08 Sep
|
Seintiv Talent Solutions
|
Hyderabad
08 Sep
Seintiv Talent Solutions
Hyderabad
Summary
We are seeking a Senior WAF Engineer with 7+ years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 3+ years of hands-on experience with Imperva (preferred) or Cloudflare. In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDo S incidents.
You will collaborate closely with Dev Ops, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.
Key Responsibilities: Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod). Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.). Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor → challenge → block).
Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.
We Need:
7+ years’ experience in WAF engineering and Implementation. Hands-on experience with at least one WAF platform: Imperva(preferred), Akamai, Mod Security, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF, Strong understanding of web app architecture, REST APIs, and common attack patterns. Proven experience tuning WAF rules and balancing security vs. false positives.
Experience with logging/monitoring and SIEM integrations.
Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML). Familiarity with CI/CD and Infrastructure-as-Code principles. Positive troubleshooting and stakeholder communication skills.
Preferred Qualifications
Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).
Experience with API gateways and API security controls (schema validation, auth hardening).
Working knowledge of cloud networking/CDN/reverse proxy concepts.
Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).
Tools & Technologies
WAF (AWS/Azure/Cloudflare/F5/Imperva), CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/Git Hub Actions/Azure Dev Ops), Python, Linux, Git.
📌 Senior Waf Engineer (Hyderabad)
🏢 Seintiv Talent Solutions
📍 Hyderabad