08 Sep
|
MyCareernet
|
Chennai
08 Sep
MyCareernet
Chennai
Key Skills: Akamai, Web Application Firewall (WAF), DevSecOps
Roles and Responsibilities:
- Act as a high-level specialist who independently drives bot detection and mitigation initiatives and escalates to management as the next step.
- Analyze ecommerce fraud attack patterns and support mitigation strategies for credential stuffing/ATO, carding, scraping, scalping/inventory denial, and promo/gift card abuse.
- Master telemetry and logging correlation across WAF/CDN logs and application logs to support investigations, detection improvements, and operational dashboards.
- Build and refine detection logic using feature engineering and traffic baselining (normal vs anomaly) to improve coverage while reducing false positives.
- Develop and maintain golden signals such as login failure rate, unique IPs per account, current device rate, checkout abandonment spikes, and 4xx/5xx patterns.
- Apply deep understanding of HTTP and client behavior to interpret headers, cookies, caching, redirects, and TLS-related signals for bot identification and mitigation.
- Engineer and tune edge/WAF/CDN rules and bot policies, including rate limiting strategies (global, per IP, per session, per account, per ASN) and challenge flows (JS challenge, CAPTCHA, proof-of-work style concepts).
- Own allowlist/denylist governance, including how allowlists can be abused, and ensure safe operational controls.
- Drive release discipline for mitigations using staged deployment (monitor alert soft block hard block) and validate impact through monitoring and alerting.
- Support staged mitigation experiments (A/B testing) to protect conversion while improving security outcomes.
- Collaborate closely with application teams, fraud, SRE, and security operations to continuously tune detection logic as attacker techniques evolve.
Skills Required:
- Strong expertise in Akamai security solutions and WAF configurations
- Deep understanding of bot detection, fraud patterns, and application security
- Experience analyzing WAF/CDN and application logs for threat detection
- Knowledge of HTTP protocol, client behavior, cookies, headers, and TLS signals
- Hands-on experience designing and tuning rate limiting and bot mitigation rules
- Familiarity with DevSecOps practices (CI/CD security integration)
- Experience in anomaly detection, traffic baselining, and feature engineering
- Strong understanding of ecommerce fraud scenarios (ATO, scraping, carding, etc.)
- Experience in staged rollout strategies (monitoring - blocking) and A/B testing for security controls
- Ability to collaborate with cross-functional teams (SRE, fraud, app, security ops)
Education: Bachelor's Degree in related field
📌 Lead Cybersecurity Engineer - Bot Detection (Chennai)
🏢 MyCareernet
📍 Chennai