Note :- WAAP (Web Application & API Protection) experience is must
Client is an innovative, dynamic company with a rich past and a promising future. Client has continuously reinvented itself. Today, Client is one of the world's leading technology companies providing networking, cloud, and security solutions for next-generation IT infrastructure.
Key Responsibilities
· Translate business and application security requirements into enterprise-grade WAAP and network security architectures.
· Develop and support solutions aligned with Client application security and defense-in-depth strategy.
· Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments.
· Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.
WAAP Responsibilities (Primary Focus)
· Architect, implement, and manage WAAP platforms, including:
o Web Application Firewall (WAF)
o API Security (discovery, protection, runtime analysis)
o Bot Management
o DDoS Protection (L3–L7)
· Design and deploy WAAP solutions using platforms such as:
o Thales Imperva
o Cloud-native WAFs (Azure, AWS WAF) or equivalent
· Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.
· Perform false positive tuning, policy optimization, and rule of lifecycle management.
· Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.
· Integrate WAAP with:
o SIEM/SOAR platforms
o Identity providers
o Threat intelligence feeds
· Collaborate with application teams to:
o Onboard applications into WAAP platforms
o Perform security assessments and risk reviews
o Ensure minimal performance impact while enforcing strong security controls
· Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).
· Lead WAAP incident response and root cause analysis for application-layer attacks.
· Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).
· Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).
Core Network Security Responsibilities
· Architect and maintain secure network infrastructure across data center, campus, and cloud environments.
· Conduct security design reviews ensuring compliance with enterprise security standards.
· Provide risk reporting, control effectiveness, and security posture visibility.
· Support internal and external security audits.
· Manage and optimize Security Information and Event Management (SIEM) systems.
· Develop and maintain network security policies and procedures.
· Collaborate with cybersecurity, infrastructure, and application teams globally.
Technical Qualifications
· 10+ years of experience in network security architecture, engineering, and operations.
WAAP & Application Security Expertise (Mandatory)
· Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted).
· Deep understanding of:
o OWASP Top 10 (Web & API)
o Application-layer threats and mitigation techniques
· Hands-on experience in:
o WAF policy creation and tuning
o API security controls (schema validation, authentication enforcement)
o Bot mitigation strategies
o DDoS protection architecture (L3–L7)
· Experience in:
o Traffic analysis (HTTP/HTTPS, TLS inspection)
o Behavioral-based threat detection
· Strong understanding of:
o Secure application architectures (monolith, microservices, APIs)
o DevSecOps integration and CI/CD security controls (nice to have)
Network Security & Infrastructure
· Strong hands-on experience in:
o Firewalls (Fortinet, Palo Alto, Juniper)
o IDS/IPS, VPN, SIEM
· Expertise in:
o Firewall policy design, NAT, routing, inspection, and threat prevention
· Experience in designing secure:
o Hybrid (on-prem + cloud + internet-facing) environments
· Experience in:
o Proxy architectures (forward/reverse)
o Secure internet gateways
Networking & Protocol Expertise
· Strong knowledge of:
o TCP/IP, DNS, HTTP/HTTPS, TLS/SSL
o Routing protocols (BGP, OSPF, MPLS)
· Experience with:
o QoS, NetFlow, ACLs, NAT, IP traffic management
o Network monitoring and analysis tools
Cloud & Integration
· Experience securing applications in:
o AWS, Azure, Google Cloud Platform
· Familiarity with:
o Cloud-native WAF and API security tools
· Integration experience with:
o SIEM, EDR/XDR, IAM platforms
Data Center & Enterprise Networking
· Experience managing enterprise environments with:
o Aruba, Arista, Juniper switches
o Firewalls, load balancers, WAN optimization tools
· Understanding of:
o High availability and performance optimization for application traffic
Operations & Lifecycle Management
· Lead onboarding and lifecycle management of applications into WAAP platforms.
· Perform security tuning, upgrades, and optimization activities.
· Support incident response and threat mitigation at application layer.
· Work within ITIL frameworks (incident, problem, change management).
Education & Certifications
· Bachelor’s Degree in Computer Science, IT, or related field (or equivalent experience).
· 10+ years of experience in enterprise network security and application security.
· Preferred certifications:
o CCNP / CCIE / JNCIE
o Security certifications (CISSP, CISM)
o Vendor certifications (Akamai, AWS Security, Azure Security)
Key Differentiators (What This JD Targets)
· Positions WAAP as a primary security control layer, not an add-on
· Strong alignment with:
o Application security + Network security convergence
o Defense-in-depth strategy
· Emphasizes:
o API security (modern requirement)
o Bot/DDoS protection (critical for internet-facing apps)
· Keeps strong foundation in:
o Firewalls, SIEM, network architecture