Senior WAF Engineer

Seintiv Talent Solutions

Hyderabad

On-site

INR 4,000,000 - 6,000,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Seintiv Talent Solutions seeks a Senior WAF Engineer with 7+ years of experience to design, implement, and optimize WAF policies for web applications and APIs. You will work across dev/stage/prod, tuning rules, and responding to security threats while ensuring application performance.

You will have hands-on experience with Imperva or other WAFs, strong knowledge of OWASP Top 10, and collaborate with DevOps, SRE, and development teams. CI/CD, IaC, and scripting are part of the role.

Qualifications

  • 7+ years in WAF engineering and implementation.
  • Hands-on with at least one WAF platform (Imperva preferred) or equivalents.
  • Strong understanding of OWASP Top 10 and REST APIs.
  • Experience with logging/monitoring and SIEM integrations.

Responsibilities

  • Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).
  • Tune rules to mitigate OWASP Top 10, reduce false positives, and balance security with performance.
  • Implement rate limiting, IP reputation controls, bot mitigation, and staged enforcement.
  • Collaborate with DevOps, SRE, and developers to improve security posture.

Skills

WAF engineering
Threat detection
Scripting
Team collaboration

Tools

Imperva
Cloudflare
Akamai
AWS WAF
Azure WAF

Job description

Job Description

We are seeking a Senior WAF Engineer with 7+ years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 3+ years of hands-on experience with Imperva (preferred) or Cloudflare. In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents. You will collaborate closely with DevOps, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.

Key Responsibilities
  • Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).
  • Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.).
  • Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor to challenge to block).
  • Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.
We Need
  • 7+ years' experience in WAF engineering and Implementation.
  • Hands-on experience with at least one WAF platform: Imperva(preferred), Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF,
  • Strong understanding of web app architecture, REST APIs, and common attack patterns.
  • Proven experience tuning WAF rules and balancing security vs. false positives.
  • Experience with logging/monitoring and SIEM integrations.
  • Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML).
  • Familiarity with CI/CD and Infrastructure-as-Code principles.
  • Good troubleshooting and stakeholder communication skills.
Preferred Qualifications

Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).

Experience with API gateways and API security controls (schema validation, auth hardening).

Working knowledge of cloud networking/CDN/reverse proxy concepts.

Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).

Tools & Technologies

WAF (AWS/Azure/Cloudflare/F5/Imperva), CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/GitHub Actions/Azure DevOps), Python, Linux, Git.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Web Application Firewall (WAF) Engineer
Senior Web Application Firewall (WAF) Engineer

TalentAmp • India

On-site
INR 1,000,000 - 1,500,000
Cyber Security Engineer - WAF
Cyber Security Engineer - WAF

Meta Infotech • Mumbai

On-site
INR 1,400,000 - 2,100,000
Senior Web Application Firewall Engineer
Senior Web Application Firewall Engineer

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Senior/Lead Security Engineer - AKAMAI
Senior/Lead Security Engineer - AKAMAI

EPAM Systems Inc • India

On-site
INR 1,800,000 - 2,800,000
Senior Web Application Firewall Consultant
Senior Web Application Firewall Consultant

EY • Thiruvananthapuram

On-site
INR 1,200,000 - 1,700,000
Senior Network Engineer
Senior Network Engineer

CtrlS Datacenters • Hyderabad

On-site
INR 1,200,000 - 1,800,000
GMS-Senior-Web Application Firewall
GMS-Senior-Web Application Firewall

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,500,000 - 4,000,000
WAF-Akami
WAF-Akami

HR India Solutions • Pune District

On-site
INR 800,000 - 1,200,000
Network Security(Akamai WAF)
Network Security(Akamai WAF)

Cloudxtreme • Chennai District, Bengaluru

On-site
INR 900,000 - 1,200,000
Security Researcher II (WAF)
Security Researcher II (WAF)

Lever, Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000