Job Summary
ROLE SUMMARY Owns vulnerability remediation across the F5 WAF (Web Application Firewall) and ASM (Application Security Manager) estate in Société Générale\'s exposed zone. Operates within the 24-hour SLA for directly exposed assets. KEY RESPONSIBILITIES ■ Triage F5 WAF/ASM findings from SG-managed scanners and route into the remediation queue. ■ Apply firmware patches and signature updates within the 24-hour SLA. ■ Configure mitigations (virtual patching, custom rules) when a firmware patch is unavailable or deferred. ■ Coordinate maintenance windows with application owners and the change board. ■ Produce closed-loop verification evidence (before/after scan, ticket, change record). ■ Contribute patterns to the Phase 2 automation backlog. REQUIRED TECHNICAL SKILLS ■ Hands-on F5 BIG-IP administration: WAF, ASM, LTM modules. ■ Familiarity with F5 iRules and ASM policy configuration. ■ Understanding of OWASP Top 10 and common web-application attack patterns. ■ Comfortable with firmware upgrade procedures and rollback playbooks. PREFERRED / NICE TO HAVE ■ F5 Certified Technology Specialist or higher. ■ Exposure to API security and bot defence. EXPERIENCE & CERTIFICATIONS ■ 4+ years operating F5 platforms in enterprise environments. ■ Certifications: F5-CA, F5-CTS (Local Traffic Manager or Application Security Manager). SOFT SKILLS ■ Calm under 24-hour SLA pressure. ■ Clear documentation discipline. ■ Effective coordination with application owners.
Key Responsibilities
ROLE SUMMARY Owns vulnerability remediation across the F5 WAF (Web Application Firewall) and ASM (Application Security Manager) estate in Société Générale\'s exposed zone. Operates within the 24-hour SLA for directly exposed assets. KEY RESPONSIBILITIES ■ Triage F5 WAF/ASM findings from SG-managed scanners and route into the remediation queue. ■ Apply firmware patches and signature updates within the 24-hour SLA. ■ Configure mitigations (virtual patching, custom rules) when a firmware patch is unavailable or deferred. ■ Coordinate maintenance windows with application owners and the change board. ■ Produce closed-loop verification evidence (before/after scan, ticket, change record). ■ Contribute patterns to the Phase 2 automation backlog. REQUIRED TECHNICAL SKILLS ■ Hands-on F5 BIG-IP administration: WAF, ASM, LTM modules. ■ Familiarity with F5 iRules and ASM policy configuration. ■ Understanding of OWASP Top 10 and common web-application attack patterns. ■ Comfortable with firmware upgrade procedures and rollback playbooks. PREFERRED / NICE TO HAVE ■ F5 Certified Technology Specialist or higher. ■ Exposure to API security and bot defence. EXPERIENCE & CERTIFICATIONS ■ 4+ years operating F5 platforms in enterprise environments. ■ Certifications: F5-CA, F5-CTS (Local Traffic Manager or Application Security Manager). SOFT SKILLS ■ Calm under 24-hour SLA pressure. ■ Clear documentation discipline. ■ Effective coordination with application owners.
Skill Requirements
ROLE SUMMARY Owns vulnerability remediation across the F5 WAF (Web Application Firewall) and ASM (Application Security Manager) estate in Société Générale\'s exposed zone. Operates within the 24-hour SLA for directly exposed assets. KEY RESPONSIBILITIES ■ Triage F5 WAF/ASM findings from SG-managed scanners and route into the remediation queue. ■ Apply firmware patches and signature updates within the 24-hour SLA. ■ Configure mitigations (virtual patching, custom rules) when a firmware patch is unavailable or deferred. ■ Coordinate maintenance windows with application owners and the change board. ■ Produce closed-loop verification evidence (before/after scan, ticket, change record). ■ Contribute patterns to the Phase 2 automation backlog. REQUIRED TECHNICAL SKILLS ■ Hands-on F5 BIG-IP administration: WAF, ASM, LTM modules. ■ Familiarity with F5 iRules and ASM policy configuration. ■ Understanding of OWASP Top 10 and common web-application attack patterns. ■ Comfortable with firmware upgrade procedures and rollback playbooks. PREFERRED / NICE TO HAVE ■ F5 Certified Technology Specialist or higher. ■ Exposure to API security and bot defence. EXPERIENCE & CERTIFICATIONS ■ 4+ years operating F5 platforms in enterprise environments. ■ Certifications: F5-CA, F5-CTS (Local Traffic Manager or Application Security Manager). SOFT SKILLS ■ Calm under 24-hour SLA pressure. ■ Clear documentation discipline. ■ Effective coordination with application owners.
Other Requirements
ROLE SUMMARY Owns vulnerability remediation across the F5 WAF (Web Application Firewall) and ASM (Application Security Manager) estate in Société Générale\'s exposed zone. Operates within the 24-hour SLA for directly exposed assets. KEY RESPONSIBILITIES ■ Triage F5 WAF/ASM findings from SG-managed scanners and route into the remediation queue. ■ Apply firmware patches and signature updates within the 24-hour SLA. ■ Configure mitigations (virtual patching, custom rules) when a firmware patch is unavailable or deferred. ■ Coordinate maintenance windows with application owners and the change board. ■ Produce closed-loop verification evidence (before/after scan, ticket, change record). ■ Contribute patterns to the Phase 2 automation backlog. REQUIRED TECHNICAL SKILLS ■ Hands-on F5 BIG-IP administration: WAF, ASM, LTM modules. ■ Familiarity with F5 iRules and ASM policy configuration. ■ Understanding of OWASP Top 10 and common web-application attack patterns. ■ Comfortable with firmware upgrade procedures and rollback playbooks. PREFERRED / NICE TO HAVE ■ F5 Certified Technology Specialist or higher. ■ Exposure to API security and bot defence. EXPERIENCE & CERTIFICATIONS ■ 4+ years operating F5 platforms in enterprise environments. ■ Certifications: F5-CA, F5-CTS (Local Traffic Manager or Application Security Manager). SOFT SKILLS ■ Calm under 24-hour SLA pressure. ■ Clear documentation discipline. ■ Effective coordination with application owners.