Posted on: 23/06/2026
Job Description :
Location : Pan India
Job Summary :
We are seeking an experienced WAF Security Engineer to design, implement, manage, and optimize Web Application Firewall (WAF) solutions across enterprise environments. The ideal candidate will possess strong expertise in web application security, WAF administration, DevSecOps practices, cloud security, and security automation. The role involves protecting web applications and APIs from emerging threats, developing custom security controls, automating security testing, and supporting enterprise-scale WAF deployments.
Key Responsibilities :
- Design, implement, configure, and maintain enterprise-scale WAF solutions.
- Develop, tune, and optimize WAF policies and custom security rules.
- Monitor, analyze, and mitigate web application and API security threats.
- Protect applications against OWASP Top 10 vulnerabilities and emerging attack vectors.
- Configure and manage HTTPS inspection, SSL/TLS termination, and certificate management.
- Implement rate-limiting and traffic control mechanisms to protect critical applications.
- Perform WAF tuning to reduce false positives and improve threat detection accuracy.
- Integrate security controls into CI/CD pipelines and DevSecOps workflows.
- Automate security testing and compliance checks across development and deployment processes.
- Implement Infrastructure as Code (IaC) solutions for security and infrastructure management.
- Support cloud-native security controls and WAF deployments across AWS, Azure, and GCP environments.
- Collaborate with development, infrastructure, and security teams to enhance application security posture.
- Monitor security events, logs, and performance metrics using enterprise monitoring platforms.
- Troubleshoot networking, connectivity, and application security issues.
Required Skills :
1. Web Application Security & WAF :
- Strong hands-on experience with Web Application Firewall (WAF) solutions.
- Experience with AWS WAF, Imperva, Akamai, F5 ASM, Cloudflare WAF, or equivalent platforms.
- WAF tuning, configuration, and policy management.
- Development of custom WAF rules and security testing packages.
- Enterprise-scale WAF deployments and management.
- Web application and API security expertise.
- OWASP Top 10 vulnerability mitigation.
- Web attack methodologies, payloads, exploits, and countermeasures.
- HTTPS inspection, SSL/TLS termination, and certificate management.
- Rate limiting and bot protection techniques.
2. Cloud & Infrastructure :
- Experience with cloud platforms such as AWS, Azure, or GCP.
- Knowledge of cloud-native WAF controls and security services.
- Containerization and orchestration technologies (Docker, Kubernetes).
3. DevSecOps & Automation :
- CI/CD tools : Jenkins, GitLab CI, CircleCI, Travis CI, Bamboo.
- Security automation within CI/CD pipelines.
- Infrastructure as Code (IaC) : Terraform, Ansible, Chef, Puppet.
4. Scripting & Development :
- Python, Bash, PowerShell.
- API Integration and Management.
5. Monitoring & Logging :
- Prometheus, Grafana, ELK Stack (Elasticsearch, Logstash, Kibana), Splunk.
6. Security & Networking :
- Networking fundamentals, Security fundamentals, Identity and Access Management (IDAM), Access control measures, Service management and troubleshooting.
Preferred Skills :
- DevSecOps best practices, Agile and Scrum methodologies, Project management methodologies, Secure SDLC implementation, Security governance and compliance, Application penetration testing.
Good-to-Have :
- Ethical Hacking, Vulnerability Assessment, Security Certifications (CEH, OSCP, Security+, CISSP, etc.).
Key Skills :
- WAF, AWS WAF, Imperva, Akamai, F5 ASM, Cloudflare WAF, OWASP Top 10, Web Application Security, API Security, DevSecOps, Jenkins, GitLab CI, Terraform, Ansible, Python, Bash, PowerShell, Docker, Kubernetes, Splunk, ELK Stack, HTTPS Inspection, SSL/TLS, Rate Limiting, Security Automation
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1647786