Ernst & Young LLP ( EY India )

GMS-Senior-Web Application Firewall

Ernst & Young LLP ( EY India )
Bengaluru/Bangalore
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 3 yearsMin. 3 years

Job Description

GMS-Senior-Web Application Firewall

At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better, too. Join us and build an exceptional experience for yourself, and a better working world for all.

Job Description: Senior Web Application Firewall (WAF) Engineer

Experience Level: 3–5 Years

Role Type: Full-Time

Role Overview

We are seeking a Senior Web Application Firewall (WAF) Engineer to own and drive the end-to-end lifecycle of our application security gateway infrastructure. Spanning the complete service delivery model—Assess, Build, Transition, and Operations—this role requires deep technical proficiency in protecting modern web applications, APIs, and microservices against sophisticated Layer 7 attacks (including OWASP Top 10, botnets, and DDoS). The ideal candidate will have hands-on experience tuning advanced WAF rule sets, managing positive and negative security models, and collaborating closely with application development and DevOps teams.

Key Responsibilities

Assess (Architecture Review & Threat Modeling)

  • Conduct thorough security assessments of existing web applications, API endpoints, and ingress traffic architectures.
  • Analyze current WAF policies, anomaly scores, and signature rulesets to identify coverage gaps against the OWASP Top 10 and API Security Top 10.
  • Collaborate with development and architecture teams to threat-model upcoming applications and define WAF integration requirements.
  • Audit SSL/TLS termination configurations, cipher suites, and certificate lifecycles at the edge.

Build (Deployment & Policy Engineering)

  • Deploy, configure, and manage enterprise WAF solutions (e.g., Cloudflare Enterprise, Akamai Kona, Imperva, F5 Advanced WAF/BIG-IP ASM, or AWS WAF).
  • Design and implement both negative security models (signatures, regex blocks) and positive security models (strict schema validation, OpenAPI/Swagger enforcement).
  • Configure advanced bot mitigation, rate limiting, geo-fencing, and API security inspection layers.
  • Integrate WAF infrastructure with CI/CD pipelines (Infrastructure as Code) for automated policy deployment and version control.

Transition (Testing, Cutover & Handover)

  • Transition WAF policies from monitoring/audit mode to blocking mode safely, minimizing false positives and disruption to legitimate user traffic.
  • Coordinate User Acceptance Testing (UAT) and application functional sign-offs prior to production traffic routing.
  • Produce comprehensive "As-Built" documentation, tuning guidelines, escalation playbooks, and topology diagrams.
  • Conduct training and knowledge transfer sessions for operations and application support teams.

Operations & Continuous Management

  • Serve as the senior technical escalation point for complex Layer 7 security incidents, DDoS attacks, and web traffic anomalies.
  • Perform continuous rule tuning, signature optimization, and exception handling based on application updates and vulnerability scan results.
  • Monitor WAF performance, backend latency, error rates, and evasion technique indicators.
  • Ensure seamless log ingestion and telemetry forwarding to the SIEM/SOAR platforms for deep forensic investigation and continuous compliance reporting.
  • Understanding of ITIL-based Change Management, managing end-to-end change lifecycle activities, CAB coordination, and compliant implementation of infrastructure and application changes

Required Skills & Qualifications

  • Experience: 3–5 years of specialized experience in web application security, WAF administration, or application delivery controller (ADC) management.
  • Core Technologies: Deep, hands-on expertise with leading cloud or on-premise WAF platforms (e.g., Cloudflare, Akamai, Imperva, F5 Advanced WAF, or AWS/Azure WAF).
  • Security Principles: Comprehensive understanding of the OWASP Top 10, API Top 10, SQL injection, Cross-Site Scripting (XSS), Remote Code Execution (RCE), and XML/JSON attacks.
  • Networking & Protocols : Solid grasp of HTTP/HTTPS protocols, RESTful APIs, JSON/XML payloads, DNS, SSL/TLS handshakes, and reverse proxy architectures.
  • Automation & Scripting: Familiarity with automation tools, Python or Bash scripting, and Infrastructure as Code (Terraform/CloudFormation) for policy management.
  • Certifications: Industry certifications (e.g., Certified AppSec Practitioner (CAP), CISSP, CCSP, or vendor-specific WAF/Cloud security credentials) are highly preferred.
  • Soft Skills: Excellent stakeholder management skills, ability to bridge security requirements with developer workflows, and strong analytical problem-solving abilities.

EY | Building a better working world



EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.



Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.



Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.

Job role

Work location
Work locationBengaluru, KA, IN, 560048
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 3 years

About company

Name
NameErnst & Young LLP ( EY India )
Job posted by Ernst & Young LLP ( EY India )

Similar jobs you can apply for

Manufacturing / Production
Awign

Installation Engineer

Awign
Bengaluru/Bangalore
₹22,000 - ₹28,000*
Field Job
Full Time
Any experience
No English Required
Study2Win Private Limited

Technical Operations Associate (Part-Time)

Study2Win Private Limited
Haralur, Bengaluru/Bangalore
₹10,000 - ₹12,000*
Work from Office
Part Time
Any experience
Good (Intermediate / Advanced) English
Jaya Surya Computers

Laptop Hardware Technician

Jaya Surya Computers
BTM Layout, Bengaluru/Bangalore
₹15,000 - ₹20,000
Field Job
Full Time
Freshers only
Basic English

Field Installation Engineer

Airtel
Marathahalli, Bengaluru/Bangalore
₹28,000 - ₹53,000*
Field Job
Full Time
Any experience
Basic English
Unaxo Solutions

Laptop Repair Technician

Unaxo Solutions
HSR Layout, Bengaluru/Bangalore
₹10,000 - ₹20,000*
Work from Office
Full Time
Min. 6 months
Basic English
Reliance Jio

Enterrpise Sales Officer

Reliance Jio
Marathahalli, Bengaluru/Bangalore
₹40,000 - ₹43,000
Field Job
Full Time
Min. 2 years
Good (Intermediate / Advanced) English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 3 to 5 years are eligible to apply for this job. You can apply for more jobs in Bengaluru/Bangalore to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Bengaluru/Bangalore at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Bengaluru/Bangalore . Through apna, you can find jobs in 64 cities across India. Join NOW!