Job description
Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Web Application Firewall (WAF)
Good to have skills : NA
Minimum 3 year(s) of experience is required
Educational Qualification : 15 years full time education
Summary:
Experienced Web Application Firewall (WAF) Engineer responsible for design, implementation, and management of enterprise-grade WAF solutions using F5 ASM/BIG-IP and Akamai WAF (Kona / App & API Protector). The role requires strong hands-on expertise in policy tuning, threat mitigation, and securing web applications against OWASP and advanced threats.
Roles & Responsibilities:
Design, implement, and manage F5 ASM and Akamai WAF security policies for web applications.
Perform policy tuning, false positive analysis, and rule optimization to ensure effective protection with minimal business impact.
Configure and manage rate limiting, bot protection, and advanced WAF controls.
Monitor, analyze, and respond to WAF logs, alerts, and security events integrate with SIEM (Splunk, QRadar).
Support application onboarding, security baseline definition, and change management.
Review and align F5 and Akamai WAF policies, identify gaps, and drive optimization
Troubleshoot incidents and collaborate with application, DevOps, and security teams.
Maintain documentation, SOPs, and support audit/compliance requirements.
Professional & Technical Skills:
3–6+ years of hands-on experience in WAF technologies.
Strong expertise in:
o F5 ASM / BIG-IP WAF
o Akamai WAF (Kona Site Defender / App & API Protector)
Solid understanding of:
o HTTP/S, SSL/TLS, Load balancing, CDN
o OWASP Top 10 vulnerabilities & web security concepts
Experience in:
o Policy creation, tuning, and signature management
o Log analysis, incident response, and troubleshooting
o SIEM integrations (Splunk/QRadar)
Additional Information:
Exposure to multi-WAF environments (F5 + Akamai) and migration scenarios
Akamai or F5 certifications
Knowledge of scripting (Python/Bash)
Experience with cloud WAF (AWS/Azure/Cloudflare)
This job post has been translated by AI and may contain minor differences or errors.