than running standalone pentest engagements.
Required Skills:
- Demonstrated WAF bypass experience against at least two commercial WAF platforms (Akamai, AWS WAF, Fastly, or Cloudflare).
- Deep working knowledge of protocol edge cases that affect WAF inspection: request smuggling primitives, chunked transfer encoding abuse, multipart boundary manipulation, Unicode normalization differentials, and header injection patterns.
- Web application penetration testing track record with WAF-specific scope. OSCP, BSCP, OSWE, or a portfolio of disclosed bypasses, conference talks, or prior validation engagements against WAF-protected assets. Tool-running alone does not qualify. - Proven ability to translate offensive findings into defensive artifacts - reproducer plus rule candidate, not just a finding.
- Strong scripting in Python or Go for building test harnesses, payload generators, and replay tooling.
- Comfortable working in CI/CD pipelines and cloud environments (AWS or Azure). Plug into existing infrastructure rather than build it.
- Education: Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related technical field, or equivalent demonstrated experience.
- API-specific attack surface depth: GraphQL injection, BOLA/BFLA, mass assignment.
- Akamai platform internals: KRS / ASE rule engine, custom Lua / EdgeWorkers exposure.
- Bot evasion at the behavioral layer: headless browser fingerprinting bypass, behavioral mimicry.
- Familiarity with edge-layer LLM/GenAI guardrails (OWASP LLM Top 10, prompt injection mitigation at the WAF tier).
- Public security research, CVE disclosures, or conference talks demonstrating original bypass work.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company EEO page to request an accommodation or assistance regarding our policy.
Vacancy posted 7 hours ago
Similar jobs that could be interesting for youBased on the WAF Adversarial Engineer in Seattle, WA vacancy
$60 - $65 per hour
Primary Skills: WAF Evasion Expert, Protocol Expert, API Security Expert, Python Scripting Expert, CI/CD Integration... ...Job Summary This role requires an experienced security engineer to conduct continuous adversarial validation of our Web Application Firewall (WAF) stack....SuggestedHourly payContract work$56.34 - $70.42 per hour
...Description WAF Adversarial Engineer Full-time Seattle, WA, US You'll be joining Adobe on a contract opportunity, employed through NextDeavor Benefits You'll Love NextDeavor offers health, vision and dental benefits for contract employees Paid...SuggestedHourly payPermanent employmentFull timeContract workRemote work$60 - $65 per hour
Akraya, Inc. is seeking a WAF Evasion Expert in Seattle, WA to conduct adversarial testing on our Web Application Firewall (WAF) stack. The role focuses on executing adversarial test campaigns and developing a comprehensive WAF bypass library. Candidates should demonstrate...SuggestedHourly payContract work- Responsibilities Run adversarial test campaigns against our WAF stack (Akamai, AWS WAF, Fastly, and Cloudflare) after each rule update cycle. Target... ...: Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related technical field,...Suggested
- Software Guidance & Assistance, Inc. (SGA, Inc.) is seeking a skilled cybersecurity professional in Seattle to run adversarial test campaigns against WAF platforms such as Akamai and AWS WAF. The ideal candidate will have proven experience in WAF bypass techniques, solid...Suggested
$106.8k - $194.8k
...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. WAF Operations Solution Engineer PRACTICE DESCRIPTION: As a WAF Operations Solution Engineer, you will be responsible for implementing and managing...Summer holidayFlexible hours$83.43k - $222.48k
Position Summary The Senior Adversary Operations Engineer plays a critical role in strengthening the organization’s security posture by executing advanced penetration testing and adversary simulation activities that uncover high‑risk vulnerabilities across enterprise, cloud...Full timeLocal area- Ernst & Young Oman is seeking a WAF Operations Solution Engineer to implement and manage Web Application Firewall (WAF) solutions aimed at protecting client applications against cyber threats. The role involves collaboration with cybersecurity teams and monitoring application...Remote jobFlexible hours
$106.8k - $194.8k
WAF Operations Solution Engineer Location: Anywhere in Country Practice Description As a WAF Operations Solution Engineer, you will be responsible for implementing and managing Web Application Firewall (WAF) solutions to protect client applications from cyber threats....Summer holidayFlexible hours$83.43k - $222.48k
The Hispanic Alliance for Career Enhancement is seeking a Senior Adversary Operations Engineer to strengthen security through advanced penetration testing and adversary simulations. This role involves conducting tests, creating actionable reports, and collaborating with...$69.83k - $145.02k
...capabilities, then consider a career in Advisory. KPMG is currently seeking a Associate, Infrastructure Project Advisory (Construction/Engineering) in Infrastructure and Projects Advisory for our Deal Advisory practice. Responsibilities : Review, analyze, and...Full timeContract workH1bLocal area$56.34 - $70.42 per hour
NextDeavor is seeking a WAF Adversarial Engineer to validate and harden web application firewall security by conducting adversarial testing. You'll run test campaigns, build a WAF bypass library, and work with edge security teams. Requirements include experience with commercial...Remote jobHourly pay- ...Job Title: Field Service Controls Engineer Job Type: Full-Time | Direct Hire Travel: 60% required Candidate can live anywhere on the west coast or mountain states region (CO, ID, UT, CA, OR, WA, NV). About the Company Our client is a leading systems integrator specializing...Full time
- ...About this Role: We are seeking a Navigation & Sensing Engineer to join our Autonomy engineering team to advance the positioning... ...deliver accurate, resilient localization across GPS-challenged and adversarial environments. In this role, you will work across GNSS,...Work at officeFlexible hours
$80k - $90k
...Building Group Department: Field Operations Market: Building Employment Type: Full Time Position Overview As a Field Engineer, you will bring a positive attitude, a results-driven mindset, and unlimited potential to some of the most exciting and rewarding...Full timeContract workFor contractorsFor subcontractorInternshipWork at officeRelocationRelocation packageWeekend work$97.22k - $129.77k
BCC Engineering, a Parsons Company, is seeking a Technical Services Engineer (TSE) I to provide expertise in engineering design and energy conservation measures. This role supports Integrated Solutions (IS) project delivery and ensures successful implementation of energy...- JLL is seeking skilled individuals for HVAC positions to install, maintain, and troubleshoot systems in commercial buildings. Responsibilities include inspections and repairs to ensure optimal performance. Candidates should possess various licenses and certifications in...Remote workFlexible hours
$117.2k - $176.7k
Job Category: Software Engineering About Salesforce Salesforce is the leading AI-driven CRM, where collaborative innovation shapes customer... ...team. In this role, you will transform vast streams of adversary data into actionable insights by developing and optimizing large...$54 - $57 per hour
...Assistant Chief Building Engineer Seattle, WA We are looking for a skilled Assistant Chief Engineer to assist the Senior Chief Engineer in directing the engineering departments operations (providing technical and administrative support), preplanning mechanical preventive...Work experience placementWork at officeRemote workShift work- ...those who have faced nation state, eCrime, and other types of adversaries in threat intelligence, incident response, and/or threat... ...massive streams of adversary data into meaningful insights by engineering and optimizing large‑scale automated pipelines. Beyond simply...Remote work
$38.46 - $45.67 per hour
A leading global real estate firm is seeking an Operating Engineer to support maintenance processes at their Bellevue, WA location. The ideal candidate will have over 3 years of experience in repair and maintenance, particularly in HVAC and plumbing systems. Responsibilities...Hourly pay$36.05 - $42.79 per hour
CBRE is seeking a Building Engineer in Seattle, WA. Responsibilities include maintaining building systems, performing preventive maintenance, and ensuring compliance with safety regulations. Candidates should have HVAC/R experience, a high school diploma or GED with relevant...Hourly pay$36.05 - $42.79 per hour
CBRE is seeking a Building Engineer for their Bellevue location. You'll be responsible for the upkeep and repair of various building systems including plumbing, electrical, and HVAC. This on-site position requires expertise in preventative maintenance and repairs, along...Hourly pay- ENFRA LLC in Seattle is looking for a Technical Services Engineer (TSE) I to support project delivery in energy conservation measures. The ideal candidate will have extensive engineering design experience and a PE license, overseeing commissioning processes and providing...
- A global real estate firm in Bellevue, WA is looking for an experienced Operating Engineer to support the operation, inspection, and maintenance of HVAC, plumbing, and electrical systems. The ideal candidate has 3+ years of experience in related fields, and strong customer...Hourly pay
$85k - $90k
...collaboration, and excellence enable us to lead the industry in providing the optimal solution for our clients. Keller is looking for a Field Engineer based out of our Seattle, WA location. Responsibilities Responsibilities will include the following: This Field Engineer position...Work at officeLocal area$95k - $110k
...., a global leader in testing, inspection, and certification is currently seeking experienced persons to work as Field Evaluation Engineers/Electrical Inspectors on client projects related to electrical equipment and machinery. The Engineer/Inspector will use experience...Full timeLocal areaRemote work- Beacon Engineering Resources in Seattle is seeking a Project Field Engineer to oversee on-site activities and coordinate project tasks. The role involves monitoring site activities, assisting with estimates and budgets, and ensuring compliance with safety and quality standards...
- At ENFRA, we blend a rich history with a forward-looking vision. With over 100 years of experience, we are a pillar of stability in the energy infrastructure industry and a leader in innovative energy solutions. Our commitment to leveraging emerging technologies ensures...
$150k - $185k
...toughest environments. We serve the people who build, operate, maintain, and defend our way of life. From technicians and engineers to first responders and service members, they embody the hard work, ingenuity, and meritocratic values that drive Western...Permanent employment
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to WAF Adversarial Engineer. Be the first to apply!


