IND Lead Engineer, Security - Web Application and API Protection Security Engineer
The HartfordMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Design, implement, and manage enterprise-scale Web Application and API Protection (WAAP) solutions including threat detection, bot management, and DoS mitigation.
Operate and maintain The Hartford’s enterprise Web Application Firewall (WAF) and API security platforms, including cloud-native deployments across AWS, Azure, and GCP.
Develop and optimize security policies, monitor application-layer threats, conduct incident response, and produce security posture reports and dashboards.
Minimum Requirements
Bachelor's degree in Information Security, Computer Science, Cybersecurity, or related field (or equivalent experience).
Minimum 3 years of experience in application security, web security, network security, or related cybersecurity roles.
Hands-on experience with WAAP technologies such as Akamai WAF & API Security, Apigee API Management, AWS WAF, or Google Cloud Armor.
Strong understanding of OWASP Top 10, OWASP API Security Top 10, and authentication/authorization protocols like OAuth2, OIDC, and SAML.
Ideal Candidate Profile
Experienced in managing and deploying enterprise WAF and API security programs with measurable impact on threat mitigation.
Skilled in integrating WAAP solutions into cloud environments (AWS, Azure, GCP) and collaborating cross-functionally with application development and cybersecurity teams.
Capable of using SIEM, security monitoring tools, and analytics to optimize security policies and support incident response activities.
