12 Sep
|
MyCareernet
|
Tamil Nadu
12 Sep
MyCareernet
Tamil Nadu
Key Skills: Akamai, Web Application Firewall (WAF), DevSecOps
nRoles and Responsibilities:
n
n
- Act as a high-level specialist who independently drives bot detection and mitigation initiatives and escalates to management as the next step.
n
- Analyze ecommerce fraud attack patterns and support mitigation strategies for credential stuffing/ATO, carding, scraping, scalping/inventory denial, and promo/gift card abuse.
n
- Master telemetry and logging correlation across WAF/CDN logs and application logs to support investigations, detection improvements, and operational dashboards.
n
- Build and refine detection logic using feature engineering and traffic baselining (normal vs anomaly) to improve coverage while reducing false positives.
n
- Develop and maintain golden signals such as login failure rate, unique IPs per account, recent device rate, checkout abandonment spikes, and 4xx/5xx patterns.
n
- Apply deep understanding of HTTP and client behavior to interpret headers, cookies, caching, redirects, and TLS-related signals for bot identification and mitigation.
n
- Engineer and tune edge/WAF/CDN rules and bot policies, including rate limiting strategies (global, per IP, per session, per account, per ASN) and challenge flows (JS challenge, CAPTCHA, proof-of-work style concepts).
n
- Own allowlist/denylist governance, including how allowlists can be abused, and ensure safe operational controls.
n
- Drive release discipline for mitigations using staged deployment (monitor alert soft block hard block) and validate impact through monitoring and alerting.
n
- Support staged mitigation experiments (A/B testing) to protect conversion while improving security outcomes.
n
- Collaborate closely with application teams, fraud, SRE, and security operations to continuously tune detection logic as attacker techniques evolve.
n
nSkills Required:
n
n
- Strong expertise in Akamai security solutions and WAF configurations
n
- Deep understanding of bot detection, fraud patterns, and application security
n
- Experience analyzing WAF/CDN and application logs for threat detection
n
- Knowledge of HTTP protocol, client behavior, cookies, headers, and TLS signals
n
- Hands-on experience designing and tuning rate limiting and bot mitigation rules
n
- Familiarity with DevSecOps practices (CI/CD security integration)
n
- Experience in anomaly detection, traffic baselining, and feature engineering
n
- Strong understanding of ecommerce fraud scenarios (ATO, scraping, carding, etc.)
n
- Experience in staged rollout strategies (monitoring - blocking) and A/B testing for security controls
n
- Ability to collaborate with cross-functional teams (SRE, fraud, app, security ops)
n
nEducation: Bachelor's Degree in related field
📌 Lead Cybersecurity Engineer - Bot Detection (Tamil Nadu)
🏢 MyCareernet
📍 Tamil Nadu