09 Sep
|
CtrlS Datacenters
|
Hyderabad
09 Sep
CtrlS Datacenters
Hyderabad
We are looking for an experienced WAF Engineer with strong hands-on expertise in Web Application Firewall (WAF), Load Balancers, Global Load Balancers (GLB), application-layer security, threat analysis, L7 DDoS protection, SQL Injection and BOT management.
The candidate will be responsible for designing, implementing, monitoring, troubleshooting, and tuning application security and traffic-management solutions across enterprise environments.
Key Responsibilities
- Design, configure, implement, and manage WAF, Load Balancer and Global Load Balancer solutions.
- Configure and maintain WAF security policies, rules, signatures, exceptions, and custom security controls.
- Analyze and mitigate application-layer attacks including SQL Injection, Cross-Site Scripting (XSS), OWASP Top 10 attacks, HTTP/HTTPS-based attacks, Application-layer DDoS / L7 DoS, Malicious and automated BOT traffic
- Perform threat analysis and investigate suspicious application traffic and security events.
- Analyze WAF logs, HTTP/HTTPS traffic, attack patterns, and security alerts to identify threats and false positives.
- Develop and fine-tune WAF policies to balance security and application availability.
- Configure BOT protection / BOT management policies to identify and mitigate malicious automated traffic.
- Implement and manage L7 DDoS protection mechanisms and mitigation strategies.
- Work on Global Load Balancing concepts such as DNS-based traffic distribution, geographic load balancing, application availability, and disaster recovery.
- Troubleshoot application connectivity, performance, SSL/TLS, routing, and load-balancing issues.
- Collaborate with network, security, application, and infrastructure teams for incident resolution.
- Participate in security incident investigation, RCA, and remediation activities.
- Monitor system performance, capacity, availability, and security posture.
- Prepare technical documentation, operational procedures, and incident reports.
Candidate Profile
- Solid understanding of application security and Layer 7 traffic management.
- Hands-on experience in WAF policy implementation and tuning.
- Good analytical and troubleshooting skills for identifying application and security-related issues.
- Ability to analyze attack signatures, HTTP requests, headers, URLs, parameters, and payloads.
- Experience handling security incidents involving SQL Injection, BOT attacks, L7 DoS/DDoS and malicious web traffic.
- Good communication and coordination skills.
📌 Senior Network Engineer (Hyderabad)
🏢 CtrlS Datacenters
📍 Hyderabad