Senior Security Engineer- Web Application Firewall
Paylocity
Job Description
Job Description
Description:
Paylocity is an award-winning provider of cloud-based HR and payroll software solutions, offering the most complete platform for the modern workforce. The company has become one of the fastest-growing HCM software providers worldwide by offering an intuitive, easy-to-use product suite that helps businesses automate and streamline HR and payroll processes, attract and retain talent, and build a strong workplace culture.
While traditional HR and payroll providers automate basic HR processes such as payroll and benefits administration, Paylocity goes further by developing tools that HR and businesses need to compete for talent and deliver against the expectations of the modern workforce.
We give our employees what they need to succeed, including great benefits and perks! We offer medical, dental, vision, life, disability, and a 401(k) match, as well as perks that support you, your family, and your finances. And if it’s career development you desire, we provide that, too! At Paylocity, people matter most and have always been at the heart of our business.
Help Paylocity enhance communication and enable employees to connect, collaborate, and create from anywhere with a position in Product & Technology!
Want to develop the strategies and principles needed to deliver compelling software? Join our team and help us enhance our all-in-one software platform, elevate our one-of-a-kind technology, and improve the employee experience.
Take your career to the next level at one of G2's Top 100 Software Companies. Explore our Product & Technology positions to see where you fit!
This is a fully remote position, allowing you to work from home or location of record within the U.S. with no in-office requirements. You must be available five days per week during designated work hours. The work arrangement for this role is subject to change based on business needs and individual performance. This may include adjustments to on-site requirements or schedule expectations, as necessary.
Position Overview
The Sr. Security Engineer (WAF) is responsible for architecting, implementing, and continuously improving application-layer security controls across Paylocity’s SaaS platforms. This role operates within the newly established Product Security function and focuses on protecting web, API, and AI workflows beyond traditional authentication boundaries.
This position requires deep expertise in Web Application Firewall technologies, Layer 7 threat patterns, and behavioral abuse mitigation. The Sr. Security Engineer (WAF) will lead enforcement strategy, mature detection capabilities, and serve as a subject matter expert for application-layer risk, working closely with Product, Engineering, Infrastructure, and Security teams. The role also plays a key part in supporting Product Security Incident Response (PSIRT).
Primary Responsibilities
The below represents the primary duties of the position; others may be assigned as needed. To perform this job successfully, an individual must be able to perform each essential duty satisfactorily.
- Architect, implement, and maintain Web Application Firewall (WAF) protections across web and API endpoints.
- Lead strategy and tuning for rate limiting, bot mitigation, and automation abuse prevention.
- Design scalable enforcement models for high-risk workflows including authentication, reporting/export, file uploads, and administrative functions.
- Analyze application-layer traffic patterns to identify behavioral anomalies, scraping activity, credential abuse, and logic misuse.
- Partner with Product and Engineering teams to ensure enforcement decisions align with intended business logic and user experience.
- Support and help operationalize Product Security Incident Response (PSIRT) for application-layer events.
- Develop investigation playbooks and continuously refine rule sets based on incident learnings.
- Optimize enforcement coverage while minimizing false positives and customer friction.
- Conduct periodic architecture and rule reviews to ensure controls evolve with emerging attack patterns and platform growth.
- Provide technical leadership and mentorship within the Product Security team on application-layer protection strategies.
Education and Experience
- Bachelor’s degree in information security, Computer Science, or a related discipline required.
- Minimum 7 years of experience in application security, WAF engineering, or edge security roles.
- Deep hands-on experience with enterprise WAF platforms across both on-premises and cloud-based environments (F5, Akamai, Imperva, AWS WAF, Cloud-based edge platforms, or equivalent).
- Experience leading or participating in WAF modernization initiatives, including migration from legacy, appliance-based architectures to scalable, distributed or cloud-aligned enforcement models.
- Strong understanding of DNS fundamentals and DNS security concepts, including authoritative vs. recursive resolution, DNS-based attack vectors, DNSSEC, and traffic steering considerations.
- Strong expertise in OWASP Top 10 and OWASP API Security Top 10.
Experience protecting large-scale, multi-tenant SaaS applications and high-volume web/API environments. - Proven experience designing and tuning rate limiting, bot mitigation, and automation detection controls.
- Experience investigating and responding to application-layer security incidents.
Strong understanding of TLS, API architectures, session handling, identity flows, and Layer 7 attack patterns. - Experience integrating WAF and application-layer telemetry into SIEM or observability platforms.
- Experience working in hybrid architectures spanning data center and cloud environments preferred.
- Experience with scripting (Python, PowerShell, Bash, etc.) for automation and rule management is a plus
- Foundational knowledge of AI/ML principles and their impact on modern application-layer threat landscapes.
Physical requirements
- Ability to sit for extended periods: The role requires sitting at a desk or workstation for long periods, typically 7-8 hours a day.
- Use of computer and phone systems: The employee must be able to operate a computer, use phone systems, and type. This includes using multiple software programs and inquiries simultaneously.
Paylocity is an equal-opportunity employer. Paylocity is committed to the full inclusion of all individuals. We recruit, train, compensate, and promote regardless of race, religion, color, national origin, sex, disability, age, veteran status, and other protected status as required by applicable law. At Paylocity, we believe diversity makes us better.
We embrace and encourage our employees’ differences in age, culture, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion or spiritual belief, sexual orientation, socio-economic status, veteran status, and other characteristics that make our employees unique. We actively cultivate these differences through our employee resource groups (ERGs), employee experiences, perspectives, talents, and approaches to drive innovation in the software and services we provide our customers.
We comply with federal and state disability laws and make reasonable accommodations for applicants and employees with disabilities. To request reasonable accommodation in the job application or interview process, please contact View email address on ziprecruiter.com. This email address is exclusively designated for such requests, aligning with federal and state disability laws. Please do not send resumes to this email address, as they will be removed.
The base pay range for this position is $101,100k - $150k/yr; however, base pay offered may vary depending on job-related knowledge, skills, and experience. This position is eligible for an annual bonus and restricted stock unit grant based on individual performance in addition to a full range of benefits outlined here. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed. Base pay information is based on market location. Applicants should apply via
Requirements:- Group Information Security (GIS) provides high quality... ...global reach. The Application Security team... ...specializes in understanding Web technology, the... ...sites and applications. Senior Web Security Engineers are technical... ...as Web application firewalls to provide layers of...ApplicationSeniorWebWork experience placementLocal area
- A leading company is seeking a Senior Web Security Engineer to enhance their application security landscape. This role involves advising stakeholders on security practices, conducting application security testing, and ensuring compliance with GIS standards. The ideal candidate...ApplicationSeniorWeb
- Halock Security Labs is hiring a Sr. Offensive Security Consultant to conduct web application and API penetration testing. The role requires 6-8 years of experience, strong proficiency in penetration testing tools, and the ability to develop custom solutions. Responsibilities...ApplicationSeniorWebRemote jobFull time
- ...requirements. Acquires and applies basic business knowledge to support application design/configuration. Make complex modifications to... ...SuiteCloud Development Framework JavaScript SQL Web Services (SOAP, REST) NetSuite Admin Preferred Skills:...ApplicationSeniorWebLocal areaRemote workWorldwide
$125k - $165k
...Position Overview We are seeking a Senior Growth Marketing Manager to drive predictable... ...into the buyer journey. Partner with web and product marketing teams to reduce friction... ...other protected status as required by applicable law. At Paylocity, we believe diversity makes...ApplicationSeniorWebWork at officeLocal areaRemote workWork from homeWorldwideShift work$70k - $110k
...Americaneagle.com is a family-owned web design, development, and digital marketing agency... ...marketing campaigns for our clients. The Senior Digital Marketing Strategist will work... ...measurement strategy. The ideal applicant will be passionate, results-oriented, and...ApplicationSeniorWebFull time$60k - $100k
...Americaneagle.com is a family-owned web design, development, and digital marketing... ...flow to increase visibility within search engines Track, analyze, and report using Google... ...how we can produce excellent sites and applications for our clients. We do all of this while...ApplicationSeniorWebFull time- ...Senior Web Developer Sonoma Consulting is one of the fastest growing Global IT Consulting and Executive Search providers with offices... ...business constituents needs are met. Provide custom web application development using the.NET Framework, C#, VB.NET, ASP.NET, SQL...ApplicationSeniorWeb
$90k - $180k
Home / Careers / Senior Full-Stack Web Application Developer / Software Engineer Senior Full-Stack Web Application Developer / Software Engineer Location: Bartlett, IL Salary: $90,000 - $180,000 Type: Full Time Min. Experience: 5+ Years *** This is an on-site position *...ApplicationSeniorWebFull time- ...About the role As the Senior Integration & Applications Developer you will design, build, support, and... ...and other IT teams to ensure reliable, secure, and maintainable data exchange and... ...and validation. Create and maintain web-based applications and APIs using...ApplicationSeniorWeb
- ...Senior Credit & Collections Specialist Elmhurst, Illinois Position Summary A 43... ...collections function. • Process new client applications, build credit files and recommend credit... ...Assist with uploading invoices to client web-based portals. • Application of client...ApplicationSeniorWebFull timeWork at officeRemote work
$39.62 per hour
...for the day-to-day operations and system security of the College's hypervisor, Windows,... ...support for server and cloud software and applications. Administers and leads technical support... ..., please visit our employment at Oakton web page. Equal Opportunity Employer...ApplicationSeniorWebHourly payFull timeWork experience placementSummer workMonday to FridayWeekend workAfternoon shift- ...scope and objectives. Works with users to support business applications, and investigate operational problems/system requirements. Devises... ...and the project delivery life cycle C# and the.NET Framework Web development with ASP.NET, HTML, or JavaScript Modern JavaScript...ApplicationSeniorWebWork at officeLocal areaFlexible hours
$90.95k
...Function and Responsibility The Senior Manager of User Support Services... ...: Computer Science, Computer Engineering, Electronics and Computer... ...visit our employment at Oakton web page. Equal Opportunity Employer Application Instructions: Please be sure...ApplicationSeniorWebWork experience placementWork at officeMonday to Friday$130k - $160k
Position: Sr. Offensive Security Consultant - Web App/API Location: United States - Remote Employment... ...Key Responsibilities Conduct web application and API penetration testing using a... ...Technology, Computer Science, Engineering or related discipline Desire to contribute...ApplicationSeniorWebFull timeRemote work$140k - $165k
...Description Senior Product Manager - Customer Portal... ...Portal across web and mobile. This is our... ...partner closely with engineering leadership, design, customer... ...building products, applications, technologies for last... ...information outside of our secure application process....ApplicationSeniorWebWork at officeLocal areaFlexible hours- ...technologies for cloud-based application development and deployment. Develop... ...project delivery. Create Web Services in C#.Net Develop... ...to modern Angular and close security issues. Manage source code using... ...Technology, Computer Engineering, Computer Science, and Digital...ApplicationSeniorWebWork experience placementLive outWork at officeLocal areaFlexible hours
$77k - $202k
...At PwC, our people in business application consulting specialise in... ...of large organizations. As a Senior Associate, you analyze complex... ...SOA architecture and fluency in web service standards, such as WSSE... ...factors thoughtfully to establish a secure and trusted workplace for all....ApplicationSeniorWebFull timeH1b- ...and implementation of global network and security solutions in cloud and on-premise environments... ...equipment including routers, switches, firewall, VPN & wireless Maintain, monitor,... ...of security products ForcePoint Web/DLP, Qualys, Vectra, Dragos, FortiNac, Ruckus...SeniorWeb
$130k - $140k
...bring several new mobile applications and other products to... ...future. The Senior Mobile Application... ...with other developers, engineers, and project managers... ...updates, improvements, and security testing. • Create... ...serial port, sockets, web services) • Engine and...ApplicationSeniorWebWork experience placementRemote workRelocation1 day per week$6,000 per month
...Tier 3 Engineer Schaumburg, IL ( • IT Apply Job Type Full... ...for server, network, application, and virtual CIO support related... ...migrations, wireless access points, firewalls, switches, and Microsoft... ...issues. Telephonic counseling and web-based services are available...ApplicationWebFull timeTemporary workWork at officeLocal areaImmediate startRemote workMonday to Friday- ...planning, and organizational skills Highly developed customer‑relations skills Proficiency in MS Office applications (Word, Excel, and PowerPoint) Familiarity with using web‑based software and smartphone applications This position requires frequent travel and possibility...ApplicationSeniorWebTemporary workWork experience placementRelocationRelocation package
$100k - $120k
Central Garden & Pet is seeking a UX & Web Experience Developer to enhance their web ecosystem across various brands. The ideal candidate will have strong skills in React, Next.js, and TypeScript, with experience in headless CMS and API integrations. This position offers...SeniorWeb- ...Work and a Top Google Partner, and they are currently seeking a talented Senior Marketing Designer to join their team. This role will play a key part in producing high-impact creative across web, video, advertising, and brand design for both internal initiatives and client...SeniorWebFull time
$185k
...Security Engineer (Azure Cloud Security) Overview We are seeking a highly skilled Security Engineer to help design, deploy... .... Support containerized workloads and modern application architectures. Collaborate cross-functionally with cloud...ApplicationRemote workRelocation- ...Hi, Position 1: Title: Senior Manager; DMP/Marketing Science Location: Chicago... ...platforms, ad serving platforms, web analytics systems and data management platforms... ...recommendations, which are specific and applicable to short-term and long-term goals...ApplicationSeniorWebContract workTemporary workFlexible hours
- ...Sr. Web Developer For the past 60 years client has been able to provide pension benefits... ...dairy and trucking. They are looking for Senior Full Stack Web Developers who can come in... ...needs are met. Provides custom web application development using the.NET Framework, C#,...ApplicationSeniorWebImmediate start
$60k - $80k
...of the Concept Schools brand voice, ensuring consistency across web content, social media, email, print materials, video scripts,... ...assistance ~ Tuition reimbursement ~ Vision insurance Application Question(s): ~ Please briefly describe your experience in marketing...ApplicationWebFull timeContract workWork at officeLocal areaRemote workRelocation packageShift workAfternoon shift$86k - $107k
...Objective of Position : The Salesforce Engineer is responsible for design, build, and... ...Services Cloud (FSC) , and Marketing related applications . This role will also be involved in... ...for developing in Apex, Lightning Web Components, Lightning Design System, and...ApplicationWebWork experience placementWork at officeRemote work$140k
...Systems Engineer-Senior Lead Networking Specialist - Hybrid (Illinois... ...of industry standards and security best practices. DUTIES... ...Data Center networking and firewalls. Lead the team in the implementation... ...Microsoft 365 products and applications, including the ability to...ApplicationSeniorFull timeRemote workMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer- Web Application Firewall. Be the first to apply!
- sr information security engineer Schaumburg, IL
- senior application security engineer Schaumburg, IL
- senior brand designer Schaumburg, IL
- senior underwriter Schaumburg, IL
- senior business analyst contract Schaumburg, IL
- senior digital account manager Schaumburg, IL
- senior account executive Schaumburg, IL
- senior database analyst Schaumburg, IL
- legal senior counsel family office Schaumburg, IL
- senior aws cloud engineer Schaumburg, IL


