About Miggo
We're Miggo — a cybersecurity startup on a mission to stop app-layer breaches before they happen. Founded in 2023 and backed by top-tier cyber VCs, we're building the world's first Application Detection & Response (ADR) platform. Why? Because 80% of cyber attacks target the app layer, and current tools just don't cut it. Miggo brings visibility into how apps actually behave at runtime, spotting risky flows and shutting down threats in real time.
We're closing the patch gap: showing security teams what's reachable, what's exploitable, and what's being attacked right now — and delivering targeted mitigations when a patch isn't ready.
At Miggo, we live by four core values:
About the Role
Miggo's WAF Copilot takes a freshly disclosed CVE and produces a validated, provider-specific WAF rule — researching the vulnerability, deriving the attack surface, composing the rule, then attacking its own output with an independent bypass judge and a false-positive prober before a human is offered a deploy.
As WAF Security Specialist you are the ground truth the Copilot is measured against — the person who can look at a generated rule and say this blocks the PoC but not the four obvious variants, this will trip on legitimate multipart uploads, this is 340 WCUs of nothing because the managed ruleset already catches it, this can't be anchored tightly enough to live in a global Web ACL.
You'll be shipping rules for real customers — and you'll do it through our AI harness, and help optimize it.
In practice that means driving the harness on live work: feeding it a vulnerability, judging what comes back, tightening the match, and validating it against real exploit traffic until it's something you'd put your name on.
Sometimes you'll write the expression yourself — the CVE with no public PoC, the emerging threat you have to reason out of a patch diff, the customer who needs coverage this afternoon. Most of the time you'll be applying expert judgment at every step of a generated rule's life, which is a different and harder skill than authoring from a blank page.
Because you'll be the harness's heaviest user, you'll also be the reason it gets better. You'll see exactly where it breaks down — the research step that missed the real sink, the composer that over-broadened, the judge that passed a rule it shouldn't have — and turn that into validations, analyses, and evals that go back into the agent. You'll work side by side with the Copilot & AI team so the agent stops making the mistake, instead of you catching it again next month. That feedback loop is the core of this role.
All of it rests on knowing where WAFs actually break: normalization and encoding evasion, parameter pollution, body-inspection size limits, oversize-content handling, rule precedence, and the gap between "the rule matched in staging" and "the rule holds against a motivated attacker." An AI can propose a rule. Knowing whether to trust it is the job.
What You'll Do
What You'll Have
Why You'll Love This Role
You'll do the craft work you're actually good at — writing rules against hard vulnerabilities, under real time pressure, for customers who feel the difference. What's unusual is that here it compounds: every rule you write and every bypass you find makes an AI system permanently better at something an expert used to do by hand, across every customer and every future CVE. You get the individual save and the leverage over the whole fleet.
You'll have real authority over what we ship and what we refuse to ship, direct access to the engineers building the agent, and a rare seat at the point where security research and AI actually meet in production.
<!-- notionvc: 9520b65f-bc16-4842-b3f2-bfa990a9bdf6 -->
Job details are sourced from the employer's original posting.
Open job postingAbout the company
Miggo Security is a cybersecurity company focused on providing advanced security solutions.