×
Register Here to Apply for Jobs or Post Jobs. X

Senior WAF Engineer

Job in 500001, Hyderabad, Telangana, India
Listing for: Seintiv Talent Solutions
Full Time position
Listed on 2026-09-05
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Network Security
Job Description & How to Apply Below
Job Description

Summary:

We are seeking a Senior WAF Engineer with 7+ years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 3+ years of hands-on experience with Imperva (preferred) or Cloudflare. In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents.

You will collaborate closely with Dev Ops, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.

Key Responsibilities:

Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).
Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.).
Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor → challenge → block).
Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.

We Need:
7+ years’ experience in WAF engineering and Implementation.
Hands-on experience with at least one WAF platform:
Imperva(preferred), Akamai, Mod Security, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF,
Strong understanding of HTTP/HTTPS, web app architecture, REST APIs, and common attack patterns.
Proven experience tuning WAF rules and balancing security vs. false positives.

Experience with logging/monitoring and SIEM integrations.
Scripting/automation skills:
Powershell/Python/Bash (plus regex and JSON/YAML).
Familiarity with CI/CD and Infrastructure-as-Code principles.
Good troubleshooting and stakeholder communication skills.

Preferred Qualifications:

Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).

Experience with API gateways and API security controls (schema validation, auth hardening).
Working knowledge of cloud networking/CDN/reverse proxy concepts.
Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).

Tools & Technologies
WAF (AWS/Azure/Cloudflare/F5/Imperva), CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/Git Hub Actions/Azure Dev Ops), Python, Linux, Git.
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary