02 Sep
|
Zettamine Labs
|
Hyderabad
02 Sep
Zettamine Labs
Hyderabad
Job Title: WAF Engineer
Experience : 7-10 Years
Summary
Summary
We are seeking a Senior WAF Engineer with 5 years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 3 years of hands-on experience with Imperva (preferred) or Cloudflare.
In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents.
You will collaborate closely with DevOps, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.
Key Responsibilities
- Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).
- Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.).
- Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor challenge block).
- Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.
- Integrate WAF logs with SIEM/log platforms (Splunk, Sentinel, ELK, QRadar) and build dashboards/alerts for threat monitoring.
- Support incident response for active attacks (L7 DDoS, exploit attempts), including rapid mitigation and post-incident improvements.
- Automate deployments using IaC (Terraform/CloudFormation/ARM/Bicep) and integrate with CI/CD pipelines.
- Conduct periodic security reviews, reporting, and metrics tracking (blocked events, top attacks, FP rate, MTTR).
- Collaborate with app teams on secure configuration (headers, TLS, authentication flows) and compatibility testing.
- Demonstrated experience in automation using PowerShell or Python to integrate with Imperva APIs for scalable WAF policy deployment, configuration management, and operational efficiency.
Required Qualifications
- 5+ years experience in WAF engineering and Implementation.
- Hands-on experience with at least one WAF platform: Imperva(preferred), Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF,
- Solid understanding of HTTP/HTTPS, web app architecture, REST APIs, and common attack patterns.
- Proven experience tuning WAF rules and balancing security vs. false positives.
- Experience with logging/monitoring and SIEM integrations.
- Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML).
- Familiarity with CI/CD and Infrastructure-as-Code principles.
- Good troubleshooting and stakeholder communication skills.
Preferred Qualifications
- Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).
- Experience with API gateways and API security controls (schema validation, auth hardening).
- Working knowledge of cloud networking/CDN/reverse proxy concepts.
- Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).
Tools & Technologies WAF (AWS/Azure/Cloudflare/F5/Imperva), CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/GitHub Actions/Azure DevOps), Python, Linux, Git.
📌 Sr WAF Engineer (Hyderabad)
🏢 Zettamine Labs
📍 Hyderabad