Job Description Job Description About Zipline Zipline is the world's largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world's largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products. Our customers include the world's largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we've built to enable seamless, reliable, global operations. Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe. We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people's lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds. About You and The Role Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real-world operational environments. You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission-critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure. You will join a small, high-ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure. This is a hybrid onsite role: you will be at our South San Francisco HQ frequently and must be available for occasional travel to distribution centers and test sites. What You'll Do Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire. Deliver measurable risk reduction: define baseline metrics (e.g., mean-time-to-detect, mean-time-to-remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high-risk findings by 50% in owned services; reduce MTTD for critical alerts to Design and implement production controls: IAM/least-privilege policies, service-to-service trust, key lifecycle and KMS integrations, runtime telemetry and alerting, secure OTA/update patterns for edge devices, and hardened CI/CD pipelines and build artifact provenance. Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering-tractable mitigations and drive their rollout to completion. Lead vulnerability management end-to-end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention. Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic-ready, and participate in incident postmortems with corrective action tracking. Secure AI/agent-assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems. Integrate external pentest and red-team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria. Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health-adjacent data handling, auditability) into concrete technical controls. What You'll Bring Hard requirements (must-haves): 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure. Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies). Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models. Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services. Direct experience threat modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows). Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6-12 months. Non-negotiable traits: Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement. Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows. Additional strong qualifications (if present): Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse). Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer-friendly security platforms or paved-road tooling. What Else You Need To Know This is a hybrid role based in South San Francisco; frequent HQ presence required and occasional travel to field sites. This role has production ownership and will participate in incident response; candidates must be prepared for on-call participation when assigned. Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities. We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply! Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. As set forth in Zipline 's Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
09/07/2026
Full time
Job Description Job Description About Zipline Zipline is the world's largest and most experienced drone delivery service. We are on a mission to serve all humans equally by ensuring access to food, medicine and essential goods anytime, anywhere. We design, build, and operate the world's largest autonomous logistics system, delivering critical supplies quickly and reliably. Today, Zipline operates on four continents, makes a delivery somewhere in the world every 30 seconds, and has completed millions of deliveries to date, including blood, vaccines, medical supplies, food, and retail products. Our customers include the world's largest and most prominent healthcare systems, governments, retailers, restaurants and global businesses who rely on us to save lives, reduce emissions, increase economic opportunity, and provide delivery from point A to point B as fast as possible. The drone is only 15% of what we've built to enable seamless, reliable, global operations. Our system strengthens supply chains, reduces congestion, and gives people time back. With more than 140 million commercial autonomous miles safely flown, Zipline is redefining access to healthcare, consumer products, and food across the globe. We operate at a global scale and are looking for practical problem solvers who thrive on real-world challenges and rapid growth. Our team is motivated by building systems that have a direct, meaningful impact on people's lives and by scaling the future of logistics. We are seeking people who sculpt from first principles, enjoy facing adversity, and can do the impossible at record breaking speeds. About You and The Role Product security at Zipline protects systems that directly affect safety, regulatory compliance, and uninterrupted delivery of critical goods in real-world operational environments. You will own security for production services and integrations that run our fleet orchestration, distribution center automation, telemetry/teleoperation, and developer/operator toolchains. This role is mission-critical: your work will reduce attack surface that could cause service outages, unsafe drone behavior, data exposure of patient/partner data, or regulatory failure. You will join a small, high-ownership security team and partner deeply with software, infrastructure, autonomy/embedded, and field-ops teams. Expect hands-on engineering work, prioritized ownership of specific services, and a mandate to ship controls that measurably reduce risk in production systems under operational pressure. This is a hybrid onsite role: you will be at our South San Francisco HQ frequently and must be available for occasional travel to distribution centers and test sites. What You'll Do Own security outcomes for 2-4 named production areas (examples: fleet orchestration APIs, DC orchestration/robotics control plane, telemetry and command channels, developer CI/CD and secrets platforms). Be the primary security owner for at least one area on hire. Deliver measurable risk reduction: define baseline metrics (e.g., mean-time-to-detect, mean-time-to-remediate, number of exploitable findings) and be accountable to improving them by defined targets in 6 and 12 months (example targets: cut exploitable high-risk findings by 50% in owned services; reduce MTTD for critical alerts to Design and implement production controls: IAM/least-privilege policies, service-to-service trust, key lifecycle and KMS integrations, runtime telemetry and alerting, secure OTA/update patterns for edge devices, and hardened CI/CD pipelines and build artifact provenance. Threat model and perform secure design reviews for services that operate near the physical fleet, regulated workflows, or partner/customer interfaces; produce engineering-tractable mitigations and drive their rollout to completion. Lead vulnerability management end-to-end for owned services: vulnerability triage with exploitability analysis, prioritized remediation plans with engineering partners, staged verification, and verification metrics for closure and regression prevention. Build and harden incident response for product incidents: author playbooks, run tabletop exercises with product and operations, validate logging/auditability so incidents are forensic-ready, and participate in incident postmortems with corrective action tracking. Secure AI/agent-assisted development and ops: define allowed copilots and patterns, implement guardrails to prevent secret exposure and unauthorized actions, and add monitoring/auditing for risky agent behaviors where it intersects owned systems. Integrate external pentest and red-team results into durable engineering changes; turn test findings into tracked engineering tickets and measurable closure criteria. Collaborate daily with SREs, platform engineers, autonomy/embedded teams, field ops, and compliance to translate regulatory/safety requirements (e.g., health-adjacent data handling, auditability) into concrete technical controls. What You'll Bring Hard requirements (must-haves): 8+ years building and operating security controls for large-scale production systems across application and cloud infrastructure. Demonstrable hands-on engineering ability: you ship automation or tooling in Python, Go, or similar and can build integrations with AI tools and agentic security bots (not only write policies). Deep practical experience with cloud-native stacks and microservices (Kubernetes, containers, IAM, CI/CD, secrets management, logging/telemetry) and with designing least-privilege service-to-service models. Prior ownership of vulnerability management, incident response playbooks, and verification processes for production services. Direct experience threat modeling and securing systems that interface with physical systems, regulated workflows, or third-party partners (embedded, teleoperation, field ops, or healthcare-adjacent data flows). Ability to define and track quantitative success metrics (MTTD, MTTR, number of exploitable findings, compliance audit readiness) and be accountable for meeting targets within 6-12 months. Non-negotiable traits: Operates as a technical owner: can persuade engineering teams, prioritize trade-offs, and drive changes through to production without relying solely on policy enforcement. Skeptical, adversarial mindset: anticipates failure modes and abuse cases for systems that interact with the physical fleet and partner workflows. Additional strong qualifications (if present): Experience securing LLM/agentic tools in engineering workflows and mitigating OWASP LLM risks (prompt injection, unsafe plugin/output handling, agentic privilege misuse). Background across multiple domains (cloud infra, web services, and embedded/autonomy) and experience building developer-friendly security platforms or paved-road tooling. What Else You Need To Know This is a hybrid role based in South San Francisco; frequent HQ presence required and occasional travel to field sites. This role has production ownership and will participate in incident response; candidates must be prepared for on-call participation when assigned. Zipline is an equal opportunity employer and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws or our own sensibilities. We value diversity at Zipline and welcome applications from those who are traditionally underrepresented in tech. If you like the sound of this position but are not sure if you are the perfect fit, please apply! Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. As set forth in Zipline 's Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
Job Description Job Description Position Overview Blue Acorn iCi is seeking a Business Consultant Digital Experience who can move fluidly between strategy and execution-from ideation and UX prototyping to validating with real users and shipping working features alongside engineering. Location: Hybrid - Onsite 3 days a week expected in San Jose, CA Key ResponsibilitiesStrategy, Discovery & UX Prototyping Lead ideation and discovery sessions to define problems worth solving. Build low to high fidelity UX prototypes, including wireframes and clickable mockups. Run validation sessions with end users, synthesize feedback, and refine designs iteratively. Product Development & Marketing Strategy Partner with developers to translate validated concepts into a React-based web application. Apply marketing strategy, planning, and operational knowledge to shape product direction. Business & Financial Strategy Use financial acumen to build business cases, prioritize features by ROI, and support budget or forecasting conversations. Present findings and recommendations to stakeholders, including senior leadership. Create documentation and guides to enable user onboarding and enablement. Required Skills & Experience 6-9 years in business consulting, product strategy, or a hybrid UX/strategy role. Hands-on experience with prototyping tools such as Figma or equivalent. Working knowledge of React or close collaboration experience with front-end teams. Background in marketing strategy, planning, and operations. Finance background, including budgeting, business case development, or financial analysis. Strong facilitation skills for user research and stakeholder workshops. Ability to communicate clearly with both technical and executive audiences. Preferred Qualifications/Education Prior experience with Adobe Workfront Planning or Workfront Workflow solutions is strongly preferred. Compensation The base salary range for this position is $125,000-$175,000 annually. Actual compensation may vary depending on experience, qualifications, geographic location, and other job-related factors. About Blue Acorn iCi Blue Acorn iCi, a business unit of Infosys Nova Holdings, LLC, is a digital experience partner helping global brands design, build, and optimize the future of customer engagement. We blend data, design, and technology to deliver connected commerce and content solutions that drive measurable results. Specializing in the Adobe Experience Cloud, we provide end-to-end services across commerce, content, analytics, and customer insights. Backed by Infosys, we're growing fast-and we're looking for exceptional talent to grow with us. Our teams work at the intersection of strategy and execution-solving complex challenges for industry leaders in healthcare, retail, manufacturing, and beyond. From large-scale digital transformation programs to platform implementations and ongoing optimization, we bring deep expertise and a collaborative mindset to every engagement. Why Join Us? Blue Acorn iCi is a place for curious thinkers, smart builders, and digital pioneers. We're more than a consultancy-we're a team of innovators helping the world's top brands shape the future of digital. Here, you won't just contribute to a project-you'll drive meaningful outcomes, collaborate with cross-disciplinary teams, and grow your skills in a high-impact, high-growth environment. We believe great work starts with great people, and we're committed to creating a culture where talent thrives, ideas spark change, and results speak for themselves. If you're ready to push boundaries, deliver real value, and help shape the next generation of digital experiences-this is your place. For US based roles, candidates must have unrestricted authorization to work in the United States without the need for employer sponsorship now or in the future. Infosys Nova Holdings, LLC does not provide immigration or visa sponsorship for this position (including H4 EAD, H 1B, OPT, CPT, TN, O 1, E 3, or J 1 visas). Full Time, Non-Temporary Employees enjoy a competitive benefits package that includes medical, dental and vision insurance, life insurance, disability, paid time off, 401(k), and more! Blue Acorn iCi is an equal opportunity employer and all qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, spouse of protected veteran, or disability. Please click to read EEO Law and Pay Transparency Act and IER Right to Work Document and Privacy Notice. Blue Acorn iCi will endeavor to make a reasonable accommodation to the known physical or mental limitations of a qualified applicant with a disability unless the accommodation would impose an undue hardship on the operation of our business. If you believe you require such assistance to complete this form or to participate in an interview, please contact us at: . California applicants: Please click here for CCPA disclosures. Powered by JazzHR ex8K2STuFS
09/07/2026
Full time
Job Description Job Description Position Overview Blue Acorn iCi is seeking a Business Consultant Digital Experience who can move fluidly between strategy and execution-from ideation and UX prototyping to validating with real users and shipping working features alongside engineering. Location: Hybrid - Onsite 3 days a week expected in San Jose, CA Key ResponsibilitiesStrategy, Discovery & UX Prototyping Lead ideation and discovery sessions to define problems worth solving. Build low to high fidelity UX prototypes, including wireframes and clickable mockups. Run validation sessions with end users, synthesize feedback, and refine designs iteratively. Product Development & Marketing Strategy Partner with developers to translate validated concepts into a React-based web application. Apply marketing strategy, planning, and operational knowledge to shape product direction. Business & Financial Strategy Use financial acumen to build business cases, prioritize features by ROI, and support budget or forecasting conversations. Present findings and recommendations to stakeholders, including senior leadership. Create documentation and guides to enable user onboarding and enablement. Required Skills & Experience 6-9 years in business consulting, product strategy, or a hybrid UX/strategy role. Hands-on experience with prototyping tools such as Figma or equivalent. Working knowledge of React or close collaboration experience with front-end teams. Background in marketing strategy, planning, and operations. Finance background, including budgeting, business case development, or financial analysis. Strong facilitation skills for user research and stakeholder workshops. Ability to communicate clearly with both technical and executive audiences. Preferred Qualifications/Education Prior experience with Adobe Workfront Planning or Workfront Workflow solutions is strongly preferred. Compensation The base salary range for this position is $125,000-$175,000 annually. Actual compensation may vary depending on experience, qualifications, geographic location, and other job-related factors. About Blue Acorn iCi Blue Acorn iCi, a business unit of Infosys Nova Holdings, LLC, is a digital experience partner helping global brands design, build, and optimize the future of customer engagement. We blend data, design, and technology to deliver connected commerce and content solutions that drive measurable results. Specializing in the Adobe Experience Cloud, we provide end-to-end services across commerce, content, analytics, and customer insights. Backed by Infosys, we're growing fast-and we're looking for exceptional talent to grow with us. Our teams work at the intersection of strategy and execution-solving complex challenges for industry leaders in healthcare, retail, manufacturing, and beyond. From large-scale digital transformation programs to platform implementations and ongoing optimization, we bring deep expertise and a collaborative mindset to every engagement. Why Join Us? Blue Acorn iCi is a place for curious thinkers, smart builders, and digital pioneers. We're more than a consultancy-we're a team of innovators helping the world's top brands shape the future of digital. Here, you won't just contribute to a project-you'll drive meaningful outcomes, collaborate with cross-disciplinary teams, and grow your skills in a high-impact, high-growth environment. We believe great work starts with great people, and we're committed to creating a culture where talent thrives, ideas spark change, and results speak for themselves. If you're ready to push boundaries, deliver real value, and help shape the next generation of digital experiences-this is your place. For US based roles, candidates must have unrestricted authorization to work in the United States without the need for employer sponsorship now or in the future. Infosys Nova Holdings, LLC does not provide immigration or visa sponsorship for this position (including H4 EAD, H 1B, OPT, CPT, TN, O 1, E 3, or J 1 visas). Full Time, Non-Temporary Employees enjoy a competitive benefits package that includes medical, dental and vision insurance, life insurance, disability, paid time off, 401(k), and more! Blue Acorn iCi is an equal opportunity employer and all qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, spouse of protected veteran, or disability. Please click to read EEO Law and Pay Transparency Act and IER Right to Work Document and Privacy Notice. Blue Acorn iCi will endeavor to make a reasonable accommodation to the known physical or mental limitations of a qualified applicant with a disability unless the accommodation would impose an undue hardship on the operation of our business. If you believe you require such assistance to complete this form or to participate in an interview, please contact us at: . California applicants: Please click here for CCPA disclosures. Powered by JazzHR ex8K2STuFS
Job Description Job Description Description: Hybrid 50% onsite in Westlake, TX Our client is hiring a Senior Software Engineer in Test (SDET) to build robust automation frameworks and drive end-to-end testing across UI and API layers for digital healthcare solutions. You will use Playwright or Cypress with TypeScript or JavaScript to create scalable and maintainable test solutions, and apply BDD practices with Cucumber to enhance collaboration and test clarity. You will work in an Agile environment with developers, product teams, and stakeholders to embed quality throughout the lifecycle, contribute to CI/CD pipelines, improve code quality standards, and ensure performance, security, reliability, and user experience meet expectations. The role includes opportunities to mentor junior engineers, influence best practices, and help shape testing strategy in a collaborative environment. Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance. Rate: $55.00 to $65.00/hr. w2 Responsibilities: Design, develop, and maintain automated test suites for web-based healthcare products. Build and enhance test frameworks using Playwright or Cypress. Develop UI and API automation using TypeScript or JavaScript. Support testing of RESTful APIs. Collaborate with product owners, developers, and stakeholders in Agile or Scrum environments. Experience Requirements: 6+ years of experience in software testing or development with a focus on automation. Strong experience building frameworks using Playwright and/or Cypress. Hands-on expertise with TypeScript and/or JavaScript. Experience with BDD frameworks such as Cucumber. Strong API testing experience with REST. Experience creating test plans and test cases. Preferred: Accessibility testing experience. Preferred: Exposure to healthcare or regulated environments. Education Requirements: Bachelor's degree or higher in Computer Science or a related field. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/07/2026
Full time
Job Description Job Description Description: Hybrid 50% onsite in Westlake, TX Our client is hiring a Senior Software Engineer in Test (SDET) to build robust automation frameworks and drive end-to-end testing across UI and API layers for digital healthcare solutions. You will use Playwright or Cypress with TypeScript or JavaScript to create scalable and maintainable test solutions, and apply BDD practices with Cucumber to enhance collaboration and test clarity. You will work in an Agile environment with developers, product teams, and stakeholders to embed quality throughout the lifecycle, contribute to CI/CD pipelines, improve code quality standards, and ensure performance, security, reliability, and user experience meet expectations. The role includes opportunities to mentor junior engineers, influence best practices, and help shape testing strategy in a collaborative environment. Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance. Rate: $55.00 to $65.00/hr. w2 Responsibilities: Design, develop, and maintain automated test suites for web-based healthcare products. Build and enhance test frameworks using Playwright or Cypress. Develop UI and API automation using TypeScript or JavaScript. Support testing of RESTful APIs. Collaborate with product owners, developers, and stakeholders in Agile or Scrum environments. Experience Requirements: 6+ years of experience in software testing or development with a focus on automation. Strong experience building frameworks using Playwright and/or Cypress. Hands-on expertise with TypeScript and/or JavaScript. Experience with BDD frameworks such as Cucumber. Strong API testing experience with REST. Experience creating test plans and test cases. Preferred: Accessibility testing experience. Preferred: Exposure to healthcare or regulated environments. Education Requirements: Bachelor's degree or higher in Computer Science or a related field. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Job Description Job Description Description: Hybrid 2 weeks per month onsite in Westlake, TX Our client is seeking a Senior Software Engineer in Test to join a Digital Solutions team supporting enterprise web applications and digital platforms. The ideal candidate is passionate about modern technologies and has a strong background in software quality engineering, test automation, Agile development, continuous integration, and software development best practices. This individual will serve as a technical lead for test automation initiatives, ensuring application quality through the design, development, and execution of automated functional, regression, integration, and API test suites. Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance. Rate: $60.00 to $65.00/hr. w2 Responsibilities: Design, develop, and maintain automated test frameworks to support enterprise applications. Develop and execute automated functional, regression, integration, and API test suites. Perform manual testing when appropriate to validate application functionality and quality. Lead test automation efforts and establish automation best practices across Agile development teams. Create and implement test automation strategies and roadmaps aligned with project objectives. Collaborate closely with software engineers, business analysts, and product owners to define test scenarios and acceptance criteria. Design, develop, and execute API and service-level testing using modern testing frameworks. Develop UI automation tests for web-based applications using Selenium and BDD frameworks. Experience Requirements: Bachelor's Degree in Computer Science or related field or equivalent experience. 5+ years of experience in a QA or Developer role. Deep understanding of manual and automated testing concepts, including BDD. Strong object-oriented programming skills. Experience with Java/JEE and JavaScript. Experience with Selenium using Java or JavaScript, and Cucumber BDD framework. Service testing experience with Karate and/or REST Assured, or SOATest/SoapUI. Experience with Oracle SQL. Experience using CI tools such as Jenkins, Maven, and Git. Experience with the Atlassian stack is preferred. Experience with UI testing frameworks such as Galen or PhantomCSS is a plus. Experience with service virtualization tools such as WireMock or Parasoft Virtualize is a plus. Knowledge of CMS platforms such as Sitecore or Documentum is a plus. Proven leadership with a track record of designing and building test automation frameworks. Ability to create strategies and roadmaps for test automation and lead implementation. Strong communication skills and curiosity about learning new technologies. Ability to document and develop technical designs for test automation and partner with analysts and developers. Ability to break down business requirements and recommend solutions. Effectiveness as both a team member and individual contributor. Provide automation solutions across front end, services, and back end data providers. Participate in scrum activities including test coverage reviews, grooming, and sprint planning. Develop and execute automated and manual test scripts for functional and regression testing. Document, maintain, and monitor software problems. Education Requirements: Bachelor's Degree in Computer Science or related field or equivalent experience. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/07/2026
Full time
Job Description Job Description Description: Hybrid 2 weeks per month onsite in Westlake, TX Our client is seeking a Senior Software Engineer in Test to join a Digital Solutions team supporting enterprise web applications and digital platforms. The ideal candidate is passionate about modern technologies and has a strong background in software quality engineering, test automation, Agile development, continuous integration, and software development best practices. This individual will serve as a technical lead for test automation initiatives, ensuring application quality through the design, development, and execution of automated functional, regression, integration, and API test suites. Due to client requirements, applicants must be willing and able to work on a w2 basis. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance. Rate: $60.00 to $65.00/hr. w2 Responsibilities: Design, develop, and maintain automated test frameworks to support enterprise applications. Develop and execute automated functional, regression, integration, and API test suites. Perform manual testing when appropriate to validate application functionality and quality. Lead test automation efforts and establish automation best practices across Agile development teams. Create and implement test automation strategies and roadmaps aligned with project objectives. Collaborate closely with software engineers, business analysts, and product owners to define test scenarios and acceptance criteria. Design, develop, and execute API and service-level testing using modern testing frameworks. Develop UI automation tests for web-based applications using Selenium and BDD frameworks. Experience Requirements: Bachelor's Degree in Computer Science or related field or equivalent experience. 5+ years of experience in a QA or Developer role. Deep understanding of manual and automated testing concepts, including BDD. Strong object-oriented programming skills. Experience with Java/JEE and JavaScript. Experience with Selenium using Java or JavaScript, and Cucumber BDD framework. Service testing experience with Karate and/or REST Assured, or SOATest/SoapUI. Experience with Oracle SQL. Experience using CI tools such as Jenkins, Maven, and Git. Experience with the Atlassian stack is preferred. Experience with UI testing frameworks such as Galen or PhantomCSS is a plus. Experience with service virtualization tools such as WireMock or Parasoft Virtualize is a plus. Knowledge of CMS platforms such as Sitecore or Documentum is a plus. Proven leadership with a track record of designing and building test automation frameworks. Ability to create strategies and roadmaps for test automation and lead implementation. Strong communication skills and curiosity about learning new technologies. Ability to document and develop technical designs for test automation and partner with analysts and developers. Ability to break down business requirements and recommend solutions. Effectiveness as both a team member and individual contributor. Provide automation solutions across front end, services, and back end data providers. Participate in scrum activities including test coverage reviews, grooming, and sprint planning. Develop and execute automated and manual test scripts for functional and regression testing. Document, maintain, and monitor software problems. Education Requirements: Bachelor's Degree in Computer Science or related field or equivalent experience. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Job Description Job Description Job Title: Senior Security Engineer - Web Application & Network Protection (Contract to Hire) Location: Columbus, OH (Local Candidates only) Rate: $70-$79/hour Work Model: Hybrid (Onsite Tuesday-Thursday, Remote Monday & Friday) Contract Length: July 27, 2026 - July 26, 2027 Extension / Conversion: Contract-to-Hire Employment Type: W-2 Only Work Authorization: U.S. Citizens Only Green Card holders also eligible; no visa sponsorship available Position Overview We are seeking an experienced Senior Security Engineer - Web Application & Network Protection to lead the design, implementation, and support of enterprise web application and network security solutions. This role is responsible for protecting internet-facing applications and critical enterprise services through a combination of web application firewall (WAF) technologies, API security, bot protection, DDoS mitigation, and network security controls. The ideal candidate brings a strong mix of application security, network security, cloud security, and automation experience, with hands-on expertise supporting technologies such as F5 Distributed Cloud WAF, Palo Alto Networks firewalls, and secure remote access platforms. This individual will partner across security, infrastructure, networking, cloud, and application teams to strengthen enterprise defenses, improve operational efficiency, and support secure onboarding of business-critical applications. This is a strong fit for a cybersecurity engineer who is equally comfortable with security architecture, operational support, incident response, automation, and stakeholder collaboration in a modern enterprise environment. Key ResponsibilitiesWeb Application Security Administer and support the F5 Distributed Cloud (XC) WAF platform. Deploy, configure, and maintain WAF policies, signatures, and security controls for internet-facing applications. Configure and optimize protections related to: API Protection Bot Defense / Bot Management DDoS Mitigation Geolocation Policies Rate Limiting CAPTCHA Challenges Investigate and tune false positives to balance protection with business usability. Perform application onboarding into WAF services and support secure rollout of web-facing applications. Conduct policy reviews and continuous optimization of WAF protections. Support investigation and response activities related to web application attacks and anomalous traffic. Application Security Apply strong understanding of common web and API threats, including: OWASP Top 10 Authentication attacks API abuse Credential stuffing Session hijacking Cross-Site Scripting (XSS) SQL Injection SSRF CSRF Review application architectures and recommend improvements to strengthen security posture. Partner with development and engineering teams during application onboarding, remediation, and troubleshooting. Help ensure secure design considerations are integrated into enterprise application delivery and support processes. Network Security Administer and support key network security technologies, including: Palo Alto Networks NGFW Prisma Access Site-to-site VPNs SSL decryption NAT and security policies Network segmentation Support DNS and routing troubleshooting related to protected applications and network flows. Assist with production security incidents and operational support activities. Participate in an on-call rotation as needed to support enterprise services and incident response. Cloud, Automation & DevSecOps Develop and maintain automation solutions using: Python REST APIs Terraform Git Automate repetitive operational tasks to improve consistency, scalability, and efficiency. Build dashboards, reporting, and visibility tools to help monitor security posture and operational performance. Support DevSecOps and CI/CD practices by partnering with engineering teams to embed security into deployment pipelines and operational processes. Contribute to secure infrastructure and application delivery practices across cloud and containerized environments. Security Operations & Continuous Improvement Participate in: Incident response Threat hunting Security assessments Vulnerability remediation Root cause analysis Architecture reviews Support identification and remediation of vulnerabilities affecting web applications, APIs, and network security infrastructure. Contribute to ongoing enhancement of detection, prevention, and response capabilities. Provide recommendations to improve operational security controls, reduce risk, and strengthen enterprise resilience. Day-to-Day Responsibilities Administer and tune WAF, API security, bot protection, and DDoS controls for enterprise applications. Onboard applications into F5 Distributed Cloud WAF and coordinate with application teams on requirements and troubleshooting. Review alerts, investigate suspicious activity, and respond to web application or network security incidents. Manage Palo Alto firewall policies, Prisma Access configurations, VPNs, and related network security controls. Support false positive analysis and policy optimization across application security tools. Develop scripts and automation to improve security operations and reduce manual effort. Collaborate with developers, infrastructure engineers, network teams, and security stakeholders to improve protections and resolve issues. Participate in architecture reviews, security assessments, and remediation planning. Required Qualifications 7+ years of experience in cybersecurity engineering, with strong focus on web application security, network security, or cloud security. Hands-on experience administering and supporting web application firewall (WAF) technologies in an enterprise environment. Experience with F5 Distributed Cloud (XC) WAF or comparable advanced WAF platforms. Strong understanding of: Web application attacks API security threats Bot mitigation DDoS protection Authentication and session-related attack patterns Experience supporting Palo Alto Networks security technologies, including NGFW and/or Prisma Access. Experience with network security concepts such as VPNs, SSL decryption, NAT, segmentation, DNS, and routing troubleshooting. Experience with automation and scripting using Python, REST APIs, Terraform, and Git. Familiarity with DevSecOps and CI/CD pipelines. Strong incident response, troubleshooting, and problem-solving skills. Ability to work across infrastructure, cloud, networking, development, and security teams in a collaborative environment. Preferred Qualifications Experience with: Bot Management API Security DDoS Protection CDN technologies Kubernetes Containers Terraform DevSecOps CI/CD pipelines Experience building security dashboards, posture reporting, or automation tooling. Familiarity with secure cloud-native application delivery and modern edge security architectures. Experience in regulated, utility, or large enterprise environments is a plus. Preferred Certifications OWASP Foundation certifications ISC2 CISSP GIAC certifications F5 certifications Palo Alto Networks certifications Core Competencies Web Application Security WAF Administration API Security Bot Management DDoS Mitigation Network Security Palo Alto Networks Prisma Access Cloud Security DevSecOps Security Automation Incident Response Ideal Candidate Profile The ideal candidate is a hands-on senior cybersecurity engineer with strong expertise in securing internet-facing applications and enterprise network environments. They are comfortable working across WAF platforms, firewalls, APIs, automation, and cloud-connected services, and they know how to balance operational support with strategic improvements to security posture. This person is proactive, technically deep, and effective at partnering across teams to protect critical enterprise services. Additional Notes This is a contract-to-hire opportunity. The role requires a hybrid onsite schedule in Columbus, OH. Candidates must be authorized to work in the United States now and in the future without sponsorship.
09/07/2026
Full time
Job Description Job Description Job Title: Senior Security Engineer - Web Application & Network Protection (Contract to Hire) Location: Columbus, OH (Local Candidates only) Rate: $70-$79/hour Work Model: Hybrid (Onsite Tuesday-Thursday, Remote Monday & Friday) Contract Length: July 27, 2026 - July 26, 2027 Extension / Conversion: Contract-to-Hire Employment Type: W-2 Only Work Authorization: U.S. Citizens Only Green Card holders also eligible; no visa sponsorship available Position Overview We are seeking an experienced Senior Security Engineer - Web Application & Network Protection to lead the design, implementation, and support of enterprise web application and network security solutions. This role is responsible for protecting internet-facing applications and critical enterprise services through a combination of web application firewall (WAF) technologies, API security, bot protection, DDoS mitigation, and network security controls. The ideal candidate brings a strong mix of application security, network security, cloud security, and automation experience, with hands-on expertise supporting technologies such as F5 Distributed Cloud WAF, Palo Alto Networks firewalls, and secure remote access platforms. This individual will partner across security, infrastructure, networking, cloud, and application teams to strengthen enterprise defenses, improve operational efficiency, and support secure onboarding of business-critical applications. This is a strong fit for a cybersecurity engineer who is equally comfortable with security architecture, operational support, incident response, automation, and stakeholder collaboration in a modern enterprise environment. Key ResponsibilitiesWeb Application Security Administer and support the F5 Distributed Cloud (XC) WAF platform. Deploy, configure, and maintain WAF policies, signatures, and security controls for internet-facing applications. Configure and optimize protections related to: API Protection Bot Defense / Bot Management DDoS Mitigation Geolocation Policies Rate Limiting CAPTCHA Challenges Investigate and tune false positives to balance protection with business usability. Perform application onboarding into WAF services and support secure rollout of web-facing applications. Conduct policy reviews and continuous optimization of WAF protections. Support investigation and response activities related to web application attacks and anomalous traffic. Application Security Apply strong understanding of common web and API threats, including: OWASP Top 10 Authentication attacks API abuse Credential stuffing Session hijacking Cross-Site Scripting (XSS) SQL Injection SSRF CSRF Review application architectures and recommend improvements to strengthen security posture. Partner with development and engineering teams during application onboarding, remediation, and troubleshooting. Help ensure secure design considerations are integrated into enterprise application delivery and support processes. Network Security Administer and support key network security technologies, including: Palo Alto Networks NGFW Prisma Access Site-to-site VPNs SSL decryption NAT and security policies Network segmentation Support DNS and routing troubleshooting related to protected applications and network flows. Assist with production security incidents and operational support activities. Participate in an on-call rotation as needed to support enterprise services and incident response. Cloud, Automation & DevSecOps Develop and maintain automation solutions using: Python REST APIs Terraform Git Automate repetitive operational tasks to improve consistency, scalability, and efficiency. Build dashboards, reporting, and visibility tools to help monitor security posture and operational performance. Support DevSecOps and CI/CD practices by partnering with engineering teams to embed security into deployment pipelines and operational processes. Contribute to secure infrastructure and application delivery practices across cloud and containerized environments. Security Operations & Continuous Improvement Participate in: Incident response Threat hunting Security assessments Vulnerability remediation Root cause analysis Architecture reviews Support identification and remediation of vulnerabilities affecting web applications, APIs, and network security infrastructure. Contribute to ongoing enhancement of detection, prevention, and response capabilities. Provide recommendations to improve operational security controls, reduce risk, and strengthen enterprise resilience. Day-to-Day Responsibilities Administer and tune WAF, API security, bot protection, and DDoS controls for enterprise applications. Onboard applications into F5 Distributed Cloud WAF and coordinate with application teams on requirements and troubleshooting. Review alerts, investigate suspicious activity, and respond to web application or network security incidents. Manage Palo Alto firewall policies, Prisma Access configurations, VPNs, and related network security controls. Support false positive analysis and policy optimization across application security tools. Develop scripts and automation to improve security operations and reduce manual effort. Collaborate with developers, infrastructure engineers, network teams, and security stakeholders to improve protections and resolve issues. Participate in architecture reviews, security assessments, and remediation planning. Required Qualifications 7+ years of experience in cybersecurity engineering, with strong focus on web application security, network security, or cloud security. Hands-on experience administering and supporting web application firewall (WAF) technologies in an enterprise environment. Experience with F5 Distributed Cloud (XC) WAF or comparable advanced WAF platforms. Strong understanding of: Web application attacks API security threats Bot mitigation DDoS protection Authentication and session-related attack patterns Experience supporting Palo Alto Networks security technologies, including NGFW and/or Prisma Access. Experience with network security concepts such as VPNs, SSL decryption, NAT, segmentation, DNS, and routing troubleshooting. Experience with automation and scripting using Python, REST APIs, Terraform, and Git. Familiarity with DevSecOps and CI/CD pipelines. Strong incident response, troubleshooting, and problem-solving skills. Ability to work across infrastructure, cloud, networking, development, and security teams in a collaborative environment. Preferred Qualifications Experience with: Bot Management API Security DDoS Protection CDN technologies Kubernetes Containers Terraform DevSecOps CI/CD pipelines Experience building security dashboards, posture reporting, or automation tooling. Familiarity with secure cloud-native application delivery and modern edge security architectures. Experience in regulated, utility, or large enterprise environments is a plus. Preferred Certifications OWASP Foundation certifications ISC2 CISSP GIAC certifications F5 certifications Palo Alto Networks certifications Core Competencies Web Application Security WAF Administration API Security Bot Management DDoS Mitigation Network Security Palo Alto Networks Prisma Access Cloud Security DevSecOps Security Automation Incident Response Ideal Candidate Profile The ideal candidate is a hands-on senior cybersecurity engineer with strong expertise in securing internet-facing applications and enterprise network environments. They are comfortable working across WAF platforms, firewalls, APIs, automation, and cloud-connected services, and they know how to balance operational support with strategic improvements to security posture. This person is proactive, technically deep, and effective at partnering across teams to protect critical enterprise services. Additional Notes This is a contract-to-hire opportunity. The role requires a hybrid onsite schedule in Columbus, OH. Candidates must be authorized to work in the United States now and in the future without sponsorship.