Why This Role Stands Out
This hybrid role offers a fantastic opportunity to shape enterprise-grade WAAP and network security architectures, driving a multi-year roadmap for application-layer security. You'll thrive here if you're an experienced security professional eager to architect and implement cutting-edge WAAP solutions, leveraging your expertise in WAF, API security, and bot protection. Apply now to join Centillion Infotech and make a significant impact!
Quick Overview
Job Description
Senior Network Security Engineer WAAP (Web Application & API Protection)
Key Responsibilities
- Translate business and application security requirements into enterprise-grade WAAP and network security architectures.
- Develop and support solutions aligned with HPE's application security and defense-in-depth strategy.
- Lead architecture, design, and deployment of Web Application and API Protection (WAAP) solutions across global environments.
- Develop and drive multi-year roadmap for application-layer security, including WAF, API security, bot protection, and DDoS mitigation.
WAAP Responsibilities (Primary Focus)
- Architect, implement, and manage WAAP platforms, including:
- Web Application Firewall (WAF)
- API Security (discovery, protection, runtime analysis)
- Bot Management
- DDoS Protection (L3 L7)
- Design and deploy WAAP solutions using platforms such as:
- Thales Imperva
- Cloud-native WAFs (Azure, AWS WAF) or equivalent
- Develop and maintain custom WAF rules, security policies, and signatures to protect critical applications.
- Perform false positive tuning, policy optimization, and rule lifecycle management.
- Enable API discovery, schema enforcement, and protection against OWASP API Top 10 threats.
- Integrate WAAP with:
- SIEM/SOAR platforms
- Identity providers
- Threat intelligence feeds
- Collaborate with application teams to:
- Onboard applications into WAAP platforms
- Perform security assessments and risk reviews
- Ensure minimal performance impact while enforcing strong security controls
- Implement protection against OWASP Top 10 vulnerabilities (SQLi, XSS, RCE, etc.).
- Lead WAAP incident response and root cause analysis for application-layer attacks.
- Define and track application security metrics and KPIs (attack trends, mitigation effectiveness).
- Ensure compliance with security frameworks (CIS, NIST, Zero Trust, data protection standards).
Core Network Security Responsibilities
- Architect and maintain secure network infrastructure across data center, campus, and cloud environments.
- Conduct security design reviews ensuring compliance with enterprise security standards.
- Provide risk reporting, control effectiveness, and security posture visibility.
- Support internal and external security audits.
- Manage and optimize Security Information and Event Management (SIEM) systems.
- Develop and maintain network security policies and procedures.
- Collaborate with cybersecurity, infrastructure, and application teams globally.
Technical Qualifications
- 10+ years of experience in network security architecture, engineering, and operations.
WAAP & Application Security Expertise (Mandatory)
- Strong experience with WAAP platforms (Akamai preferred; Cloud WAF or equivalent accepted).
- Deep understanding of:
- OWASP Top 10 (Web & API)
- Application-layer threats and mitigation techniques
- Hands-on experience in:
- WAF policy creation and tuning
- API security controls (schema validation, authentication enforcement)
- Bot mitigation strategies
- DDoS protection architecture (L3 L7)
- Experience in:
- Traffic analysis (HTTP/HTTPS, TLS inspection)
- Behavioral-based threat detection
- Strong understanding of:
- Secure application architectures (monolith, microservices, APIs)
- DevSecOps integration and CI/CD security controls (nice to have)
Network Security & Infrastructure
- Strong hands-on experience in:
- Firewalls (Fortinet, Palo Alto, Juniper)
- IDS/IPS, VPN, SIEM
- Expertise in:
- Firewall policy design, NAT, routing, inspection, and threat prevention
- Experience in designing secure:
- Hybrid (on-prem + cloud + internet-facing) environments
- Experience in:
- Proxy architectures (forward/reverse)
- Secure internet gateways
Networking & Protocol Expertise
- Strong knowledge of:
- TCP/IP, DNS, HTTP/HTTPS, TLS/SSL
- Routing protocols (BGP, OSPF, MPLS)
- Experience with:
- QoS, NetFlow, ACLs, NAT, IP traffic management
- Network monitoring and analysis tools
Cloud & Integration
- Experience securing applications in:
- AWS, Azure, Google Cloud Platform
- Familiarity with:
- Cloud-native WAF and API security tools
- Integration experience with:
- SIEM, EDR/XDR, IAM platforms
Data Center & Enterprise Networking
- Experience managing enterprise environments with:
- Aruba, Arista, Juniper switches
- Firewalls, load balancers, WAN optimization tools
- Understanding of:
- High availability and performance optimization for application traffic
Operations & Lifecycle Management
- Lead onboarding and lifecycle management of applications into WAAP platforms.
- Perform security tuning, upgrades, and optimization activities.
- Support incident response and threat mitigation at application layer.
- Work within ITIL frameworks (incident, problem, change management).
Education & Certifications
- Bachelor's Degree in Computer Science, IT, or related field (or equivalent experience).
- 10+ years of experience in enterprise network security and application security.
- Preferred certifications:
- CCNP / CCIE / JNCIE
- Security certifications (CISSP, CISM)
- Vendor certifications (Akamai, AWS Security, Azure Security)
Key Differentiators (What This JD Targets)
- Positions WAAP as a primary security control layer, not an add-on
- Strong alignment with:
- Application security + Network security convergence
- Defense-in-depth strategy
- Emphasizes:
- API security (modern requirement)
- Bot/DDoS protection (critical for internet-facing apps)
- Keeps strong foundation in:
- Firewalls, SIEM, network architecture
Similar jobs
- II
Sr. Principal Cyber Systems Engineer Level 4 with Security Clearance
NewIndotronix International Corp
San Antonio, TX🇺🇸On-site21 hours agoAgileTechnology - II
Cyber Systems Engineer (CSE) Level 3 with Security Clearance
NewIndotronix International Corp
San Antonio, TX🇺🇸On-site21 hours agoAgileTechnology - RT
GRC Security Risk Specialist
NewRequest Technology, LLC
Austin, TX🇺🇸On-siteYesterdayAdministrative - IS
IAM Security Engineer(Wireless)(NAC/MFA)
NewiCUBE Solutions
United States🇺🇸On-site21 hours agoMFAOAuthSAML+1Technology - MA
CNO Vulnerability Researcher with Security Clearance
MANTECH
Herndon, VA🇺🇸Hybrid6 weeks agoEncryptionScrumAgile+5Technology - AT
Information Systems Security Manager (ISSM) with Security Clearance
Abacus Technology Corporation
Hanscom AFB, MA🇺🇸$178.8k - $200.1k/yrHybrid6 weeks agoTechnology