Match Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Own design, implementation, tuning, and automation of WAF policies protecting web applications and APIs across multiple environments.
Respond operationally to web security incidents including OWASP Top 10 attacks, bot abuse, and Layer 7 DDoS attacks with rapid mitigation and post-incident review.
Collaborate with DevOps/SRE and application teams to balance security effectiveness with minimizing false positives and performance impacts.
Minimum Requirements
5 to 7+ years experience in WAF engineering, application security, or edge security.
3+ years hands-on experience with Imperva WAF preferred; experience with any leading WAF platform (AWS, Azure, Cloudflare, F5 ASM, etc.) required.
Expertise in HTTP/HTTPS, REST APIs, common web attack patterns, WAF rule tuning, false positive reduction, and SIEM integration.
Scripting/automation skills in Powershell, Python, or Bash and knowledge of Infrastructure-as-Code and CI/CD tools.
Ideal Candidate Profile
Experienced security engineer with demonstrated ability to manage WAF lifecycle including policy design, tuning, and incident response in complex environments.
Comfortable working cross-functionally with DevOps, SRE, and application development teams to integrate security controls effectively without operational disruption.
Strong operational mindset focused on measurable impact: reducing attacks, false positives, and mean time to recovery (MTTR) with automation and continuous improvement.
