B

Network Security-WAAP

Birlasoft · State of Karnataka, India

3–9 yrs experiencePosted 1w ago

Job description

Country/Region: IN Requisition ID: 38398 Work Model: Position Type: Salary Range: Location: INDIA - BENGALURU - HP # **Title:** **Network Security-WAAP** Description: ## **Area(s) of responsibility** **Skills: Network Security-WAAP** **Experience: 6-10 years** **Location: (Bangalore Preferred)/ Mumbai/ Pune/ Noida/ Hyderabad/ Chennai** **Key Responsibilities** **WAAP Responsibilities (Primary Focus)** - Architect, implement, and manage **WAAP platforms**, including: - - Web Application Firewall (WAF) - API Security (discovery, protection, runtime analysis) - Bot Management - DDoS Protection (L3–L7) - Design and deploy WAAP solutions using platforms such as: - - **Thales Imperva** - Cloud-native WAFs (Azure, AWS WAF) or equivalent - Develop and maintain **custom WAF rules, security policies, and signatures** to protect critical applications. - Perform **false positive tuning, policy optimization, and rule lifecycle management**. - Enable **API discovery, schema enforcement, and protection against OWASP API Top 10 threats**. - Integrate WAAP with: - - **SIEM/SOAR platforms** - Identity providers - Threat intelligence feeds - Collaborate with application teams to: - - Onboard applications into WAAP platforms - Perform **security assessments and risk reviews** - Ensure minimal performance impact while enforcing strong security controls - Implement protection against **OWASP Top 10 vulnerabilities** (SQLi, XSS, RCE, etc.). - Lead **WAAP incident response** and root cause analysis for application-layer attacks. - Define and track **application security metrics and KPIs** (attack trends, mitigation effectiveness). - Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards). **WAAP & Application Security Expertise (Mandatory)** - Strong experience with **WAAP platforms** (Akamai preferred; Cloud WAF or equivalent accepted). - Deep understanding of: - - **OWASP Top 10 (Web & API)** - Application-layer threats and mitigation techniques - Hands-on experience in: - - WAF policy creation and tuning - API security controls (schema validation, authentication enforcement) - Bot mitigation strategies - DDoS protection architecture (L3–L7) - Experience in: - - **Traffic analysis (HTTP/HTTPS, TLS inspection)** - **Behavioral-based threat detection** - Strong understanding of: - - Secure application architectures (monolith, microservices, APIs) - DevSecOps integration and CI/CD security controls (nice to have) **Network Security & Infrastructure** - Strong hands-on experience in: - - Firewalls (Fortinet, Palo Alto, Juniper) - IDS/IPS, VPN, SIEM - Expertise in: - - Firewall policy design, NAT, routing, inspection, and threat prevention - Experience in designing secure: - - Hybrid (on-prem + cloud + internet-facing) environments - Experience in: - - Proxy architectures (forward/reverse) Secure internet gateways