Neither. Experience. Let me re-phrase, it depends really what aspect of "Info Sec" you want to go into... happy to talk further if you'd like was in this predicament a few years ago too
If your application is coded securely, it should be able to withstand most of what a waf can do. The problem is companies have a false sense of reality by and large: thinking their application is secure, when really its just waiting to be hacked.