Hello,
Greetings from ZettaMine Labs Pvt Ltd!!
We are looking for an experienced Senior WAF Engineer with project opportunities.
Job Role
Senior WAF Engineer
Location
Hyderabad
Experience
7–12 Years
Relevant Experience
Minimum 5+ years of hands-on experience in WAF Engineering and Implementation, with at least 3 years of experience working on Imperva or other enterprise WAF platforms.
Mandatory
WAF Engineering + WAF Implementation + Imperva/Cloudflare/Akamai/AWS WAF/Azure WAF/F5 ASM + WAF Policy Configuration + Rule Tuning + OWASP Top 10 + False Positive Reduction + HTTP/HTTPS + REST APIs + SIEM + Python/PowerShell/Bash + Regex + JSON/YAML + CI/CD + Terraform/IaC
REQUIREMENT FOR SENIOR WAF ENGINEER
Key Responsibilities
- Design, implement, and manage WAF policies for web applications and APIs across Dev, Stage, and Production environments.
- Configure and tune managed and custom WAF rules to protect against OWASP Top 10 threats including SQL Injection, XSS, CSRF, RCE, LFI/RFI, SSRF, and other web attacks.
- Perform WAF rule tuning and false-positive reduction through traffic baselining, exception handling, and staged enforcement.
- Implement rate limiting, IP reputation, Geo/ASN controls, and bot mitigation strategies.
- Protect applications and APIs against abuse, credential stuffing, malicious automation, and other attacks.
- Integrate WAF logs with SIEM and monitoring platforms such as Splunk, Microsoft Sentinel, ELK, and QRadar.
- Build dashboards, alerts, and reports for security monitoring and threat analysis.
- Support incident response for active security threats including Layer 7 DDoS attacks and exploit attempts.
- Perform rapid WAF policy changes and mitigation during security incidents.
- Automate WAF deployments and policy management using Terraform, CloudFormation, ARM, or Bicep.
- Integrate WAF deployment and configuration processes with CI/CD pipelines.
- Conduct periodic WAF security reviews, optimization, and performance assessments.
- Track security metrics including blocked events, top attacks, false-positive rate, and MTTR.
- Collaborate with application, DevOps, SRE, and network teams on secure application configurations.
- Support TLS, security headers, authentication flows, API security,
and compatibility testing.
- Develop automation using Python or PowerShell to integrate with Imperva/WAF APIs and improve operational efficiency.
- Troubleshoot WAF, application, API, and connectivity-related security issues.
- Maintain technical documentation, policies, procedures, and incident reports.
Who Can Apply?
- Candidates with 7–12 years of overall experience and strong WAF Engineering experience.
- Minimum 5+ years of hands-on WAF Engineering/Implementation.
- At least 3 years of experience with Imperva is preferred.
- Candidates with experience in Cloudflare, Akamai, ModSecurity, AWS WAF, Azure WAF, or F5 ASM/Advanced WAF can also be considered.
- Strong understanding of HTTP/HTTPS, web application architecture, REST APIs, and common web attacks.
- Hands-on experience in WAF policy configuration, rule tuning, and false-positive reduction.
- Experience with SIEM integration and security monitoring.
- Strong scripting and automation skills using Python, PowerShell, or Bash.
- Valuable understanding of Regex, JSON, and YAML.
- Experience with CI/CD and Infrastructure as Code.
- Strong troubleshooting and stakeholder communication skills.
Good to Have
- Experience with Bot Management and advanced bot detection techniques.
- Behavioral and fingerprint-based threat detection experience.
- Experience with API Gateways and API Security.
- Knowledge of API schema validation and authentication hardening.
- Working knowledge of CDN, cloud networking, reverse proxy, and edge security.
- Experience with Terraform and cloud security automation.
- Security certifications such as AWS Security Specialty, Azure Security Engineer, CCSP, CEH, or Security+.
- Experience with Jenkins, GitHub Actions, or Azure DevOps.
- Linux and Git experience.
Tools & Technologies WAF:
Imperva | Cloudflare | Akamai | AWS WAF | Azure WAF | F5 ASM/Advanced WAF | ModSecurity
Security: OWASP Top 10 | Bot Mitigation | Rate Limiting | L7 DDoS | API Security | TLS | Security Headers
SIEM/Monitoring: Splunk | Microsoft Sentinel | ELK | QRadar
Automation/IaC: Terraform | CloudFormation | ARM | Bicep
CI/CD: Jenkins | GitHub Actions | Azure DevOps
Programming/Scripting: Python | PowerShell | Bash | Regex | JSON | YAML
Other: Linux | Git | CDN | Reverse Proxy | REST APIs
Key Skills
WAF Engineering | WAF Implementation | Imperva | Cloudflare | Akamai | AWS WAF | Azure WAF | F5 WAF | WAF Policy Management | Rule Tuning | OWASP Top 10 | False Positive Reduction | Bot Management | Rate Limiting | L7 DDoS | API Security | SIEM | Python | PowerShell | Bash | Terraform | CI/CD | HTTP/HTTPS | REST APIs | TLS
Mandatory Project Experience
- Minimum 5+ years of hands-on WAF Engineering and Implementation.
- Minimum 3+ years hands-on experience with Imperva preferred.
- Experience designing and managing WAF policies across Dev/Stage/Production.
- Strong experience with WAF rule configuration, tuning, and false-positive reduction.
- Hands-on experience mitigating OWASP Top 10, bot attacks, credential stuffing, and L7 DDoS.
- Experience integrating WAF logs with SIEM platforms.
- Experience with Python/PowerShell/Bash automation and WAF APIs.
- Experience with Terraform/IaC and CI/CD integration.
- Experience working with application, DevOps, SRE, and security teams.
Please share the following details along with your updated resume:
- Full Name:
- Contact Number:
- Current Location:
- Total Experience:
- Relevant WAF Experience:
- Imperva Experience:
- Cloudflare Experience:
- Akamai Experience:
- AWS/Azure WAF Experience:
- F5 WAF Experience:
- WAF Implementation Experience:
- WAF Rule Tuning Experience:
- OWASP Top 10 Experience:
- Bot Management Experience:
- L7 DDoS Experience:
- SIEM Experience:
- Python/PowerShell/Bash Experience:
- Terraform/IaC Experience:
- CI/CD Experience:
- API Security Experience:
- Current Company:
- Notice Period:
- Current CTC:
- Expected CTC:
Share your updated resume to
[email protected] We look forward to connecting with you!
📌 [BIWWSr. WAF Engineer (Hyderabad)
🏢 ZettaMine Labs
📍 Hyderabad