Country/Region:  IN
Requisition ID:  38398
Work Model: 
Position Type: 
Salary Range: 
Location:  INDIA - BENGALURU - HP

Title:  Network Security-WAAP

Description: 

Area(s) of responsibility

Skills: Network Security-WAAP

Experience: 6-10 years

Location: (Bangalore Preferred)/ Mumbai/ Pune/ Noida/ Hyderabad/ Chennai

Key Responsibilities

WAAP Responsibilities (Primary Focus)

  • Architect, implement, and manage WAAP platforms, including:
    • Web Application Firewall (WAF)
    • API Security (discovery, protection, runtime analysis)
    • Bot Management
    • DDoS Protection (L3–L7)
  • Design and deploy WAAP solutions using platforms such as:
    • Thales Imperva
    • Cloud-native WAFs (Azure, AWS WAF) or equivalent
  • Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.
  • Perform false positive tuning, policy optimization, and rule lifecycle management.
  • Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.
  • Integrate WAAP with:
    • SIEM/SOAR platforms
    • Identity providers
    • Threat intelligence feeds
  • Collaborate with application teams to:
    • Onboard applications into WAAP platforms
    • Perform security assessments and risk reviews
    • Ensure minimal performance impact while enforcing strong security controls
  • Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).
  • Lead WAAP incident response and root cause analysis for application-layer attacks.
  • Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).
  • Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).

WAAP & Application Security Expertise (Mandatory)

  • Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted).
  • Deep understanding of:
    • OWASP Top 10 (Web & API)
    • Application-layer threats and mitigation techniques
  • Hands-on experience in:
    • WAF policy creation and tuning
    • API security controls (schema validation, authentication enforcement)
    • Bot mitigation strategies
    • DDoS protection architecture (L3–L7)
  • Experience in:
    • Traffic analysis (HTTP/HTTPS, TLS inspection)
    • Behavioral-based threat detection
  • Strong understanding of:
    • Secure application architectures (monolith, microservices, APIs)
    • DevSecOps integration and CI/CD security controls (nice to have)

Network Security & Infrastructure

  • Strong hands-on experience in:
    • Firewalls (Fortinet, Palo Alto, Juniper)
    • IDS/IPS, VPN, SIEM
  • Expertise in:
    • Firewall policy design, NAT, routing, inspection, and threat prevention
  • Experience in designing secure:
    • Hybrid (on-prem + cloud + internet-facing) environments
  • Experience in:
    • Proxy architectures (forward/reverse)

Secure internet gateways