IT 安全 - 资深
IT Security -Senior
职位:IT安全 - 高级
职位编号:JD-1182
能力等级:未说明
开始日期:2026-10-01
结束日期:2026-12-31
续约选项:是
范围:100%
地点:远程
远程工作:100%
语言:英语
申请截止日期:2026-09-25
咨询顾问人数:3
安全许可:无
关于该职位
我们的客户正在寻找临时加强Cloudflare WAF服务的支持和运营团队,以应对高峰期的需求。该职位将涉及管理与IT安全相关的事件、变更请求和操作任务。
职责
- 通过ServiceNow管理并解决与Cloudflare WAF相关的事件、服务请求和变更请求。
- 处理符合定义SLA目标的日常操作工单。
- 对安全事件和应用访问问题进行根本原因分析(RCA)。
- 与应用、基础设施、网络和安全团队协调以解决问题。
- 参与重大事件电话会议,并在停机期间提供技术支持。
- 监控Cloudflare安全事件、警报和仪表板。
- 调查并排查被阻止的流量、误报和应用功能问题。
- 优化Cloudflare托管规则、自定义规则、速率限制规则和机器人防护策略。
- 审查WAF日志和安全分析,识别威胁并提出改进建议。
- 支持应用程序到Cloudflare的上线和下线。
- 通过ServiceNow变更管理流程实施已批准的变更。
- 部署并验证WAF策略更新、ACL更改、SSL证书修改和DNS更新。
- 执行预生产及实施后的验证。
- 支持计划维护和生产切换。
- 排查应用连接性、DNS解析、SSL/TLS证书和Cloudflare隧道问题。
- 与应用团队合作,识别并解决流量路由和安全策略问题。
- 分析HTTP/S流量、网络追踪和Cloudflare日志以解决相关问题。
- 创建和管理WAF规则、防火墙策略、IP列表、速率限制和机器人缓解控制。
- 支持DDoS保护配置和攻击缓解活动。
- 实施安全基线和已批准的例外请求。
- 确保Cloudflare配置符合组织的安全标准。
- 监控受保护应用的服务健康状况和安全态势。
- 准备每周和每月的运营报告。
查看英文原文
Role: IT Security -Senior
Job Ref Id: JD-1182
Competence level: Not stated
Start date: 2026-10-01
End date: 2026-12-31
Extension option: Yes
Scope: 100%
Location: Remote
Remote work: 100%
Language: English
Application deadline: 2026-09-25
Number of consultants: 3
Security clearance: No
About the assignment
Our client is seeking to temporarily strengthen their support and operations team for the Cloudflare WAF service during a peak period. The assignment will involve managing incidents, change requests, and operational tasks related to IT security.
Responsibilities
- Manage and resolve Cloudflare WAF-related incidents, service requests, and change requests through ServiceNow.
- Handle daily operational tickets within defined SLA targets.
- Perform root cause analysis (RCA) for security incidents and application access issues.
- Coordinate with Application, Infrastructure, Network, and Security teams for issue resolution.
- Participate in major incident calls and provide technical support during outages.
- Monitor Cloudflare security events, alerts, and dashboards.
- Investigate and troubleshoot blocked traffic, false positives, and application functionality issues.
- Fine-tune Cloudflare Managed Rules, Custom Rules, Rate Limiting Rules, and Bot Protection policies.
- Review WAF logs and security analytics to identify threats and recommend improvements.
- Support onboarding and offboarding of applications to Cloudflare.
- Implement approved changes through ServiceNow change management processes.
- Deploy and validate WAF policy updates, ACL changes, SSL certificate modifications, and DNS updates.
- Perform pre-production and post-implementation validation.
- Support planned maintenance and production cutovers.
- Troubleshoot application connectivity, DNS resolution, SSL/TLS certificate, and Cloudflare Tunnel issues.
- Work with application teams to identify and resolve traffic routing and security policy issues.
- Analyze HTTP/S traffic, network traces, and Cloudflare logs for problem resolution.
- Create and manage WAF rules, firewall policies, IP lists, rate limits, and bot mitigation controls.
- Support DDoS protection configurations and attack mitigation activities.
- Implement security baselines and approved exception requests.
- Ensure Cloudflare configurations comply with organizational security standards.
- Monitor service health and security posture of protected applications.
- Prepare weekly and monthly operational reports.
- Track onboarding status, incidents, change success rates, and attack mitigation metrics.
- Maintain operational dashboards and KPI reporting.
- Maintain operational runbooks, SOPs, and knowledge base articles.
- Update architecture diagrams and support documentation.
- Participate in security reviews, audits, and compliance activities.
- Support risk assessments and security exception processes.
Requirements
Mandatory
- Strong knowledge in Cloudflare WAF
- Hands-on experience with ServiceNow Incident, Request, Problem, and Change Management.
- Experience supporting Cloudflare WAF in a 24x7 enterprise environment.
- Strong troubleshooting skills for DNS, SSL/TLS, HTTP/S, Load Balancing, and Application Security.
- Familiarity with Cloudflare WAF, DDoS, Bot Management, Zero Trust, and Cloudflare Tunnels.
- Experience working with Azure, AWS, on prem, and enterprise application environments.
Originally posted on Himalayas