WAF Engineer

TATA Consultancy Services Ltd

Chennai, Tamil Nadu, India

Type: Full-Time Arrangement: On-Site
5 - 8 Yrs800000 - 1400000(Annually)

Posted: 2 Sept 2026

Job Description

Monitor and analyze Cloudflare and Akamai WAF alerts, logs, and dashboards for advanced threat detection. Perform initial triage to classify alerts into true positives and false positives. Conduct deep-dive analysis of web application attacks including SQL Injection, XSS, RCE, bot attacks, and API abuse. Analyze WAF logs to identify potential threats and validate rule triggers against known attack patterns. Manage firewall HA configuration and troubleshooting. Escalate confirmed or high-risk incidents to L2/L3 teams with supporting evidence. Support WAF rule tuning by identifying false positives/negatives and execute predefined playbooks for common web attacks. Ensure WAF platform health, uptime, and alerting mechanisms are functioning. Support onboarding of new applications into WAF and ensure proper protection policies are applied. Maintain incident documentation, ticket updates, and reporting records. Coordinate with AppSec, SOC, and network teams for incident resolution and tuning. Gain exposure to DDoS protection mechanisms and rate-limiting strategies.

Required Qualifications

  • 5+ years of experience in Web Application Firewall management
  • Expertise in Cloudflare and Akamai WAF platforms
  • Proficiency in log analysis and threat detection
  • Strong understanding of OWASP Top 10 vulnerabilities
  • Experience with firewall high availability configuration
  • Knowledge of incident triage and escalation procedures

Preferred Qualifications

  • Experience with WAF rule tuning and policy optimization
  • Familiarity with DDoS protection mechanisms and rate-limiting strategies
  • Hands-on experience executing security playbooks
  • Collaboration experience with AppSec and SOC teams
  • Ability to manage multi-vendor WAF environments

Skills Required

CloudflareAkamaiWAF AdministrationWeb Application SecurityThreat DetectionLog AnalysisVulnerability AssessmentFirewall HADDoS MitigationRate LimitingIncident ResponseSQL Injection PreventionXSS MitigationBot ManagementAPI SecuritySOC CoordinationNetwork SecurityPolicy TuningPlaybook ExecutionDashboard Monitoring