Senior Web Application Firewall Engineer

Ernst & Young LLP ( EY India )

Bengaluru

On-site

INR 1,500,000 - 2,100,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

EY in Bengaluru is seeking a Senior Web Application Firewall (WAF) Engineer to own the end-to-end lifecycle of our application security gateway infrastructure. You will protect modern web apps, APIs, and microservices against Layer 7 attacks and work with DevOps to automate policy deployment.

The role requires hands-on experience tuning WAF rules, integrating with CI/CD, and guiding incident response. You will collaborate with development teams, perform threat modeling, and produce documentation

Qualifications

  • 3–5 years of specialized experience in web application security, WAF administration, or ADC management.
  • Hands-on expertise with leading cloud or on-prem WAF platforms (Cloudflare, Akamai, Imperva, F5 Advanced WAF, AWS/Azure WAF).
  • Strong knowledge of OWASP Top 10, API Top 10, and common web attacks (SQLi, XSS, RCE).

Responsibilities

  • Assess architecture and threat model web applications, APIs, and ingress traffic.
  • Deploy, configure, and manage enterprise WAF solutions; implement negative and positive security models.
  • Tune rules, monitor performance, and integrate WAF with CI/CD and SIEM/SOAR platforms.

Skills

WAF administration
OWASP Top10
API security
Python scripting
Terraform IaC
CI/CD integration
Threat modelling
Stakeholder mgmt

Education

CAP/CISSP/CCSP preferred

Tools

Cloudflare
Akamai
Imperva
F5 ASM
AWS WAF
Azure WAF

Job description

GMS-Senior-Web Application Firewall At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Job Description:

Senior Web Application Firewall (WAF) Engineer Experience Level: 3–5 Years Role Type: Full-Time Role Overview We are seeking a Senior Web Application Firewall (WAF) Engineer to own and drive the end-to-end lifecycle of our application security gateway infrastructure. Spanning the complete service delivery model—Assess, Build, Transition, and Operations—this role requires deep technical proficiency in protecting modern web applications, APIs, and microservices against sophisticated Layer 7 attacks (including OWASP Top 10, botnets, and DDoS). The ideal candidate will have hands‑on experience tuning advanced WAF rule sets, managing positive and negative security models, and collaborating closely with application development and DevOps teams.

Key Responsibilities

Assess (Architecture Review & Threat Modeling) Conduct thorough security assessments of existing web applications, API endpoints, and ingress traffic architectures. Analyze current WAF policies, anomaly scores, and signature rulesets to identify coverage gaps against the OWASP Top 10 and API Security Top 10. Collaborate with development and architecture teams to threat‑model upcoming applications and define WAF integration requirements. Audit SSL/TLS termination configurations, cipher suites, and certificate lifecycles at the edge. Build (Deployment & Policy Engineering) Deploy, configure, and manage enterprise WAF solutions (e.g., Cloudflare Enterprise, Akamai Kona, Imperva, F5 Advanced WAF/BIG-IP ASM, or AWS WAF). Design and implement both negative security models (signatures, regex blocks) and positive security models (strict schema validation, OpenAPI/Swagger enforcement). Configure advanced bot mitigation, rate limiting, geo‑fencing, and API security inspection layers. Integrate WAF infrastructure with CI/CD pipelines (Infrastructure as Code) for automated policy deployment and version control. Transition (Testing, Cutover & Handover) Transition WAF policies from monitoring/audit mode to blocking mode safely, minimizing false positives and disruption to legitimate user traffic. Coordinate User Acceptance Testing (UAT) and application functional sign-offs prior to production traffic routing. Produce comprehensive "As‑Built" documentation, tuning guidelines, escalation playbooks, and topology diagrams. Conduct training and knowledge transfer sessions for operations and application support teams. Operations & Continuous Management Serve as the senior technical escalation point for complex Layer 7 security incidents, DDoS attacks, and web traffic anomalies. Perform continuous rule tuning, signature optimization, and exception handling based on application updates and vulnerability scan results. Monitor WAF performance, backend latency, error rates, and evasion technique indicators. Ensure seamless log ingestion and telemetry forwarding to the SIEM/SOAR platforms for deep forensic investigation and continuous compliance reporting. Understanding of ITIL-based Change Management, managing end-to-end change lifecycle activities, CAB coordination, and compliant implementation of infrastructure and application changes

Required Skills & Qualifications

Experience: 3–5 years of specialized experience in web application security, WAF administration, or application delivery controller (ADC) management. Core Technologies: Deep, hands‑on expertise with leading cloud or on‑premise WAF platforms (e.g., Cloudflare, Akamai, Imperva, F5 Advanced WAF, or AWS/Azure WAF). Security Principles: Comprehensive understanding of the OWASP Top 10, API Top 10, SQL injection, Cross‑Site Scripting (XSS), Remote Code Execution (RCE), and XML/JSON attacks. Networking & Protocols : Solid grasp of HTTP/HTTPS protocols, RESTful APIs, JSON/XML payloads, DNS, SSL/TLS handshakes, and reverse proxy architectures. Automation & Scripting: Familiarity with automation tools, Python or Bash scripting, and Infrastructure as Code (Terraform/CloudFormation) for policy management. Certifications: Industry certifications (e.g., Certified AppSec Practitioner (CAP), CISSP, CCSP, or vendor‑specific WAF/Cloud security credentials) are highly preferred. Soft Skills: Excellent stakeholder management skills, ability to bridge security requirements with developer workflows, and strong analytical problem‑solving abilities.

EY | Building a better working world

EY exists to build a better working world, helping to create long‑term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GMS-Senior-Web Application Firewall
GMS-Senior-Web Application Firewall

Ernst & Young Advisory Services Sdn Bhd • Bengaluru

On-site
INR 2,500,000 - 4,000,000
Senior Security Engineer - Web Application Firewall and Network Segmentation
Senior Security Engineer - Web Application Firewall and Network Segmentation

Ernst & Young LLP ( EY India ) • Thiruvananthapuram

On-site
INR 1,800,000 - 3,000,000
GMS_Senior_WAF
GMS_Senior_WAF

EY • Thiruvananthapuram

On-site
INR 2,000,000 - 3,500,000
GMS_Senior_WAF
GMS_Senior_WAF

EY • Bengaluru

On-site
INR 2,400,000 - 3,600,000
Senior Web Application Firewall (WAF) Engineer
Senior Web Application Firewall (WAF) Engineer

TalentAmp • India

On-site
INR 1,000,000 - 1,500,000
Senior WAF Engineer
Senior WAF Engineer

Seintiv Talent Solutions • Hyderabad

On-site
INR 4,000,000 - 6,000,000
EY-Cybersecurity-Network Security And Security Infrastructure Operations-Manager
EY-Cybersecurity-Network Security And Security Infrastructure Operations-Manager

EY • Ernakulam

On-site
INR 3,000,000 - 6,000,000
Senior Network Security Engineer - Firewall and VPN Management
Senior Network Security Engineer - Firewall and VPN Management

Ernst & Young LLP ( EY India ) • Bengaluru

On-site
INR 2,400,000 - 4,200,000
Security Researcher II (WAF)
Security Researcher II (WAF)

Lever, Inc. • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Security Researcher II (WAF)
Security Researcher II (WAF)

Balbix, Inc. • Bengaluru

On-site
INR 1,500,000 - 2,500,000