





Niche WAF specialization reduces applicant pool despite Hyderabad metro location.
Specialized WAF and security platform expertise limits cross-domain transferability across non-security roles.
Mandatory 7+ years plus specific WAF platforms, SIEM, IaC and scripting requirements make screening stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Design, implement, and manage WAF policies for web applications and APIs including rule tuning and deployment automation.
Respond in real-time to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents.
Collaborate with DevOps, SRE, and application teams to optimize security posture while minimizing false positives and maintaining application performance.
7+ years of experience in WAF engineering and implementation.
Hands-on experience with at least one WAF platform: Imperva (preferred), Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, or F5 ASM/Advanced WAF.
Proficiency in scripting/automation using PowerShell, Python, or Bash and familiarity with CI/CD and Infrastructure-as-Code tools such as Terraform.
Strong understanding of HTTP/HTTPS, web application architecture, REST APIs, and common web attack vectors.
Experienced in balancing WAF rule tuning for effective threat mitigation and false positive reduction through traffic baselining and staged enforcement.
Skilled in integrating WAF logs with SIEM platforms like Splunk or Sentinel and creating monitoring dashboards for threat detection.
Comfortable automating WAF policy deployment and configuration using APIs and Infrastructure-as-Code in a cloud environment.