Hello All,
Greetings from ZettaMine!!!
Role: WAF Engineer (GCP Focus)
Experience: 5+ Years
Location: Bengaluru, PAN INDIA
Notice Period: Immediate Joiners
Hiring for one of the Big 4's Clients
We are looking for Immediate to 15 Days Joiners only
Role Purpose The WAF Engineer will be responsible for tuning, engineering, and managing Web Application Firewall (WAF) solutions with a strong focus on GCP. The role involves crafting custom rules, conducting log analysis, mitigating false positives, and integrating WAF solutions seamlessly into the organization’s security infrastructure. The engineer will also contribute to DevSecOps automation pipelines, ensuring continuous improvement of WAF efficacy and alignment with industry best practices.
Key Responsibilities
- Identification and crafting of complex custom WAF rules & features to mitigate MVP and security posture gaps.
- Crafting efficacy testing for baseline & custom rules and integrating testing in automation pipelines.
- Providing SME support for WAF PoCs, new features, and solutions to reduce reliance on third-party vendors.
- Offering WAF-focused SME support on Web & API attack methodologies, evasions, and mitigation techniques.
- Supporting DevSecOps pipeline build and automation initiatives.
- Monitoring and reviewing all tuning requests.
- Conducting detailed log analysis to identify false positives and optimize WAF rules.
- Creating and maintaining documentation for WAF tuning procedures, policies, and configurations.
- Developing,
testing, and recommending WAF policies tailored to specific applications and environments.
- Collaborating with cross-functional teams to integrate WAF solutions into existing security infrastructure.
- Performing regular assessments and audits of WAF configurations to ensure compliance and optimal security posture.
- Staying updated with emerging web security threats, vulnerabilities, and trends.
Key Accountabilities
- Defend the organization and its customers from web-based attacks that could impact operations, reputation, and customer trust.
- Conduct technical evaluations of WAF rulesets to confirm adherence to baselines and maximize detection of threats.
- Create custom rules and features to augment WAF solutions.
- Identify and mitigate evasions and circumventions of WAF solutions.
- Develop and implement testing packages for WAF PoCs, managed/custom rules, and current features.
- Automate efficacy testing procedures and integrate them into CI/CD pipelines.
- Reverse-engineer exploits and payloads to devise mitigation rules when required.
- Ensure timely review and action on all WAF tuning requests.
- Maintain comprehensive documentation for tuning procedures and configurations.
- Provide expert recommendations for WAF configurations based on best practices.
Interested candidates share your updated CV to
[email protected] or WhatsApp to (phone hidden). Thanks& Regards,
Praneeth.N
📌 [VWAF Engineer (GCP Focus) (Bengaluru)
🏢 ZettaMine Labs
📍 Bengaluru