Job Details
- Location: Bangalore
- Experience: 7 - 9 Years
- Job Type: Full Time
- Openings: 1
Role Description
Key Responsibilities
• Translate business and application security requirements into enterprise-grade WAAP and network security architectures.
• Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments.
• Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.
WAAP Responsibilities (Primary Focus)
• Architect, implement, and manage WAAP platforms, including:
ü Web Application Firewall (WAF)
ü API Security (discovery, protection, runtime analysis)
ü Bot Management o DDoS Protection (L3–L7)
• Design and deploy WAAP solutions using platforms such as:
ü Thales Imperva o Cloud-native WAFs (Azure, AWS WAF) or equivalent
• Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.
• Perform false positive tuning, policy optimization, and rule lifecycle management.
• Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.
• Integrate WAAP with:
ü SIEM/SOAR platforms
ü Identity providers
ü Threat intelligence feeds
• Collaborate with application teams to:
ü Onboard applications into WAAP platforms
ü Perform security assessments and risk reviews
ü Ensure minimal performance impact while enforcing strong security controls
• Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).
• Lead WAAP incident response and root cause analysis for application-layer attacks.
• Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).
• Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).
Core Network Security Responsibilities
• Architect and maintain secure network infrastructure across data center, campus, and cloud environments.
• Conduct security design reviews ensuring compliance with enterprise security standards.
• Provide risk reporting, control effectiveness, and security posture visibility.
• Support internal and external security audits.
• Manage and optimize Security Information and Event Management (SIEM) systems.
• Develop and maintain network security policies and procedures.
• Collaborate with cybersecurity, infrastructure, and application teams globally.
Technical Qualifications
• 10+ years of experience in network security architecture, engineering, and operations.
WAAP & Application Security Expertise (Mandatory)
• Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted).
• Deep understanding of:
ü OWASP Top 10 (Web & API)
ü Application-layer threats and mitigation techniques
• Hands-on experience in:
ü WAF policy creation and tuning
ü API security controls (schema validation, authentication enforcement)
ü Bot mitigation strategies o DDoS protection architecture (L3–L7)
• Experience in:
ü Traffic analysis (HTTP/HTTPS, TLS inspection)
ü Behavioral-based threat detection
• Strong understanding of:
ü Secure application architectures (monolith, microservices, APIs)
ü DevSecOps integration and CI/CD security controls (nice to have)
Network Security & Infrastructure
• Strong hands-on experience in:
ü Firewalls (Fortinet, Palo Alto, Juniper)
ü IDS/IPS, VPN, SIEM
• Expertise in:
ü Firewall policy design, NAT, routing, inspection, and threat prevention
• Experience in designing secure:
ü Hybrid (on-prem + cloud + internet-facing) environments
• Experience in:
ü Proxy architectures (forward/reverse)
ü Secure internet gateways
Networking & Protocol Expertise
• Strong knowledge of:
ü TCP/IP, DNS, HTTP/HTTPS, TLS/SSL
ü Routing protocols (BGP, OSPF, MPLS)
• Experience with:
ü QoS, NetFlow, ACLs, NAT, IP traffic management
ü Network monitoring and analysis tools
Cloud & Integration
• Experience securing applications in:
ü AWS, Azure, GCP
• Familiarity with:
ü Cloud-native WAF and API security tools
• Integration experience with:
ü SIEM, EDR/XDR, IAM platforms
Data Center & Enterprise Networking
• Experience managing enterprise environments with:
ü Aruba, Arista, Juniper switches
ü Firewalls, load balancers, WAN optimization tools
• Understanding of:
ü High availability and performance optimization for application traffic
Operations & Lifecycle Management
• Lead onboarding and lifecycle management of applications into WAAP platforms.
• Perform security tuning, upgrades, and optimization activities.
• Support incident response and threat mitigation at application layer.
• Work within ITIL frameworks (incident, problem, change management).
Education & Certifications
• Bachelor’s degree in computer science, IT, or related field (or equivalent experience).
• 10+ years of experience in enterprise network security and application security.
• Preferred certifications:
ü CCNP / CCIE / JNCIE
ü Security certifications (CISSP, CISM)
ü Vendor certifications (Akamai, AWS Security, Azure Security)
Key Differentiators (What This JD Targets)
• Positions WAAP as a primary security control layer, not an add-on
• Strong alignment with:
ü Application security + Network security convergence
ü Defense-in-depth strategy
• Emphasizes:
ü API security (modern requirement)
ü Bot/DDoS protection (critical for internet-facing apps)
• Keeps strong foundation in:
ü Firewalls, SIEM, network architecture
Skills
Access Control Lists, Application Security, Issue Analysis, Incident Response