UST
Posted 4d ago

Senior Network Security Engineer – WAAP (Web Application & API Protection)

UST
Bangalore, Karnataka, India
OnsiteFull Time
Responsibilities
  • architecting WAAP
  • managing firewalls
  • responding incidents
Requirements
  • Requires a bachelor's degree or equivalent experience and 10+ years in enterprise network and application security
  • Including WAAP, WAF
  • API security
  • Firewalls, SIEM
  • Cloud security, and network architecture
Technical tools mentioned
Thales ImpervaAzureAWS WAFAkamaiSIEMSOAROWASP Top 10CI/CDFortinetPalo AltoJuniperIDS/IPSVPNTCP/IPDNSHTTP/HTTPSTLS/SSLBGPOSPFMPLSQoSNetFlowACLsNATAWSGCPEDR/XDRIAMArubaAristaWAN

Job description

Job Details

  • Location: Bangalore
  • Experience: 7 - 9 Years
  • Job Type: Full Time
  • Openings: 1

Role Description

Key Responsibilities 

• Translate business and application security requirements into enterprise-grade WAAP and network security architectures.

• Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments.

 • Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.

 

 WAAP Responsibilities (Primary Focus)

• Architect, implement, and manage WAAP platforms, including:

ü  Web Application Firewall (WAF)

ü  API Security (discovery, protection, runtime analysis)

ü  Bot Management o DDoS Protection (L3–L7)

• Design and deploy WAAP solutions using platforms such as:

ü  Thales Imperva o Cloud-native WAFs (Azure, AWS WAF) or equivalent

• Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.

• Perform false positive tuning, policy optimization, and rule lifecycle management.

 • Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.

• Integrate WAAP with:

ü  SIEM/SOAR platforms

ü  Identity providers

ü  Threat intelligence feeds

• Collaborate with application teams to:

ü  Onboard applications into WAAP platforms

ü  Perform security assessments and risk reviews

ü  Ensure minimal performance impact while enforcing strong security controls

• Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).

 • Lead WAAP incident response and root cause analysis for application-layer attacks.

• Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).

 • Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).

 

Core Network Security Responsibilities

• Architect and maintain secure network infrastructure across data center, campus, and cloud environments.

• Conduct security design reviews ensuring compliance with enterprise security standards.

• Provide risk reporting, control effectiveness, and security posture visibility.

• Support internal and external security audits.

• Manage and optimize Security Information and Event Management (SIEM) systems.

• Develop and maintain network security policies and procedures.

• Collaborate with cybersecurity, infrastructure, and application teams globally. 

Technical Qualifications

• 10+ years of experience in network security architecture, engineering, and operations.

 WAAP & Application Security Expertise (Mandatory)

• Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted).

 • Deep understanding of:

ü  OWASP Top 10 (Web & API)

ü  Application-layer threats and mitigation techniques

• Hands-on experience in:

ü  WAF policy creation and tuning

ü  API security controls (schema validation, authentication enforcement)

ü  Bot mitigation strategies o DDoS protection architecture (L3–L7)

• Experience in:

ü  Traffic analysis (HTTP/HTTPS, TLS inspection)

ü  Behavioral-based threat detection

• Strong understanding of:

ü  Secure application architectures (monolith, microservices, APIs)

ü  DevSecOps integration and CI/CD security controls (nice to have) 

 

Network Security & Infrastructure

• Strong hands-on experience in:

ü  Firewalls (Fortinet, Palo Alto, Juniper)

ü  IDS/IPS, VPN, SIEM

• Expertise in:

ü  Firewall policy design, NAT, routing, inspection, and threat prevention

• Experience in designing secure:

ü  Hybrid (on-prem + cloud + internet-facing) environments

• Experience in:

ü  Proxy architectures (forward/reverse)

ü  Secure internet gateways

 

Networking & Protocol Expertise

• Strong knowledge of:

ü  TCP/IP, DNS, HTTP/HTTPS, TLS/SSL

ü  Routing protocols (BGP, OSPF, MPLS)

• Experience with:

ü  QoS, NetFlow, ACLs, NAT, IP traffic management

ü  Network monitoring and analysis tools

Cloud & Integration

• Experience securing applications in:

ü  AWS, Azure, GCP

• Familiarity with:

ü  Cloud-native WAF and API security tools

• Integration experience with:

ü  SIEM, EDR/XDR, IAM platforms

 

Data Center & Enterprise Networking

• Experience managing enterprise environments with:

ü  Aruba, Arista, Juniper switches

ü  Firewalls, load balancers, WAN optimization tools

• Understanding of:

ü  High availability and performance optimization for application traffic

Operations & Lifecycle Management

• Lead onboarding and lifecycle management of applications into WAAP platforms.

• Perform security tuning, upgrades, and optimization activities.

• Support incident response and threat mitigation at application layer.

• Work within ITIL frameworks (incident, problem, change management).

 

 Education & Certifications

• Bachelor’s degree in computer science, IT, or related field (or equivalent experience).

• 10+ years of experience in enterprise network security and application security.

 

• Preferred certifications:

ü  CCNP / CCIE / JNCIE

ü  Security certifications (CISSP, CISM)

ü  Vendor certifications (Akamai, AWS Security, Azure Security)

Key Differentiators (What This JD Targets)

• Positions WAAP as a primary security control layer, not an add-on

• Strong alignment with:

ü  Application security + Network security convergence

ü  Defense-in-depth strategy

• Emphasizes:

ü  API security (modern requirement)

ü  Bot/DDoS protection (critical for internet-facing apps)

• Keeps strong foundation in:

ü  Firewalls, SIEM, network architecture

Skills

Access Control Lists, Application Security, Issue Analysis, Incident Response

About UST

Global provider of digital transformation and IT services.

Year founded
1999
Employees
30000
Organization type
Private
Latest investment
Raised $1.00B Private Equity (2018) — led by Temasek
Headquarters
US

Similar jobs

Network Security Engineer roles near Bangalore, Karnataka
13h
Save
Mark Applied
Hide
DIGITAL SECURITY - Threat Prevention - NETWORK SECURITY - Proxy
Hyderabad or Bengaluru or Milpitas or Seattle or Princeton or Cape Town or London or Zurich or Singapore or Mexico City
RemoteFull Time
Zensar
ZensarNational Stock Exchange of India: ZENSARTECH: Global technology firm providing digital transformation and infrastructure services.
7+ YOERequires 7+ years in network and security engineering, 4+ years with Zscaler, global enterprise experience, and a bachelor's degree or equivalent practical experience.
Zscaler Internet Access (ZIA), Zscaler Private Access (ZPA), Zscaler Digital Experience (ZDX), Cloud Firewall, CASB, Browser Isolation, Data Loss Prevention (DLP), SSL Inspection, Azure AD (Entra ID), Okta, Ping Identity, Active Directory, SAML, OAuth, OpenID Connect, Multi-Factor Authentication (MFA), Python, YAML, Jira, Confluence, Ansible
1d
Save
Mark Applied
Hide
Sr. Network Security Engineer with Microsegmentation
Bengaluru, Karnataka, India
OnsiteFull Time
Birlasoft
BirlasoftNational Stock Exchange of India: BSOFT: Provides digital transformation and IT consulting services for global enterprises.
8+ YOERequires 8–11 years of network security experience, including microsegmentation, Zero Trust, firewalls, cloud security, routing, network services, SDN/SD-WAN, proxies, and load balancing.
BGP, OSPF, RIP, MPLS, DNS, DHCP, NTP, Fortinet, FortiGate, Palo Alto, Juniper, AWS, Microsoft Azure, Google Cloud Platform (GCP), SIEM, IAM, EDR/XDR, F5 GTM/LTM, VPN, SDN, SD-WAN, NetFlow, ACLs, NAT, 802.11, IPv4, IPv6
4d
Save
Mark Applied
Hide
Administrator - Networks
Bangalore, Karnataka, India
OnsiteFull Time
Manhattan Associates
Manhattan AssociatesNASDAQ: MANH: Develops software to manage supply chains and omnichannel operations.
3+ YOERequires 3–4 years in network security engineering or operations, 1+ year in cloud security, TCP/IP and VPN expertise, Cisco security experience, and a related bachelor's degree or equivalent practical experience.
Cisco ISE, Cisco ASA, Cisco Firepower Threat Defense (FTD), VPN, IPsec, Cisco Umbrella, Secure Access, Splunk, SIEM, Cisco Secure Cloud Analytics (XDR), Azure, ServiceNow, Microsoft cloud security integrations, TCP/IP, IDS/IPS
6d
Save
Mark Applied
Hide
Network Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Point72
Point72: Global alternative investment firm managing capital and venture investments.
5+ YOERequires 5–7 years in network security, preferably in financial services or regulated environments, with firewall, cloud networking, segmentation, SASE, NDR, compliance, and security certification experience.
Illumio, Palo Alto Networks, GlobalProtect, Prisma Access, Cloudflare, Cisco ISE, AWS, Microsoft Azure, Google Cloud Platform (GCP), Guardicore, VMware NSX, VMware NSX-T, vArmour, Cisco ACI, ShieldX, Unisys Stealth, Zero Networks, zScaler, NetSkope, Darktrace, ExtraHop, Vectra, PCI DSS, HIPAA, GDPR
6d
Save
Mark Applied
Hide
L2 Network Security Engineer
Bengaluru, Karnataka, India
OnsiteFull Time
Systal
Systal: Global provider of managed network, cloud, and security solutions.
Enterprise or managed-services network security experience; networking, firewalls, VPNs, security incidents, SIEM, ServiceNow, ITIL, troubleshooting, documentation, and stakeholder communication skills.
TCP/IP, Check Point, IDS/IPS, SIEM, syslog, SolarWinds, Splunk, ServiceNow, ITIL, Cisco CCNA Security, CompTIA Security+
1w
Save
Mark Applied
Hide
T&T | Cyber: D&R | Assistant Manager | Network Security | Bengaluru
Bengaluru, Karnataka, India
OnsiteFull Time
Deloitte
Deloitte: Professional services firm providing audit, consulting, and advisory services.
4+ YOERequires 4+ years in network security and infrastructure support, cybersecurity or IT degree, firewall and VPN expertise, security platform experience, troubleshooting skills, and ability to mentor L1 teams.
Palo Alto, Fortinet, Cisco, Check Point, SIEM, EDR, XDR, DLP, WAF, PAM, CASB, NAC, Forescout, Cisco ISE, Aruba Clear Pass, Windows, Linux, Intune, Workspace ONE, Wireshark, TCPDump, Azure, AWS, GCP
1w
Save
Mark Applied
Hide
Network Security Engineer
Bangalore, Karnataka, India
OnsiteFull Time
Unisys
UnisysNYSE: UIS: Provides enterprise-scale IT services and digital transformation solutions.
4+ YOEBachelor's degree and 4–6 years of relevant experience, or an equivalent combination of education and experience; expertise in security controls, deployments, automation, APIs, and incident resolution.
API
1w
Save
Mark Applied
Hide
Network Security Engineer
Bengaluru, Karnataka, India
₹350k-₹600k/yr OnsiteFull Time
SNS India
SNS India: Provides comprehensive cybersecurity solutions and managed security services.
Bachelor's degree in a related field; hands-on FortiGate, FortiSwitch, or Check Point experience; Kannada proficiency; networking, troubleshooting, communication, and analytical skills.
FortiGate, FortiSwitch, Check Point, TCP/IP, VLANs