CSbusinesmgmt.in
Company:
https://www.linkedin.com/company/csbusinesmgmt-in
Seniority: Entry level
Industries: IT Services and IT Consulting
Job details:
Cloud WAF Engineer – GCP | LTIMindtreeJob Details
- Role: Cloud WAF Engineer – GCP
- Location: PAN India
- Experience: 5+ Years
- Openings: 3
- Notice Period: 15 Days
- Company: LTIMindtree
- Mandatory Skills: Cloud Security, GCP WAF, AWS Native Security, Akamai WAF/DDoS, F5 WAF/DDoS
Job Description
We are looking for a Cloud WAF Engineer – GCP to work as part of the Run the Bank (RTB) team on a cybersecurity programme focused on deploying and managing WAF solutions across internet-facing and internal web applications.
The role involves working closely with global business teams, cloud platform teams, cybersecurity, compliance, vendors and other stakeholders to manage WAF policies, custom rules, exceptions, false-positive analysis, baseline policies and service requests.
Key Responsibilities
- Manage and support WAF solutions across cloud, edge and on-premises environments.
- Work extensively with GCP Cloud WAF and preferably multi-vendor WAF platforms such as F5 and Akamai.
- Develop and maintain custom WAF rules and security configurations.
- Perform WAF tuning, policy configuration and false-positive analysis.
- Review and maintain baseline/MVP WAF configurations.
- Analyze web application security attacks and implement appropriate mitigations.
- Handle WAF-related service requests, incidents and change requests.
- Work with SOC teams during WAF-related security incidents.
- Support HTTPS inspection, SSL/TLS termination and certificate management.
- Implement and manage rate-limiting policies.
- Support version control and update mechanisms for WAF solutions.
- Maintain security logging and identify appropriate logging options across cloud environments.
- Provide DevSecOps pipeline maintenance and automation support.
- Identify additional automation opportunities to improve RTB processes.
- Work closely with Cloud Platform Leads, Business Teams, Compliance, Cyber Security, Change Teams and vendors.
- Identify risks early and provide appropriate status reporting and escalation.
- Work within an Agile framework.
Mandatory / Core Skills
- Strong experience with multiple WAF solutions across edge, cloud and on-premises environments.
- Strong cloud security experience, preferably GCP.
- Experience with AWS Native Security.
- Experience with Akamai WAF/DDoS.
- Experience with F5 WAF/DDoS.
- Strong understanding of web application security attacks and mitigation techniques.
- WAF tuning and configuration.
- Custom WAF rule development.
- Web application security principles.
- HTTPS inspection and certificate management.
- Rate limiting.
- Security logging and monitoring.
- WAF incident handling and SOC coordination.
- General network/connectivity troubleshooting.
- DevSecOps and automation pipeline support.
- Version control and configuration management.
Preferred Background
Candidates with a Cyber SOC/CSIRT or Web Application Security background who have strong experience in security log analysis and are willing to work as a WAF Engineering SME would be preferred.
Soft Skills
- Strong stakeholder management
- Excellent written and verbal communication
- Strong analytical and problem-solving skills
- Ability to analyze large datasets
- Attention to detail
- Agile methodology experience
- Self-starter with the ability to work independently
- Strong team collaboration skills
Click on Apply to know more.