Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, and operations, we help clients realize their boldest ambitions and build future-ready, sustainable businesses. With over 230,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.
Job Description
Profile: Technical Lead (Application Security - WAF)
Location: No location constraints (but preference to Pune/Mumbai)
About the role:
We are looking to onboard Technical Lead (Application Security - WAF) for our GCISO Unit.
R͏oles & Responsibilities
• Onboard applications onto WAF and ensure all internet-facing apps are properly protected behind WAF
• Configure and enforce WAF policies and rule sets aligned to OWASP Top 10 and organizational standards
• Perform regular rule tuning and fine-tuning to reduce false positives/negatives and improve detection accuracy
• Collaborate with application and DevOps teams for safe rule deployment
• Maintain WAF dashboards, reports, and metrics (coverage, blocked attacks, false positives, etc.)
• Establish and enforce WAF governance processes, standards, and SOPs
• Validate WAF effectiveness through attack simulations / penetration testing. Conduct comprehensive DAST penetration testing on web, APIs, mobile, and thick client applications. Leverage automated scanning tools (e.g., Burp Suite, Webinspect) as part of the testing.
• Perform in-depth manual application penetration testing to showcase the exploitation steps of vulnerabilities to understand their impact.
• Conduct tool based SAST and SCA using Opentext Fortify and Sonatype.
• Collaborate with development teams to remediate identified vulnerabilities and provide security recommendations.
͏Qualifications
• Bachelor’s degree in a technical field
• 3-6years of experience in application security testing
• Strong experience in WAF technologies (e.g., F5, Akamai, Cloudflare, AWS WAF, Imperva, Azure WAF)
• Hands-on experience in policy creation, rule tuning, and false positive reduction
• Should have experience in:
• Dynamic Application Security Testing (DAST)
• Static Application Security Testing (SAST)
• Software Composition Analysis (SCA)
• Manual penetration testing of web, APIs, mobile, and thick client applications
• Well versed with tools – BurpSuite, Webinspect, Fortify, Sonatype
• Good communication skills to work with developers, infra, and security teams
Good to have Certifications:
-CEH, GWAPT, GPEN, CISSP, or similar
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention. Come to Wipro. Realize your ambitions.
Applications from people with disabilities are explicitly welcome.