Company Name: VARITE India Private Limited
About The Client
An Indian multinational information technology (IT) consulting company headquartered in Noida, The company has offices in 52 countries and over 225,944 employees. The Client is a global IT services and consulting company that offers a wide range of services and products across various industries like IT Infrastructure Services, Cybersecurity Services, Cloud Services, Big Data and Analytics, Internet of Things (IoT) Solutions, Semiconductor Services and Enterprise Software Products. About The Job:
- Implement central AWS governance capabilities for web application protection, workload isolation, and controlled egress based on an approved architecture.
- The role focuses on reusable Terraform modules, CI/CD pipelines, centralized policy enforcement, logging, monitoring, and operational guardrails for AWS WAF, Amazon CloudFront, Application Load Balancer, AWS Firewall Manager, AWS Network Firewall, and related multi-account governance services.
Essential Job Functions:
- Develop reusable Terraform modules for AWS WAF, CloudFront, ALB, Firewall Manager, Network Firewall, security groups, VPC routing, logging, and policy associations.
- Implement governance guardrails across AWS Organizations, accounts, organizational units, landing zones, and shared network patterns.
- Build CI/CD pipelines for Terraform validation, testing, approvals, release management, and controlled rollout across environments.
- Enable AWS WAF, CloudFront, ALB, VPC Flow Logs, Network Firewall, CloudWatch, and SIEM integration for security monitoring and operations.
- Support application onboarding, parameterization, rule tuning, exception handling, troubleshooting, documentation, and operational handover.
Qualifications:
Must-Have Skills
Terraform, IaC & DevOps Engineering
- Strong hands-on experience with reusable, parameterized, versioned, and documented Terraform modules for AWS resources.
- Experience with Terraform state management, provider configuration, multi-account and multi-region patterns, module testing, and release versioning.
- CI/CD experience with GitHub Actions, GitLab CI, AWS CodePipeline,
Azure DevOps, or comparable tooling.
- Ability to translate architecture and governance requirements into maintainable automation components.
AWS WAF, CloudFront & Application Load Balancer Implementation
- Hands-on implementation experience with AWS WAF web ACLs for CloudFront, Application Load Balancers, and API-facing workloads.
- Knowledge of managed rule groups, OWASP-oriented protections, custom rules, rate-based rules, IP sets, regex patterns, rule priorities, exclusions, and count versus block mode.
- Experience with CloudFront origin patterns, ALB routing, TLS integration, caching behavior, logging, metrics, and SIEM forwarding.
AWS Workload Isolation & Egress Filtering
- Experience with VPCs, subnets, route tables, security groups, NACLs, VPC endpoints, PrivateLink, DNS, and Transit Gateway.
- Experience with centralized egress filtering using AWS Network Firewall, firewall policies, rule groups, NAT Gateway patterns, and forced egress routing.
- Understanding of shared services VPCs, centralized inspection VPCs, ingress and egress inspection, and multi-account routing models.
AWS Platform Engineering & Governance Automation
- AWS Firewall Manager policy implementation for AWS WAF, security groups, Network Firewall, and organization-wide protection rollout.
- AWS Config rules, conformance packs, remediation workflows, delegated administration, and policy-as-code patterns.
- Estate discovery and compliance reporting across WAF coverage, CloudFront, ALBs, security groups, routing, private connectivity, and egress controls.
Collaboration, Documentation & Delivery
- Strong collaboration with cloud architecture, platform engineering, network, security, operations, and application teams.
- Clear documentation of Terraform modules,
onboarding instructions, runbooks, deployment examples, and operational handover material.
Preferred Skills
- Experience with AWS Organizations, Firewall Manager delegated administration, and PrivateLink.
- Experience with Config as Code, GuardDuty, Security Hub, or comparable security and compliance tooling.
- Knowledge of OWASP Top 10, API protection, bot protection, Microsoft Sentinel, and security monitoring use cases.
- Experience with large-scale onboarding programs, reusable platform services, governance implementations, ITIL practices, and operational handovers..
How to Apply: Interested candidates are encouraged to respond/submit their updated resumes, and for additional job opportunities, please visit Jobs In India – VARITE.
Unlock Rewards: Refer Candidates and Earn.
If you're not available or interested in this chance, please pass this along to anyone in your network who might be a good fit and interested in our open positions. VARITE offers a Candidate Referral program, where you'll receive a one-time referral bonus based on the following scale if the referred candidate completes a three-month assignment with VARITE.
Experience Level Bonus Referral: 0-2 years INR 5,000 2-6 years INR 7,500 6+ years INR 10,000
About VARITE: VARITE is a global staffing and IT consulting company providing technical consulting and team augmentation services to Fortune 500 Companies in USA, UK, CANADA and INDIA. VARITE is currently a primary and direct vendor to the leading corporations in the verticals of Networking, Cloud Infrastructure, Hardware and Software, Digital Marketing and Media Solutions, Clinical Diagnostics, Utilities, Gaming and Entertainment, and Financial Services.
Equal Opportunity Employer:
VARITE is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, marital status, veteran status, or disability status.
📌 AWS WAF Governance DevOps Engineer (India)
🏢 VARITE
📍 India