WAF Management & Configuration • Deploy, configure, and tune WAF policies and rules across multiple environments (different applications for different brands). • Implement custom rules to mitigate emerging security threats, bot attacks or API vulnerabilities. • Partner with developers/application teams to align WAF rules with business requirements. • Integrate WAF solutions with SIEM or other monitoring systems for real-time visibility and reporting. • Investigate and resolve issues related to WAF functionality, performance, and traffic flow and support developers and DevOps teams in troubleshooting blocked traffic and false positives. Security Operations • Create meaningful alerts to trigger when a specific incident or changes in traffic pattern is happening. • Monitor WAF logs and alerts to detect and respond to suspicious activity. • Continuously update rule sets to adapt to emerging threats. • Conduct periodic audits to ensure WAF coverage and compliance with security policies. Collaboration & Documentation • Maintain clear documentation of WAF policies, configurations,
and troubleshooting guides. • Collaboration with other colleagues in Security Operation Center and Network Operation Centers.
Preferred candidate profile
Robust understanding of HTTP/S protocols, web application/API architecture, and common web application/API attack and defense mechanism. • Proven experience managing and troubleshooting WAF solutions (Cloudflare, AWS WAF, Azure WAF, or similar). • Familiarity with API security, CDN integrations, and bot management solutions. • Experience in log management solutions (e.g., Splunk, ELK, OpenSearch etc.) and integrating WAF logs into other platforms. • Working knowledge of DevOps best practices (CI/CD pipelines, Infrastructure as Code, Terraform/CloudFormation preferred). • Programming skills (Python, JavaScript etc.) for creating automation workflows or relevant applications to facilitate the day to day tasks. • Strong analytical and problem-sol