͏
Job Description: WAF Engineer
This role will play a critical role in enhancing our Web Application Firewall (WAF) across multiple solutions and applications and will be pivotal in crafting, testing, and implementing advanced WAF solutions.
This role requires in depth knowledge across multiple platforms to be able to assess capabilities and ensure consistent coverage across platforms. It will involve a strong focus on WAF tuning via detailed log analysis, false positive detection and mitigation, and making tuning and configuration recommendations. The ideal candidate will have experience in SOC for in-depth log analysis and have previously worked with the Akamai platform, although working with at least two major WAF vendors such as F5, AWS, GCP, is also key.
The successful candidate will monitor and review tuning requests, proactively assist with identifying false positives and provide expert recommendations to ensure optimal protection and performance. This will require staying up to date with the latest web security threats and platform enhancements.
͏
Key Responsibilities
- Consult with Capability Lead to deliver Web Application and API Protection for our critical applications, primarily on the Akamai platform.
- Monitor and review all tuning requests.
- Conduct detailed log analysis to identify false positives and optimize WAF rules for improved accuracy and performance.
- Create and maintain comprehensive documentation for WAF tuning, tuning procedures, policies, and configurations.
- Develop, test, and recommend WAF policies and rules tailored to specific applications and environments.
- Proactively assist with identifying false positives
- Collaborate with cross-functional teams to ensure seamless integration of WAF solutions into existing security infrastructure.
- Collaborate with Application teams to enable web application protection.
- Deliver anti-bypass protection for on-premise application currently using Akamai.
- Provide recommendations for WAF configuration based on best practices and security requirements.
- Perform regular assessments and audits of WAF configurations to ensure optimal security posture and compliance with industry standards.
- Maintain evidence for audit and regulatory asks
- Deliver monthly / quarterly business reviews for application owners to show the effectiveness of the WAF control.
- Stay updated with the latest web security threats, vulnerabilities, and trends to continually enhance WAF effectiveness.
- Evaluate, design, and deliver new and alternative WAAP features and/or solutions.
Ideal Candidate Profile
- Extensive experience in WAF management, tuning, and engineering, with a strong understanding of web application security principles.
- Proven track record of proactively identifying and mitigating false positives to optimize WAF performance.
- Background in SOC or CSIRT environments, demonstrating hands-on experience in in-depth log analysis.
- Proficiency in log analysis tools and techniques, with the ability to identify patterns and anomalies in web traffic
Experience: 5-8 Years .
Reinvent your world. We are building a modern Wipro. We are an end-to-end digital transformation partner with the boldest ambitions. To realize them, we need people inspired by reinvention. Of yourself, your career, and your skills. We want to see the constant evolution of our business and our industry. It has always been in our DNA - as the world around us changes, so do we. Join a business powered by purpose and a place that empowers you to design your own reinvention. Come to Wipro. Realize your ambitions. Applications from people with disabilities are explicitly welcome.