02 Oct
|
Sincera Technology India
|
Bengaluru
02 Oct
Sincera Technology India
Bengaluru
As part of the under-Network Security Department, the Web Application Security team is responsible for deploying
and maintaining the Firms internet facing web application security controls. The technology and solution stack spans
all internet facing web applications of the Institutional Security and Wealth Management Businesses. It consists of
home-grown software, 3rd party software, open-source products, appliances, and auxiliary services and solutions.
An Akamai Resident Engineer will be responsible for onboarding applications to Akamai, tuning and operating WAF
protections, troubleshooting production issues, reviewing security events, supporting AI/API security initiatives,
coordinating quarterly security improvements, and acting as the technical bridge between Akamai and internal
application teams.
Morgan Stanley anticipates the need for one (1) Akamai Resident Engineer and one (1) backup resource, with a
maximum of two resources proposed.
Consultant’s responsibilities under this Task Order will include:
1. WAF Onboarding and Application Migration
• Lead onboarding internet-facing applications to Akamai WAF.
• Work with applications, DNS, load balancer, proxy, firewall, and QA teams to migrate applications into
monitor/alert mode and ultimately deny mode.
• Coordinate testing, rollout plans, traffic cutovers, validation, and rollback procedures.
2. WAF Policy Tuning and False Positive Analysis
• Analyze production traffic and WAF events to identify false positives.
• Tune security policies to reduce business impact while maintaining strong protection.
• Review blocked requests, investigate application behavior, and create narrowly scoped exceptions when
justified.
3. AI, LLM, and API Security Support
• Troubleshoot AI- and LLM-related traffic that triggers WAF protections such as SQL injection controls.
• Work with application teams and vendors to design compensating controls, header-based attestation
mechanisms, and API-specific protections.
• Evaluate emerging Akamai AI security capabilities such as AI-powered detections, Firewall for AI, bot
identification, and agentic AI protections.
4. Security Event Monitoring and Threat Analysis
• Review WAF, Bot Manager, DDoS, Client Reputation, and API Security events.
• Analyze attack patterns and determine whether activity is malicious or legitimate.
• Recommend policy improvements and mitigations based on observed threats.
5. Quarterly Security Reviews and Platform Upgrades
• Conduct structured reviews of applications protected by Akamai.
• Evaluate opportunities to move applications from monitoring to mitigation mode.
• Perform quarterly WAF upgrades, policy reviews, and security-control tuning to keep protections aligned
with current threat intelligence.
6. Incident Response and Troubleshooting
• Assist with production incidents where application behavior changes after WAF enablement.
• Investigate latency issues, traffic-routing problems, load-balancer interactions, client IP handling, surge
queue events, and application outages.
• Coordinate with Akamai engineering resources and internal teams to identify root causes and corrective
actions
7.
Security Architecture and Design Consulting
• Advise application teams on secure web architectures, OWASP protections, API security, bot mitigation,
client reputation controls, and DDoS protection.
• Provide guidance on best practices for onboarding, secure application design, and remediation of web
vulnerabilities
8. Program Management and Stakeholder Engagement
• Partner with application owners, infrastructure teams, auditors, risk managers, and security leadership.
• Track onboarding progress, risks, dependencies, and remediation activities through program governance
and ticketing systems.
• Present status updates, metrics, risks, and remediation plans to senior management
9. Operational Metrics and Reporting
• Produce dashboards and reporting covering WAF adoption, deny-mode coverage, bot mitigation
effectiveness, API discovery, security exceptions, and attack activity.
• Measure onboarding progress, control effectiveness, and risk reduction across the organization.
10. Vendor Liaison and Technology Roadmap Guidance
• Act as the primary interface between the enterprise and Akamai.
• Engage Akamai product teams on product defects, enhancement requests, AI roadmap discussions, policy
recommendations, and complex troubleshooting.
• Evaluate current Akamai capabilities and coordinate pilot deployments where appropriate.
Mandatory Experience
• 5+ years of Akamai experience
• Akamai Kona Site Defender
• Akamai Bot Manager
• Akamai API Security
• OWASP Top 10
• Incident response experience
Preferred Experience
• AI/LLM security
• Akamai Firewall for AI
• Enterprise-scale migration experience
• Financial services experience
📌 Akamai Security Engineer (Bengaluru)
🏢 Sincera Technology India
📍 Bengaluru