Do you love a career where you Experience , Grow & Contribute at the same time, while earning at least 10% above the market? If so, we are excited to have bumped onto you.
Learn how we are redefining the meaning of work , and be a part of the team raved by Clients, Job-seekers and Employees.
If you are a Application Security Engineer looking for excitement, challenge and stability in your work, then you would be glad to come across this page.
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Check if you are up for maximizing your earning/growth potential, leveraging our Disruptive Talent Solution.
Role: Application Security Engineer
Work Mode: Hybrid
Type: Contract to Hire
Notice Period:Immdiate Joiners
Requirements
The Application Security Engineer candidate will have a strong background incybersecurity and understanding of web application and zero trust proxy securitypractices. The primary responsibility of the Engineer will be to ensure theeffective deployment, configuration, and maintenance of our systems for Globalcustomers. This role requires expertise in Web Application Firewalls, ZeroTrust Proxy, Cloud security as well as experience with alerts and detectionsand data log analysis. This role will be part of the Application EdgeProtection Service within the CyberSecurity pillar.
Role SpecificResponsibilities
- Web ApplicationFirewall Management: Deploy,configure, and maintain web application firewall systems to protect our webapplications against potential threats and vulnerabilities.
- Zero Trust Proxy: Deploy, configure, and Zero Trust Proxy systems to supportidentity gates to include defining and maintaining policies and connectors.
- Security IncidentResponse: Monitor and analyzesecurity events, alerts, and logs generated by the web application firewallsystems. Investigate and respond to potential security incidents, workingclosely with the Security Operations Center (SOC) and other Cybersecurityteams.
- Detection andAnalysis: Develop and maintain detection rules, alerts, and reports to proactively identify and mitigate risks utilizing logs. Providesinvestigation findings to relevant business units to help improve informationsecurity posture.
- CDNIntegration: Collaborate with theinfrastructure and application teams tointegrate the web applicationfirewall with CDNssuch Akamai and Radware, ensuring seamless trafficmanagement and content delivery.
- VulnerabilityAssessment: Utilize WAF data toidentify potential vulnerabilities and recommend appropriate remediationmeasures to customers.
- Documentation andReporting: Maintain accurate documentation of WAFconfigurations, policies, and procedures. Prepare reports and metrics relatedto web application security, including trends, incident summaries, andmitigation strategies, as needed.
- Collaboration: This role requires ability to explain security details to non-security teams such as application and engineering teams.Must be able tocollaborate withcross-functional teams to ensure effective communication, knowledge sharing,and alignment of security objectives. Provide guidance to application teams onapplication security best practices and security awareness, as needed.
Automation: This role required individualswho are knowledgeable of automation processes, python terraform, use of AI andCloud native concepts with AWS, Azure and Google cloud.
Education(degree): Bachelor’s Degree or equivalent experience
Other(Explain): B achelor's Degree/University Degree and/or UndergraduateDiploma in Information Security, Information Technology, Computer Science,Engineering or equivalent years in experience
Yearsof Experience: 4+ years with minimum 2 yearsin network security and 2 years in application security
TechnicalSkills
- Strong knowledge ofweb application security concepts, OWASP Top 10 vulnerabilities, and relatedmitigation techniques.
- Understanding ofauthentication and authorization flows (OAuth, SAMAL, OIDC)
- Strong technicalbackground with Web Application Firewall (WAF), Zero Trust Network Access,APIs, and Cloud security policies.
- Understanding of APIsecurity issues and API authentication.
- Previous experiencein a Security Operations Center (SOC) or performing cybersecurity analysis, loganalysis, and threat detection is highly desirable.
- Good understanding of informationsecurity principles and policy enforcement.
- Solid comprehensionof HTTP protocol and demonstrated ability to troubleshoot using HTTP logs
- Strong technicalbackground in web development and familiarity with potential attackvectors/methods
- Understanding of Authentication,DNS, Networks, Firewalls, SSL Certificates
Experiencein the following areas are strongly preferred:
- Knowledge of Web Application Firewalltechnologies (Akamai)
- Knowledge of Zero Trust frameworkand technologies
- Experience integrating zero trustwith WAF
- Familiarity withcloud security services, concepts, and best practices (AWS, Azure, GCP)
- Infrastructure ascode (Terraform) and automation using Python
- Ethical hacking
- CISSP, CISM, CISA,GIAC or other security certifications are desired
- Familiarity andcomfortability using AI tools
SoftSkills
- High degree ofpersonal integrity and ethics with a passion for protecting people and systems againstcybersecyurity threats
- Excellent writtenand oral communication and presentation skills for technical and businessaudiences
- Advanced criticalthinking, problem solving and technical troubleshooting abilities
- Track record ofgetting things done quickly and with high levels of quality
- Demonstrated abilityto operate in a dynamic, evolving environment
- Ability tocoordinate completion of multiple tasks and meet aggressive time frames
- Strong analyticalskills with high attention to detail and accuracy
- Experience with andthe ability to thrive in a complex and fast-paced technology and/or informationsecurity organization, within a large enterprise environment