





Niche WAF specialization reduces candidate pool despite metro location.
Role requires niche WAF/security experience and platform expertise, limiting cross-industry transferability.
Explicit 7+ years requirement and mandatory WAF platform and automation skills create strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Design, implement, and manage WAF policies for web applications and APIs, including tuning rules to mitigate OWASP Top 10 vulnerabilities and reduce false positives.
Automate WAF deployments and configurations using Infrastructure as Code (Terraform/CloudFormation) and scripting (PowerShell/Python), integrating with CI/CD pipelines.
Respond to real-time security threats such as Layer 7 DDoS and bot attacks, collaborating with DevOps, SRE, and app teams to maintain optimal security and application performance.
7+ years experience in WAF engineering and implementation.
3+ years hands-on experience with Imperva WAF platform preferred (or Cloudflare).
Proficient with WAF rule tuning, SIEM/logging integrations, scripting for automation (PowerShell or Python), and Infrastructure as Code concepts.
Strong understanding of HTTP/HTTPS, web application architecture, REST APIs, and OWASP Top 10 attack mitigation.
Experienced in security operations focusing on application-layer protection, capable of balancing security controls with false positive reduction.
Skilled in automation and integration of security tools within CI/CD and DevOps environments.
Proficient in collaborating cross-functionally with DevOps, SRE, and app development teams to enhance security posture and incident response.