WAF Administrator / Security Engineer – (Mumbai)

WAF Administrator / Security Engineer – (Mumbai)

01 Sep
|
Kyndryl India
|
Mumbai

01 Sep

Kyndryl India

Mumbai

Role Summary :

The F5 WAF L3 Administrator will be responsible for providing advanced technical support, administration, troubleshooting, optimization, and lifecycle management of enterprise F5 BIG-IP Advanced WAF / ASM infrastructure.

The role will act as the technical escalation point for L1/L2 teams and will handle complex production incidents, WAF policy issues, application onboarding, security events, upgrades, vulnerability remediation, RCA, performance issues, and OEM escalations.

The candidate is expected to possess strong expertise in F5 Advanced WAF/ASM, LTM, HTTP/HTTPS, SSL/TLS, application security, and enterprise network architecture, with the ability to independently troubleshoot critical production issues.

Key Responsibilities :

1. Advanced WAF Administration & Engineering

- Administer and provide L3 support for F5 BIG-IP Advanced WAF / ASM infrastructure.
- Design, create, implement, and optimize WAF security policies for critical web applications.
- Lead onboarding and migration of applications to the WAF platform.
- Configure and troubleshoot:
- Security Policies
- Virtual Servers
- Pools and Nodes
- HTTP/HTTPS Profiles
- SSL Profiles
- TCP Profiles
- Persistence Profiles
- SNAT
- Health Monitors
- Local Traffic Policies
- iRules
- Perform advanced policy tuning and transition applications from Transparent/Learning mode to Blocking mode.
- Analyze and eliminate false positives while maintaining the required security posture.
- Review and tune attack signatures, URLs, parameters, file types, HTTP protocol compliance, and application-specific security controls.
- Implement protection against OWASP Top 10 and other application-layer attacks.
- Support Advanced WAF capabilities including Bot Defense, IP Intelligence, Threat Campaigns, Behavioral DoS and application-layer DoS, where applicable.
- Support WAF/API security requirements for REST, JSON, XML and API-based applications.

2. L3 Incident & Problem Management

- Act as the highest technical escalation point for complex F5 WAF incidents.
- Provide technical guidance to L1/L2 teams during troubleshooting.
- Troubleshoot complex production issues involving:
- Application accessibility
- WAF blocking
- False positives
- HTTP/HTTPS errors
- SSL/TLS handshake failures
- Load balancing
- Persistence
- Health monitors
- Performance degradation
- HA/failover
- Configuration synchronization
- Perform packet-level troubleshooting using tcpdump, Wireshark and F5 diagnostic utilities.
- Analyze traffic flows from client to WAF/LTM and backend application servers.
- Perform detailed Root Cause Analysis (RCA) for major and recurring incidents.
- Identify permanent corrective and preventive actions.
- Participate in Major Incident Management and critical production troubleshooting bridges.
- Coordinate with Application, Network, SOC, Security and OEM teams for resolution of complex issues.

3. WAF Security Policy Management

- Review WAF security violations and determine whether events represent genuine attacks, false positives, or application behavior changes.
- Perform advanced WAF policy tuning without unnecessarily relaxing security controls.
- Review policy learning suggestions and determine appropriate actions.
- Maintain application-specific policy exceptions with appropriate justification and approval.




- Periodically review existing exceptions and remove obsolete relaxations.
- Ensure critical applications have appropriate security policies and blocking controls.
- Work with application security teams to translate vulnerability findings into appropriate WAF controls.
- Implement temporary/compensating WAF controls when application vulnerabilities cannot be immediately remediated.

4. Vulnerability & Patch Management

- Review F5 security advisories, CVEs, vulnerabilities, attack signatures, hotfixes and software releases.
- Perform technical applicability assessment against deployed F5 platforms.
- Determine potential business and technical impact of vulnerabilities.
- Coordinate with F5/OEM for second-level validation where required.
- Develop remediation plans for applicable vulnerabilities.
- Implement patches, hotfixes and security fixes within defined SLA timelines.
- Identify compensating controls where immediate remediation is not technically possible.
- Provide technical evidence and closure details for vulnerability management and audit teams.

5. Upgrade & Lifecycle Management

- Plan and execute BIG-IP software upgrades, hotfix installations and platform migrations.
- Perform upgrade compatibility and impact assessments.
- Review release notes, known issues, bug IDs and upgrade paths.
- Prepare detailed Method of Procedure (MOP), implementation, validation and rollback plans.
- Perform pre-upgrade and post-upgrade health checks.
- Troubleshoot upgrade-related issues and coordinate with F5 Support when required.
- Maintain platform lifecycle and ensure unsupported/EOL versions are identified and remediated.

6. High Availability & Disaster Recovery

- Manage and troubleshoot F5 HA architecture, Device Service Clustering, ConfigSync and failover.
- Investigate synchronization and failover issues.
- Validate HA health and configuration consistency.
- Participate in planned failover and Disaster Recovery exercises.
- Develop and maintain recovery procedures for F5 WAF infrastructure.
- Ensure configuration backups are available and periodically validated.

7. SSL/TLS & Certificate Management

- Manage SSL/TLS configuration and certificates on F5 platforms.
- Troubleshoot SSL handshake, cipher, protocol and certificate-chain issues.
- Configure Client SSL and Server SSL profiles.
- Support certificate renewal and replacement activities.
- Review weak protocols/ciphers and implement security hardening.
- Support TLS upgrades based on organizational security standards.

8. Performance & Capacity Management

- Monitor and analyze:
- CPU utilization
- Memory utilization
- Disk utilization
- Connection statistics
- Throughput
- SSL transactions
- WAF utilization
- Interface statistics
- HA status
- Investigate platform performance degradation.
- Perform capacity analysis and provide recommendations for scaling.
- Identify abnormal traffic patterns impacting platform performance.




- Work with OEM for advanced performance analysis where necessary.

9. Change Management

- Perform technical review of complex F5/WAF changes.
- Prepare detailed implementation and rollback procedures.
- Validate dependencies and potential application impact before implementation.
- Execute critical changes during approved maintenance windows.
- Perform comprehensive post-change validation.
- Support emergency changes during security or production incidents.
- Participate in technical review/CAB discussions for high-risk changes.

10. OEM / F5 Support Coordination

- Own complex technical cases with F5 Support/OEM.
- Generate and analyze QKView, tcpdump, logs and diagnostic information.
- Provide required technical information to OEM for problem analysis.
- Track F5 cases through resolution.
- Review OEM recommendations before implementation in production.
- Escalate critical OEM cases where resolution timelines impact business services.

11. Automation & Operational Improvement

- Identify repetitive operational activities suitable for automation.
- Develop or support automation using:
- F5 REST APIs
- Python
- Ansible
- Shell scripting
- Automate health checks, reporting, configuration validation and repetitive administrative activities where feasible.
- Identify opportunities to improve operational stability, security and efficiency.

Mandatory Technical Skills The candidate should have strong hands-on expertise in:

- F5 BIG-IP Advanced WAF / ASM
- F5 BIG-IP LTM
- WAF policy creation, learning, tuning and enforcement
- Application onboarding onto WAF
- OWASP Top 10
- HTTP/HTTPS
- TCP/IP
- DNS
- SSL/TLS and PKI
- Load balancing
- Reverse Proxy
- Virtual Servers, Pools, Nodes and Profiles
- Health Monitors
- Persistence
- SNAT
- iRules
- Local Traffic Policies
- HA / DSC / ConfigSync
- F5 upgrades and hotfixes
- QKView
- tcpdump/Wireshark
- F5 logging and diagnostics
- Vulnerability and patch management
- Incident, Problem and Change Management

Preferred Technical Skills Knowledge or hands-on experience with the following will be advantageous:

- F5 BIG-IQ
- F5 REST APIs
- API Security
- Bot Defense
- Behavioral/Application DoS
- IP Intelligence
- Threat Campaigns
- Splunk/SIEM integration
- Python
- Ansible
- Automation/scripting
- Enterprise monitoring platforms
- ITSM tools
- PCI DSS security requirements

Experience Recommended: 7–10+ years of overall Network/Application Security experience, including:

- Minimum 4–5 years of strong hands-on experience with F5 BIG-IP WAF/ASM/Advanced WAF.
- Solid hands-on experience with F5 LTM.
- Experience managing large-scale, high-availability enterprise production environments.
- Experience handling P1/P2 or critical production incidents independently.
- Experience performing major F5 upgrades and migrations.
- Experience working directly with F5/OEM Support on complex issues.
- Experience in highly regulated environments such as Banking/Financial Services will be preferred.

Preferred Certifications

- F5 Certified BIG-IP Administrator
- F5 Certified Technology Specialist – Security / ASM
- F5 Certified Technology Specialist – LTM
- CCNP or equivalent networking certification
- Relevant Cyber Security certification

Work Location : Airoli, Navi Mumbai. This is a work from office role for a large private sector Bank

📌 WAF Administrator / Security Engineer – (Mumbai)
🏢 Kyndryl India
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: waf administrator / security engineer – (mumbai) / mumbai

Subscribe to this job alert:

Get the latest job offers by email for: waf administrator / security engineer – (mumbai) / mumbai