





Tier-1 employer, mid-level 3–6 years, and metro location increase applicant competition.
Security and WAF expertise transfer across industries but require specific tooling and compliance experience.
Explicit 3–6 years plus mandatory WAF, DAST/SAST, SCA, and pentesting skills create strict filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Onboard and maintain internet-facing applications on WAF ensuring application security with configured policies and ongoing rule tuning to reduce false positives.
Conduct and lead application penetration testing including DAST, SAST, and manual testing using tools like Burp Suite, Webinspect, Fortify, and Sonatype.
Collaborate with development and DevOps teams for deployment and remediation of vulnerabilities and maintain WAF governance, dashboards, reports, and metrics.
Bachelor’s degree in a technical field required.
3-6 years of experience in application security testing.
Strong hands-on experience with WAF technologies such as F5, Akamai, Cloudflare, AWS WAF, Imperva, or Azure WAF including policy creation and rule tuning.
Experience with DAST, SAST, SCA, manual penetration testing, and security tools like Burp Suite, Webinspect, Fortify, and Sonatype.
Experienced in applying WAF security controls aligned to OWASP Top 10 and organizational security standards in enterprise environments.
Hands-on technical lead capable of both technical implementation (rule tuning, penetration testing) and cross-team collaboration for secure application deployment.
Comfortable managing WAF governance processes and delivering measurable security outcomes through testing and policy enforcement.