About this role
Job title: WAF Engineer
About the Role
Join Wipro Limited as a WAF Engineer focused on delivering WAF solutions across edge, cloud, and on-prem environments. You will implement and tune WAF controls, manage HTTPS inspection and rate limiting, and work with CI/CD and IaC practices to secure web applications.
What You'll Do
- Design, deploy, and maintain WAF solutions across edge, cloud, and on-prem environments.
- Tune and configure WAF policies, develop custom WAF rules, and prepare security testing packages.
- Manage IDAM protocols and access control for WAF management.
- Implement HTTPS inspection, including termination and certificate management.
- Apply rate limiting techniques to mitigate attacks.
- Troubleshoot connectivity and service management issues.
- Collaborate on CI/CD pipelines using Jenkins, CircleCI, Travis CI, GitLab CI, and Bamboo.
- Develop automation scripts with Python, Bash, and PowerShell.
- Use Infrastructure as Code tools such as Terraform, Ansible, Chef, or Puppet.
- Integrate and manage APIs; work with containerization and orchestration on Cloud platforms.
- Set up and maintain monitoring and logging with Prometheus, Grafana, ELK Stack, or Splunk.
- Apply networking and security fundamentals; address OWASP Top 10 vulnerabilities.
- Develop custom WAF rules and security testing packages; automate security testing within CI/CD pipelines.
- Demonstrate strong verbal and written communication; manage multiple priorities.
What We're Looking For
- Deep knowledge of WAF functionalities and limitations across edge, cloud, and on-prem.
- Experience with WAF tuning and configuration.
- IDAM protocols and access control for WAF management.
- HTTPS inspection and certificate management.
- Proficiency with CI/CD tools: Jenkins, CircleCI, Travis CI, GitLab CI, and Bamboo.
- Scripting skills: Python, Bash, PowerShell.
- Experience with IaC: Terraform, Ansible, Chef, Puppet.
- API integration and management; containerization and orchestration; cloud platforms.
- Monitoring and logging experience: Prometheus, Grafana, ELK Stack, Splunk.
- Networking and security fundamentals; OWASP Top 10 vulnerabilities.
- Experience developing custom WAF rules and security testing packages.
- Experience automating security testing within CI/CD pipelines.
- Excellent verbal and written communication; ability to manage multiple priorities.
- Experience with AWS WAF or other WAF solutions.