Full Time

GMS-Senior-Web Application Firewall

EYKA, INNot Disclosed
Apply Now
GMS-Senior-Web Application Firewall
Apply Now
Job Description
Location: Bengaluru Other locations: Primary Location Only Salary: Competitive Date: Oct 1, 2026 **Job description** ------------------- Requisition ID: 1744117 At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all. **Job Description: Senior Web Application Firewall (WAF) Engineer** **Experience Level: 3–5 Years** **Role Type: Full\-Time** **Role Overview** We are seeking a Senior Web Application Firewall (WAF) Engineer to own and drive the end\-to\-end lifecycle of our application security gateway infrastructure. Spanning the complete service delivery model—Assess, Build, Transition, and Operations—this role requires deep technical proficiency in protecting modern web applications, APIs, and microservices against sophisticated Layer 7 attacks (including OWASP Top 10, botnets, and DDoS). The ideal candidate will have hands\-on experience tuning advanced WAF rule sets, managing positive and negative security models, and collaborating closely with application development and DevOps teams. **Key Responsibilities** **Assess (Architecture Review \& Threat Modeling)** * Conduct thorough security assessments of existing web applications, API endpoints, and ingress traffic architectures. * Analyze current WAF policies, anomaly scores, and signature rulesets to identify coverage gaps against the OWASP Top 10 and API Security Top 10\. * Collaborate with development and architecture teams to threat\-model upcoming applications and define WAF integration requirements. * Audit SSL/TLS termination configurations, cipher suites, and certificate lifecycles at the edge. **Build (Deployment \& Policy Engineering)** * Deploy, configure, and manage enterprise WAF solutions (e.g., Cloudflare Enterprise, Akamai Kona, Imperva, F5 Advanced WAF/BIG\-IP ASM, or AWS WAF). * Design and implement both negative security models (signatures, regex blocks) and positive security models (strict schema validation, OpenAPI/Swagger enforcement). * Configure advanced bot mitigation, rate limiting, geo\-fencing, and API security inspection layers. * Integrate WAF infrastructure with CI/CD pipelines (Infrastructure as Code) for automated policy deployment and version control. **Transition (Testing, Cutover \& Handover)** * Transition WAF policies from monitoring/audit mode to blocking mode safely, minimizing false positives and disruption to legitimate user traffic. * Coordinate User Acceptance Testing (UAT) and application functional sign\-offs prior to production traffic routing. * Produce comprehensive "As\-Built" documentation, tuning guidelines, escalation playbooks, and topology diagrams. * Conduct training and knowledge transfer sessions for operations and application support teams. **Operations \& Continuous Management** * Serve as the senior technical escalation point for complex Layer 7 security incidents, DDoS attacks, and web traffic anomalies. * Perform continuous rule tuning, signature optimization, and exception handling based on application updates and vulnerability scan results. * Monitor WAF performance, backend latency, error rates, and evasion technique indicators. * Ensure seamless log ingestion and telemetry forwarding to the SIEM/SOAR platforms for deep forensic investigation and continuous compliance reporting. * Understanding of ITIL\-based Change Management, managing end\-to\-end change lifecycle activities, CAB coordination, and compliant implementation of infrastructure and application changes **Required Skills \& Qualifications** * **Experience:** 3–5 years of specialized experience in web application security, WAF administration, or application delivery controller (ADC) management. * **Core Technologies:** Deep, hands\-on expertise with leading cloud or on\-premise WAF platforms (e.g., Cloudflare, Akamai, Imperva, F5 Advanced WAF, or AWS/Azure WAF). * **Security Principles:** Comprehensive understanding of the OWASP Top 10, API Top 10, SQL injection, Cross\-Site Scripting (XSS), Remote Code Execution (RCE), and XML/JSON attacks. * **Networking \& Protocols**: Solid grasp of HTTP/HTTPS protocols, RESTful APIs, JSON/XML payloads, DNS, SSL/TLS handshakes, and reverse proxy architectures. * **Automation \& Scripting:** Familiarity with automation tools, Python or Bash scripting, and Infrastructure as Code (Terraform/CloudFormation) for policy management. * **Certifications:** Industry certifications (e.g., Certified AppSec Practitioner (CAP), CISSP, CCSP, or vendor\-specific WAF/Cloud security credentials) are highly preferred. * **Soft Skills:** Excellent stakeholder management skills, ability to bridge security requirements with developer workflows, and strong analytical problem\-solving abilities. **EY \| Building a better working world** EY exists to build a better working world, helping to create long\-term value for clients, people and society and build trust in the capital markets. Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate. Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
0 ApplicationsApply Now

GMS-Senior-Web Application Firewall

KA, IN
EY
London, England
Category:
—
Company Size:
—
Experience:
4+ Yrs
Level:
Senior Level
Openings:
1
Applications:
0
GMS-Senior-Web Application Firewall at EY | Jobiora