01 Sep
|
RARR Technologies
|
Hyderabad
01 Sep
RARR Technologies
Hyderabad
We are seeking a Senior WAF Engineer with 7+ years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 4+ years of hands-on experience with Imperva (preferred) or Cloudflare . In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents.
You will collaborate closely with DevOps, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.
- Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).
- Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.).
- Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor challenge block).
- Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.
- Integrate WAF logs with SIEM/log platforms (Splunk, Sentinel, ELK, QRadar) and build dashboards/alerts for threat monitoring.
- Support incident response for active attacks (L7 DDoS, exploit attempts), including rapid mitigation and post-incident improvements.
- Automate deployments using IaC (Terraform / CloudFormation / ARM / Bicep) and integrate with CI/CD pipelines.
- Conduct periodic security reviews, reporting, and metrics tracking (blocked events, top attacks, FP rate, MTTR).
- Collaborate with app teams on secure configuration (headers, TLS, authentication flows) and compatibility testing.
- Demonstrated experience in automation using PowerShell or Python to integrate with Imperva APIs for scalable WAF policy deployment, configuration management, and operational efficiency.
Required Qualifications:
- Education: Master s or bachelor s degree in computer science, Information Technology, Cybersecurity, or a related field.
- 7+ years experience in WAF engineering and Implementation.
- Hands-on experience with at least one WAF platform: Imperva(preferred), Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF,
- Strong understanding of HTTP/HTTPS, web app architecture, REST APIs, and common attack patterns.
- Proven experience tuning WAF rules and balancing security vs. false positives.
- Experience with logging/monitoring and SIEM integrations.
- Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML).
- Familiarity with CI/CD and Infrastructure-as-Code principles.
- Positive troubleshooting and stakeholder communication skills.
Preferred Qualifications:
- Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).
- Experience with API gateways and API security controls (schema validation, auth hardening).
- Working knowledge of cloud networking/CDN/reverse proxy concepts.
- Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).
Tools Technologies:
- WAF (AWS / Azure / Cloudflare / F5 / Imperva) , CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/GitHub Actions/Azure DevOps), Python, Linux, Git.
Disclaimer: This job posting and Location has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 WAF Engineer (Hyderabad)
🏢 RARR Technologies
📍 Hyderabad