Zelis

Senior Web Application Firewall (WAF) Engineer

Zelis
Hyderabad
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 5 yearsMin. 5 years

Job Description

Senior Engineer WAF

About Us 

Zelis is modernizing the healthcare financial experience in the United States (U.S.) across payers, providers, and healthcare consumers. We serve more than 750 payers, including the top five national health plans, regional health plans, TPAs and millions of healthcare providers and consumers across our platform of solutions. Zelis sees across the system to identify, optimize, and solve problems holistically with technology built by healthcare experts – driving real, measurable results for clients.

Why We Do What We Do 

In the U.S., consumers, payers, and providers face significant challenges throughout the healthcare financial journey. Zelis helps streamline the process by offering solutions that improve transparency, efficiency, and communication among all parties involved. By addressing the obstacles that patients face in accessing care, navigating the intricacies of insurance claims, and the logistical challenges healthcare providers encounter with processing payments, Zelis aims to create a more seamless and effective healthcare financial system.

Zelis India plays a crucial role in this mission by supporting various initiatives that enhance the healthcare financial experience. The local team contributes to the development and implementation of innovative solutions, ensuring that technology and processes are optimized for efficiency and effectiveness. Beyond operational expertise, Zelis India cultivates a collaborative work culture, leadership development, and global exposure, creating a dynamic environment for professional growth. With hybrid work flexibility, comprehensive healthcare benefits, financial wellness programs, and cultural celebrations, we foster a holistic workplace experience. Additionally, the team plays a vital role in maintaining high standards of service delivery and contributes to Zelis’ award-winning culture. 

Position Overview

We are seeking a Senior WAF Engineer with 5–7+ years of experience in securing web applications and APIs using Web Application Firewalls (WAF) and edge security controls. The ideal candidate will have at least 3+ years of hands-on experience with Imperva (preferred) or Cloudflare.
In this role, you will be responsible for the design, implementation, and optimization of WAF policies, including rule tuning, deployment automation, and real-time response to security threats such as OWASP Top 10 vulnerabilities, bot attacks, and Layer 7 DDoS incidents.
You will collaborate closely with DevOps, SRE, and application development teams to enhance security posture while ensuring minimal false positives and maintaining optimal application performance.

Key Responsibilities

  • Design, implement, and manage WAF policies for web applications and APIs across environments (dev/stage/prod).

  • Configure and tune managed rules and custom rules to mitigate OWASP Top 10 (SQLi, XSS, CSRF, RCE, LFI/RFI, SSRF, etc.).

  • Perform rule tuning and false-positive reduction using traffic baselining, exception handling, and staged enforcement (monitor → challenge → block).

  • Implement rate limiting, IP reputation, geo/ASN controls, and bot mitigation strategies to reduce abuse and credential stuffing.

  • Integrate WAF logs with SIEM/log platforms (Splunk, Sentinel, ELK, QRadar) and build dashboards/alerts for threat monitoring.

  • Support incident response for active attacks (L7 DDoS, exploit attempts), including rapid mitigation and post-incident improvements.

  • Automate deployments using IaC (Terraform/CloudFormation/ARM/Bicep) and integrate with CI/CD pipelines.

  • Conduct periodic security reviews, reporting, and metrics tracking (blocked events, top attacks, FP rate, MTTR).

  • Collaborate with app teams on secure configuration (headers, TLS, authentication flows) and compatibility testing.

  • Demonstrated experience in automation using PowerShell or Python to integrate with Imperva APIs for scalable WAF policy deployment, configuration management, and operational efficiency.

Required Qualifications

  • 7+ years experience in WAF engineering and Implementation.

  • Hands-on experience with at least one WAF platform:  Imperva(preferred), Akamai, ModSecurity, AWS WAF, Azure WAF, Cloudflare, F5 ASM/Advanced WAF,

  • Strong understanding of HTTP/HTTPS, web app architecture, REST APIs, and common attack patterns.

  • Proven experience tuning WAF rules and balancing security vs. false positives.

  • Experience with logging/monitoring and SIEM integrations.

  • Scripting/automation skills: Powershell/Python/Bash (plus regex and JSON/YAML).

  • Familiarity with CI/CD and Infrastructure-as-Code principles.

  • Good troubleshooting and stakeholder communication skills.

Preferred Qualifications

  • Experience with bot management and advanced detection techniques (behavioral, fingerprinting where supported).

  • Experience with API gateways and API security controls (schema validation, auth hardening).

  • Working knowledge of cloud networking/CDN/reverse proxy concepts.

  • Security certifications: AWS Security Specialty, Azure Security Engineer, CCSP, CEH, Security+ (nice to have).

Tools & Technologies

WAF (AWS/Azure/Cloudflare/F5/Imperva), CDN, TLS, SIEM (Splunk/Sentinel), Terraform, CI/CD (Jenkins/GitHub Actions/Azure DevOps), Python, Linux, Git.

Commitment to Diversity, Equity, Inclusion, and Belonging

At Zelis, we champion diversity, equity, inclusion, and belonging in all aspects of our operations. We embrace the power of diversity and create an environment where people can bring their authentic and best selves to work. We know that a sense of belonging is key not only to your success at Zelis, but also to your ability to bring your best each day.

Equal Employment Opportunity

Zelis is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Accessibility Support

We are dedicated to ensuring our application process is accessible to all candidates. If you are a qualified individual with a disability and require reasonable accommodation with any part of the application and/or interview process, please email talentacquisition@zelis.com.

Experience Level

Senior Level

Job role

Work location
Work locationIndia Hyderabad (Galaxy)
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 5 years

About company

Name
NameZelis
Job posted by Zelis

Similar jobs you can apply for

Accounts / Finance
Quess Corp Limited

Field Installation Engineer

Quess Corp Limited
Kondapur, Hyderabad
₹21,000 - ₹27,000
Field Job
Full Time
Any experience
No English Required

Computer Technician

Superman Computers
Manikonda, Hyderabad
₹15,000 - ₹20,000
Work from Office
Full Time
Any experience
Basic English
V5 Global

Installation Engineer

V5 Global
Gachibowli, Hyderabad
₹17,000 - ₹23,000*
Field Job
Full Time
Any experience
No English Required

Fiber Field Engineer

Fixcell Enterprises
Madhapur, Hyderabad
₹20,000 - ₹25,000
Field Job
Full Time
Any experience
No English Required
Prism Bpo Private Limited

System Network Administrator

Prism Bpo Private Limited
Banjara Hills, Hyderabad
₹20,000 - ₹30,000
Work from Office
Full Time
Min. 2 years
Basic English
Quess Corp Limited

Field Installation Engineer

Quess Corp Limited
Yousufguda, Hyderabad
₹21,000 - ₹27,000
Field Job
Full Time
Any experience
No English Required

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 5 to 31 years are eligible to apply for this job. You can apply for more jobs in Hyderabad to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Hyderabad at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Hyderabad . Through apna, you can find jobs in 64 cities across India. Join NOW!