Demo

WAF Adversarial Engineer

NextDeavor
Seattle, WA Full Time
POSTED ON 5/13/2026
AVAILABLE BEFORE 6/11/2026

You’ll be joining Adobe on a contract opportunity, employed through NextDeavor


Benefits You'll Love

NextDeavor offers health, vision and dental benefits for contract employees Paid sick leave eligibility is contingent on state of residence Optional 401k Plan (excludes employer match) Opportunity to get your foot in the door at a well-established corporation, with potential for extended or permanent full-time employment


Become a Key Player as a WAF Adversarial Engineer

You will validate and harden the client's web application firewall (WAF) program by running continuous adversarial testing and translating offensive findings into actionable rule candidates. Your work will influence edge security, incident response, and rule-deployment cadence across the security and engineering teams. This role is hybrid/remote with Seattle preferred and open to remote candidates.


Here's How You'll Make an Impact on the Team

  • Run adversarial test campaigns against the client's WAF stack after each rule update cycle, targeting encoding evasion, HTTP parsing differentials, request smuggling, and other edge-layer weaknesses.
  • Build and maintain a versioned WAF bypass library organized by vulnerability class (e.g., SQLi, XSS, SSRF, path traversal, SSTI) and validate against staging and production WAF configurations.
  • Conduct adversarial testing of API endpoints behind the WAF (business logic abuse, BOLA/BFLA, mass assignment, parameter manipulation) and document which attack classes the WAF can and cannot reliably cover.
  • Triage complex false positives by reproducing ambiguous traffic from the attacker side and recommending targeted rule adjustments.
  • Produce concise validation reports that deliver a reproducer plus a rule recommendation suitable for refinement and deployment.
  • Provide adversarial perspective during active edge incidents, identifying likely attacker behavior, blind spots, and next probable moves.
  • Integrate continuous validation into the team's rule update cadence rather than running standalone penetration tests.


Here's What You'll Need to Be Successful in This Role

  • Demonstrated WAF bypass experience against at least two commercial WAF platforms (e.g., Akamai, AWS WAF, Fastly, Cloudflare).
  • Deep working knowledge of HTTP protocol edge cases affecting WAF inspection: request smuggling primitives, chunked transfer encoding abuse, multipart boundary manipulation, Unicode normalization differentials, and header injection patterns.
  • Proven web application penetration testing track record with WAF-specific scope; tool-running alone does not qualify.
  • Certifications or demonstrated outputs such as OSCP, BSCP, OSWE, or a portfolio of disclosed bypasses, conference talks, or prior validation engagements.
  • Strong scripting skills in Python or Go for building test harnesses, payload generators, and replay tooling.
  • Comfortable working in CI/CD pipelines and cloud environments (AWS or Azure) and integrating with existing infrastructure.
  • Bachelor's degree in Computer Science, Computer Engineering, Information Security, or a related technical field, or equivalent demonstrated experience.


Here's What Else Might Help You Out

  • Deep API-specific attack knowledge: GraphQL injection, BOLA/BFLA, mass assignment.
  • Familiarity with Akamai internals (KRS / ASE rule engine, custom Lua / EdgeWorkers).
  • Experience with bot evasion techniques at the behavioral layer (headless browser fingerprinting bypass, behavioral mimicry).
  • Familiarity with edge-layer LLM/GenAI guardrails and prompt injection mitigation at the WAF tier.
  • Public security research, CVE disclosures, or conference talks demonstrating original bypass work.


Pay Range

$56.34 - $70.42/hour


Ready to Make Your Mark?

This role may fill quickly. Submit your resume to be considered.

Salary : $56 - $70

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a WAF Adversarial Engineer?

Sign up to receive alerts about other jobs on the WAF Adversarial Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$56,383 - $86,743
Income Estimation: 
$63,454 - $101,244
Income Estimation: 
$53,080 - $99,161
Income Estimation: 
$87,640 - $113,243
Income Estimation: 
$77,897 - $116,523
Income Estimation: 
$68,048 - $83,238
Income Estimation: 
$79,882 - $99,769
Income Estimation: 
$94,567 - $126,847
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at NextDeavor

  • NextDeavor Bellingham, WA
  • Benefits You’ll Love Health insurance Dental insurance Vision insurance Life insurance 401(k) with matching contributions Paid training, onboarding, and on... more
  • 10 Days Ago

  • NextDeavor Irvine, CA
  • Become a Key Player as a Test Technician You will help ensure quality and on-time delivery by accurately testing fan and pump assemblies, supporting manufa... more
  • 10 Days Ago

  • NextDeavor Mentor, OH
  • Become a Key Player as a Mechanical Engineer You will support R&D test lab mechanical systems and testing to advance aerospace product development. You’ll ... more
  • 11 Days Ago

  • NextDeavor Simi Valley, CA
  • Become a Key Player as a Quality Inspector 1 You will perform routine visual and mechanical inspections to ensure components meet quality standards and aer... more
  • 11 Days Ago


Not the job you're looking for? Here are some other WAF Adversarial Engineer jobs in the Seattle, WA area that may be a better fit.

  • Software Guidance & Assistance Seattle, WA
  • Software Guidance & Assistance, Inc., (SGA), is searching for a WAF Adversarial Engineer for a contract assignment with one of our premier SaaS clients in ... more
  • 1 Day Ago

  • VARITE INC Seattle, WA
  • VARITE is looking for qualified WAF Adversarial Engineer WHAT THE CLIENT DOES? An American computer software company that offers a wide range of programs f... more
  • 3 Days Ago

AI Assistant is available now!

Feel free to start your new journey!