Bangalore, Karnataka
Job Summary
Job Summary : Senior Network Security Engineer – WAAP (Web Application & API Protection) Hewlett Packard Enterprise is an innovative, dynamic company with a rich past and a promising future. Originally Hewlett-Packard Company, HPE has continuously reinvented itself. Today, HPE is one of the world's leading technology companies providing networking, cloud, and security solutions for next-generation IT infrastructure. WAAP Responsibilities (Primary Focus) • Architect, implement, and manage WAAP platforms, including: o Web Application Firewall (WAF) o API Security (discovery, protection, runtime analysis) o Bot Management o DDoS Protection (L3–L7) • Design and deploy WAAP solutions using platforms such as: o Thales Imperva o Cloud-native WAFs (Azure, AWS WAF) or equivalent • Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications. • Perform false positive tuning, policy optimization, and rule lifecycle management. • Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats. • Integrate WAAP with: o SIEM/SOAR platforms o Identity providers o Threat intelligence feeds • Collaborate with application teams to: o Onboard applications into WAAP platforms o Perform security assessments and risk reviews o Ensure minimal performance impact while enforcing strong security controls • Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.). • Lead WAAP incident response and root cause analysis for application-layer attacks. • Define and track application security metrics and KPIs (attack trends, mitigation effectiveness). • Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).Core Network Security Responsibilities • Architect and maintain secure network infrastructure across data center, campus, and cloud environments. • Conduct security design reviews ensuring compliance with enterprise security standards. • Provide risk reporting, control effectiveness, and security posture visibility. • Support internal and external security audits. • Manage and optimize Security Information and Event Management (SIEM) systems. • Develop and maintain network security policies and procedures. • Collaborate with cybersecurity, infrastructure, and application teams globally.Technical Qualifications • 10+ years of experience in network security architecture, engineering, and operation.Network Security & Infrastructure • Strong hands-on experience in: o Firewalls (Fortinet, Palo Alto, Juniper) o IDS/IPS, VPN, SIEM • Expertise in: o Firewall policy design, NAT, routing, inspection, and threat prevention • Experience in designing secure: o Hybrid (on-prem + cloud + internet-facing) environments • Experience in: o Proxy architectures (forward/reverse) o Secure internet gateways.• Bachelor’s Degree in Computer Science, IT, or related field (or equivalent experience). • 10+ years of experience in enterprise network security and application security. • Preferred certifications: o CCNP / CCIE / JNCIE o Security certifications (CISSP, CISM) o Vendor certifications (Akamai, AWS Security, Azure Security). Key Differentiators (What This JD Targets) • Positions WAAP as a primary security control layer, not an add-on • Strong alignment with: o Application security + Network security convergence o Defense-in-depth strategy • Emphasizes: o API security (modern requirement) o Bot/DDoS protection (critical for internet-facing apps) • Keeps strong foundation in: o Firewalls, SIEM, network architecture.
Key Responsibilities
Key Responsibilities • Translate business and application security requirements into enterprise-grade WAAP and network security architectures. • Develop and support solutions aligned with HPE’s application security and defense-in-depth strategy.
• Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments. • Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.
Skill Requirements
Skill Requirement : Senior Network Security Engineer – WAAP (Web Application & API Protection) Hewlett Packard Enterprise is an innovative, dynamic company with a rich past and a promising future. Originally Hewlett-Packard Company, HPE has continuously reinvented itself. Today, HPE is one of the world's leading technology companies providing networking, cloud, and security solutions for next-generation IT infrastructure. WAAP Responsibilities (Primary Focus) • Architect, implement, and manage WAAP platforms, including: o Web Application Firewall (WAF) o API Security (discovery, protection, runtime analysis) o Bot Management o DDoS Protection (L3–L7) • Design and deploy WAAP solutions using platforms such as: o Thales Imperva o Cloud-native WAFs (Azure, AWS WAF) or equivalent • Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications. • Perform false positive tuning, policy optimization, and rule lifecycle management. • Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats. • Integrate WAAP with: o SIEM/SOAR platforms o Identity providers o Threat intelligence feeds • Collaborate with application teams to: o Onboard applications into WAAP platforms o Perform security assessments and risk reviews o Ensure minimal performance impact while enforcing strong security controls • Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.). • Lead WAAP incident response and root cause analysis for application-layer attacks. • Define and track application security metrics and KPIs (attack trends, mitigation effectiveness). • Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).Network Security & Infrastructure • Strong hands-on experience in: o Firewalls (Fortinet, Palo Alto, Juniper) o IDS/IPS, VPN, SIEM • Expertise in: o Firewall policy design, NAT, routing, inspection, and threat prevention • Experience in designing secure: o Hybrid (on-prem + cloud + internet-facing) environments • Experience in: o Proxy architectures (forward/reverse) o Secure internet gateways.Networking & Protocol Expertise • Strong knowledge of: o TCP/IP, DNS, HTTP/HTTPS, TLS/SSL o Routing protocols (BGP, OSPF, MPLS) • Experience with: o QoS, NetFlow, ACLs, NAT, IP traffic management o Network monitoring and analysis tools.Key Differentiators (What This JD Targets) • Positions WAAP as a primary security control layer, not an add-on • Strong alignment with: o Application security + Network security convergence o Defense-in-depth strategy • Emphasizes: o API security (modern requirement) o Bot/DDoS protection (critical for internet-facing apps) • Keeps strong foundation in: o Firewalls, SIEM, network architecture.
Other Requirements
Senior Network Security Engineer – WAAP (Web Application & API Protection) Hewlett Packard Enterprise is an innovative, dynamic company with a rich past and a promising future. Originally Hewlett-Packard Company, HPE has continuously reinvented itself. Today, HPE is one of the world's leading technology companies providing networking, cloud,
and security solutions for next-generation IT infrastructure.Key Responsibilities • Translate business and application security requirements into enterprise-grade WAAP and network security architectures. • Develop and support solutions aligned with HPE’s application security and defense-in-depth strategy. • Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments. • Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.WAAP Responsibilities (Primary Focus) • Architect, implement, and manage WAAP platforms, including: o Web Application Firewall (WAF) o API Security (discovery, protection, runtime analysis) o Bot Management o DDoS Protection (L3–L7) • Design and deploy WAAP solutions using platforms such as: o Thales Imperva o Cloud-native WAFs (Azure, AWS WAF) or equivalent • Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications. • Perform false positive tuning, policy optimization, and rule lifecycle management. • Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats. • Integrate WAAP with: o SIEM/SOAR platforms o Identity providers o Threat intelligence feeds • Collaborate with application teams to: o Onboard applications into WAAP platforms o Perform security assessments and risk reviews o Ensure minimal performance impact while enforcing strong security controls • Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.). • Lead WAAP incident response and root cause analysis for application-layer attacks. • Define and track application security metrics and KPIs (attack trends, mitigation effectiveness). • Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards). Core Network Security Responsibilities • Architect and maintain secure network infrastructure across data center, campus, and cloud environments. • Conduct security design reviews ensuring compliance with enterprise security standards. • Provide risk reporting, control effectiveness, and security posture visibility. • Support internal and external security audits. • Manage and optimize Security Information and Event Management (SIEM) systems. • Develop and maintain network security policies and procedures. • Collaborate with cybersecurity, infrastructure, and application teams globally.Technical Qualifications • 10+ years of experience in network security architecture, engineering, and operations.WAAP & Application Security Expertise (Mandatory) • Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted). • Deep understanding of: o OWASP Top 10 (Web & API) o Application-layer threats and mitigation techniques • Hands-on experience in: o WAF policy creation and tuning o API security controls (schema validation, authentication enforcement) o Bot mitigation strategies o DDoS protection architecture (L3–L7) • Experience in: o Traffic analysis (HTTP/HTTPS, TLS inspection) o Behavioral-based threat detection • Strong understanding of: o Secure application architectures (monolith, microservices, APIs) o DevSecOps integration and CI/CD security controls (nice to have) Network Security & Infrastructure • Robust hands-on experience in: o Firewalls (Fortinet, Palo Alto, Juniper) o IDS/IPS, VPN, SIEM • Expertise in: o Firewall policy design, NAT, routing, inspection, and threat prevention • Experience in designing secure: o Hybrid (on-prem + cloud + internet-facing) environments • Experience in: o Proxy architectures
#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-#body.unify div.unify-button-container .unify-apply-now: focus, #body.unify div.unify-button-container .unify-apply-
📌 Track Lead - Web App firewall, Cloud Security, Palo Alto Firewalls (India)
🏢 HCLTech
📍 India