18 days ago
Hyderābād, IndiaSenior
Responsibilities
- Design, implement, and manage WAF policies for web applications and APIs across development, staging, and production environments.
- Configure and tune managed and custom rules to mitigate OWASP Top 10 threats, including SQL injection, XSS, CSRF, RCE, LFI/RFI, and SSRF.
- Reduce false positives through traffic baselining, exception handling, and staged monitor, challenge, and block enforcement.
- Implement rate limiting, IP reputation, geographic and ASN controls, and bot mitigation strategies.
- Integrate WAF logs with SIEM and log platforms and build threat-monitoring dashboards and alerts.
- Support incident response for active attacks, including Layer 7 DDoS and exploit attempts, and perform post-incident improvements.
- Automate WAF deployments and configuration management using infrastructure-as-code tools and CI/CD pipelines.
- Conduct security reviews, reporting, and metrics tracking for blocked events, attacks, false-positive rates, and MTTR.
- Collaborate with application teams on secure headers, TLS, authentication flows, and compatibility testing.
- Use PowerShell or Python to integrate with Imperva APIs and improve scalable WAF operations.
Requirements
- At least 7 years of experience in WAF engineering and implementation.
- At least 3 years of hands-on experience with Imperva or Cloudflare is preferred.
- Hands-on experience with at least one WAF platform, including Imperva, Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, or F5 ASM/Advanced WAF.
- Strong understanding of HTTP/HTTPS, web application architecture, REST APIs, and common attack patterns.
- Experience tuning WAF rules and balancing security requirements against false positives.
- Experience with logging, monitoring, and SIEM integrations.
- Scripting and automation skills with PowerShell, Python, or Bash, plus regex and JSON/YAML.
- Familiarity with CI/CD and infrastructure-as-code principles.
- Experience with bot management, advanced detection techniques, API gateways, API security controls, cloud networking, CDNs, or reverse proxies is preferred.
- Security certifications such as AWS Security Specialty, Azure Security Engineer, CCSP, CEH, or Security+ are preferred.
Benefits
- Hybrid work flexibility in Zelis India.
- Comprehensive healthcare benefits, financial wellness programs, and cultural celebrations.
- Collaborative work culture, leadership development, and global exposure.
