Full-Time

Web Service Protection Engineer

NIH-NCBI

NIH-NCBI

Biomedical research information

No salary listed

Bethesda, MD, USA

In Person

Category
DevOps & Infrastructure (1)
Required Skills
Computer Networking
Requirements
  • Strong understanding of high-volume web service architecture — how traffic flows, where bottlenecks and abuse vectors appear, and how load balancers and edge infrastructure make routing decisions.
  • Hands-on experience with a major cloud provider's security and networking stack, including: Global load balancing and traffic management, Edge-layer security policy enforcement and WAF capabilities, Large-scale log querying and metric-driven alerting.
  • Solid grasp of HTTP/HTTPS protocol internals — headers, TLS behavior, connection patterns, and how these relate to traffic analysis and fingerprinting techniques.
  • Experience analyzing traffic using network and application-layer signals including address-based, organizational, and transport-layer fingerprinting methods.
  • Familiarity with common web server platforms, their log formats, and configuration.
  • Ability to read, write, and tune access control and rate-limiting rules under pressure.
  • Comfort working across hybrid infrastructure environments.
Responsibilities
  • Develop and own protection metrics and alerting — build dashboards and alert pipelines that surface anomalies across a range of network and application-layer signals.
  • Perform deep log analysis to identify overuse, scraping, abuse, DDoS, and attack patterns across millions of daily requests.
  • Operate and tune cloud-based edge security controls — configure and update security policies, rate limiting, and adaptive protection rules in response to evolving threats.
  • Enforce traffic controls — apply a range of mitigation strategies to abusive traffic while minimizing impact to legitimate users.
  • Monitor continuously and respond quickly — this role requires a bias for action. You will triage incidents and either resolve them directly or escalate to development or sysadmin teams with clear, actionable information.
  • Support protection across a mixed cloud and on-premises infrastructure — NCBI operates services in both environments, and protection coverage must extend consistently across both.
Desired Qualifications
  • Experience with advanced abuse mitigation techniques, including traffic redirection and challenge-response mechanisms.
  • Scripting or automation experience (Python, Bash, or similar) for log parsing and rule generation.
  • Prior work protecting high-traffic government or research platforms.
  • Knowledge of bot detection techniques beyond simple blocking — behavioral signals, fingerprinting, headless browser detection, and similar approaches.
  • Familiarity with evolving attacker tradecraft and how modern scrapers and abusers adapt to countermeasures.

The National Center for Biotechnology Information is a biomedical information center within the National Library of Medicine at the National Institutes of Health. NCBI develops and maintains databases, search systems and computational resources used to access scientific literature, genomic data and other biomedical information. Researchers, clinicians and the public use services including PubMed and related data platforms. This description follows the NIH and NCBI institutional identity, as directed, and does not treat the external contractor applicant system as the organization itself.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A