GMS-Senior-Web Application Firewall

Ernst & Young Advisory Services Sdn Bhd

Bengaluru

On-site

INR 2,500,000 - 4,000,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

EY seeks a Senior Web Application Firewall (WAF) Engineer to own the end‑to‑end lifecycle of our application security gateway infrastructure. You will assess architectures, build deployment policies, transition to blocking mode, and operate at scale to protect APIs, microservices, and web apps.

The role requires hands‑on tuning of WAF rulesets, bot mitigation, rate limiting, and integration with CI/CD pipelines for policy management.

Qualifications

  • 3–5 years of web application security/WAF administration experience.
  • Hands-on with leading WAF platforms (cloud or on-prem).
  • Strong scripting and IaC for policy management and automation.

Responsibilities

  • Own end‑to‑end WAF lifecycle: assess, build, transition and operate WAF infrastructure.
  • Tune policies, manage positive/negative security models, and monitor for false positives.
  • Collaborate with DevOps and application teams; ensure secure traffic and compliance.

Skills

WAF administration
Cloud/WAF platforms
OWASP Top 10
Python/Bash scripting
IaC (Terraform/CloudFormation)
Networking & protocols

Tools

Cloudflare
Akamai Kona
Imperva
F5 BIG-IP ASM
AWS WAF

Job description

Job Description: Senior Web Application Firewall (WAF) Engineer
Experience Level: 3–5 Years
Role Type: Full-Time
Role Overview

We are seeking a Senior Web Application Firewall (WAF) Engineer to own and drive the end-to-end lifecycle of our application security gateway infrastructure. Spanning the complete service delivery model—Assess, Build, Transition, and Operations—this role requires deep technical proficiency in protecting modern web applications, APIs, and microservices against sophisticated Layer 7 attacks (including OWASP Top 10, botnets, and DDoS). The ideal candidate will have hands‑on experience tuning advanced WAF rule sets, managing positive and negative security models, and collaborating closely with application development and DevOps teams.

Key Responsibilities
Assess (Architecture Review & Threat Modeling)
  • Conduct thorough security assessments of existing web applications, API endpoints, and ingress traffic architectures.
  • Analyze current WAF policies, anomaly scores, and signature rulesets to identify coverage gaps against the OWASP Top 10 and API Security Top 10.
  • Collaborate with development and architecture teams to threat‑model upcoming applications and define WAF integration requirements.
  • Audit SSL/TLS termination configurations, cipher suites, and certificate lifecycles at the edge.
Build (Deployment & Policy Engineering)
  • Deploy, configure, and manage enterprise WAF solutions (e.g., Cloudflare Enterprise, Akamai Kona, Imperva, F5 Advanced WAF/BIG‑IP ASM, or AWS WAF).
  • Design and implement both negative security models (signatures, regex blocks) and positive security models (strict schema validation, OpenAPI/Swagger enforcement).
  • Configure advanced bot mitigation, rate limiting, geo‑fencing, and API security inspection layers.
  • Integrate WAF infrastructure with CI/CD pipelines (Infrastructure as Code) for automated policy deployment and version control.
Transition (Testing, Cutover & Handover)
  • Transition WAF policies from monitoring/audit mode to blocking mode safely, minimizing false positives and disruption to legitimate user traffic.
  • Coordinate User Acceptance Testing (UAT) and application functional sign‑offs prior to production traffic routing.
  • Produce comprehensive "As‑Built" documentation, tuning guidelines, escalation playbooks, and topology diagrams.
  • Conduct training and knowledge transfer sessions for operations and application support teams.
Operations & Continuous Management
  • Serve as the senior technical escalation point for complex Layer 7 security incidents, DDoS attacks, and web traffic anomalies.
  • Perform continuous rule tuning, signature optimization, and exception handling based on application updates and vulnerability scan results.
  • Monitor WAF performance, backend latency, error rates, and evasion technique indicators.
  • Ensure seamless log ingestion and telemetry forwarding to the SIEM/SOAR platforms for deep forensic investigation and continuous compliance reporting.
  • Understanding of ITIL-based Change Management, managing end‑to‑end change lifecycle activities, CAB coordination, and compliant implementation of infrastructure and application changes
Required Skills & Qualifications
  • Experience: 3–5 years of specialized experience in web application security, WAF administration, or application delivery controller (ADC) management.
  • Core Technologies: Deep, hands‑on expertise with leading cloud or on‑premise WAF platforms (e.g., Cloudflare, Akamai, Imperva, F5 Advanced WAF, or AWS/Azure WAF).
  • Security Principles: Comprehensive understanding of the OWASP Top 10, API Top 10, SQL injection, Cross‑Site Scripting (XSS), Remote Code Execution (RCE), and XML/JSON attacks.
  • Networking & Protocols: Solid grasp of HTTP/HTTPS protocols, RESTful APIs, JSON/XML payloads, DNS, SSL/TLS handshakes, and reverse proxy architectures.
  • Automation & Scripting: Familiarity with automation tools, Python or Bash scripting, and Infrastructure as Code (Terraform/CloudFormation) for policy management.
  • Certifications: Industry certifications (e.g., Certified AppSec Practitioner (CAP), CISSP, CCSP, or vendor‑specific WAF/Cloud security credentials) are highly preferred.
  • Soft Skills: Excellent stakeholder management skills, ability to bridge security requirements with developer workflows, and strong analytical problem‑solving abilities.

EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets.

Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.

Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Select how often (in days) to receive an alert:

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Web Application Firewall Engineer
Senior Web Application Firewall Engineer

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,500,000 - 2,100,000
GMS_Senior_WAF
GMS_Senior_WAF

EY • Bengaluru

On-site
INR 2,400,000 - 3,600,000
GMS_Senior_WAF
GMS_Senior_WAF

EY • Thiruvananthapuram

On-site
INR 2,000,000 - 3,500,000
Senior Security Engineer - Web Application Firewall and Network Segmentation
Senior Security Engineer - Web Application Firewall and Network Segmentation

Ernst & Young LLP ( EY India ) • Thiruvananthapuram

On-site
INR 1,800,000 - 3,000,000
Senior Web Application Firewall (WAF) Engineer
Senior Web Application Firewall (WAF) Engineer

TalentAmp • India

On-site
INR 1,000,000 - 1,500,000
Senior WAF Engineer
Senior WAF Engineer

Seintiv Talent Solutions • Hyderabad

On-site
INR 4,000,000 - 6,000,000
Senior Web Application Firewall Consultant
Senior Web Application Firewall Consultant

EY • Thiruvananthapuram

On-site
INR 1,200,000 - 1,700,000
EY-Cybersecurity-Network Security And Security Infrastructure Operations-Manager
EY-Cybersecurity-Network Security And Security Infrastructure Operations-Manager

EY • Ernakulam

On-site
INR 3,000,000 - 6,000,000
GMS-Senior-Firewall and VPN Management
GMS-Senior-Firewall and VPN Management

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,400,000 - 3,600,000
Cyber Security Engineer - WAF
Cyber Security Engineer - WAF

Meta Infotech • Mumbai

On-site
INR 1,400,000 - 2,100,000