WAF Security Engineer

1 month ago


Bangalore, Karnataka, India Shining Sheroes Full time

Programme Summary :

HSBC has a large volume of globally distributed internet web applications, and a larger volume of internal web applications, hosted across many countries and time zones. These web applications are hosted both in HSBC operated Datacentre and Cloud Service Provider environments.

The HSBC Web Application Firewall strategy is aiming to unify and deploy coherent, consistent, and uniform protection across the Bank for both internet and internal web applications, and in conjunction with other strategies.

Additionally, it is paramount to not only ensure that the technology is in-place and performing properly, but also that the people and processes are appropriate to ensure that HSBC is protected.

The role :

This role will play a critical role in enhancing our Web Application Firewall (WAF) across multiple solutions and applications and will be pivotal in crafting, testing, and implementing advanced WAF solutions.

This role involves a strong focus on developing robust security measures against web-based attacks, contributing significantly to the security posture of our organization and achieving audits.

Key Responsibilities :

- Develop and refine complex custom WAF rules and features, ensuring mitigation of Minimum Viable Product (MVP) and security posture gaps.

- Coding expertise to create effective testing mechanisms for baseline and custom WAF rules, integrating these tests seamlessly into automation pipelines.

- Offer subject matter expert (SME) support in various security testing areas, including WAF Proofs of Concept (PoCs)

- Provide specialized WAF-focused advice on web and API attack methodologies, evasions, and mitigation techniques, leveraging your ethical hacking background.

- Contribute to DevSecOps / DevOps with security testing expertise to enhance the automation aspects of the project.

Key Accountabilities :

- Utilize ethical hacking skills to safeguard the organization from web-based attacks, ensuring the protection of operations, reputation, and customer trust.

- Conduct in-depth technical evaluations of WAF solution rulesets, focusing on detection and prevention of web and API security threats.

- Develop custom WAF rules and features, addressing gaps and enhancing overall security measures.

- Identify and counter technical strategies that bypass WAF solutions.

- Design and implement testing protocols to evaluate the effectiveness of various security initiatives, including WAF rules and new features.

- Facilitate the integration of testing procedures into CI/CD pipelines

- Reverse-engineer attacker tactics to create effective mitigation rules.

- Maintain and secure essential documentation and reports, ensuring traceability and compliance.

- Inform the EPS Management team about emerging threats and vulnerabilities, recommending countermeasures.

- Communicate effectively with a range of stakeholders, providing updates on security-related matters

Ideal Candidate Profile :

- Strong background in ethical hacking

- Extensive experience with web-based attack methodologies, including knowledge of tools, payloads, exploits, and countermeasures.

- Proficient in web application and API security.

- Skilled in identifying and mitigating WAF/IPS/CSPM security vulnerabilities.

- Expertise in developing custom WAF rules and security testing packages.

- Solid understanding of OWASP top 10 vulnerabilities.

- Proficiency in at least one programming language

- Ability to automate security testing within CI/CD pipelines.

- Knowledgeable in networking, cloud firewalls, and web technologies.

- Strong grasp of DevSecOps principles and practices.

- Awareness of Agile methodologies

(ref:hirist.tech)

  • Bangalore, Karnataka, India THOUGHTSPOT INDIA PRIVATE LIMITED Full time

    Responsibilities: Define and execute the security posture for ThoughtSpot services running across multiple cloud and hybrid environments.Provide technical leadership, mentor team members, and lead initiatives across the R/D org across geographies.Experiment and drive technology decisions across multi-cloud environments - AWS, GCP, and private cloud.Architect...

  • Security Engineer

    1 month ago


    Bangalore, Karnataka, India Whizz HR Full time

    Overview :We are seeking a talented Security Engineer with 4 to 8 years of experience. The ideal candidate will have a strong technical background in cybersecurity and hands-on experience in implementing security solutions.As a Security Engineer, you will play a critical role in safeguarding our systems and data against potential threats and :Security...


  • Bangalore, Karnataka, India IT Full time

    Job Description : We are seeking a skilled Saviynt Implementer to join our team. The Saviynt Implementer will be responsible for configuring, customizing, and deploying the Saviynt platform to meet our clients' identity governance, access management, and cloud security needs. The ideal candidate will have a strong technical background, hands-on...


  • Bangalore, Karnataka, India IISC Full time

    We are looking for candidates with core Java expertise who will be part of development, testing teams with an objective of delivering a rugged cloud platform to be deployed across multiple cities in India.Responsibilities :- Developing secure, scalable, high-performance, distributed software systems- Developing and testing source code for new...


  • Bangalore, Karnataka, India Infiniti Research Full time

    About Quantzig : . Quantzig is a global analytics and advisory firm with offices in the US, UK, Canada, China, and India. we have assisted our clients across the globe with end-to-end advanced analytics, visual storyboarding, Machine Learning, and data engineering solutions implementation for prudent decision making. We are a rapidly growing organization...

  • Staff Engineer

    1 month ago


    Bangalore, Karnataka, India Sequoia Full time

    Responsibilities :Design and implementation of low-latency, high-availability, and high-performance applications.Create software architecture models to guide development teams.Set and enforce coding standards to ensure quality and maintainability of code.Review design proposals and provide constructive feedback to ensure alignment with architectural...

  • CI/CD Engineer

    3 weeks ago


    Bangalore, Karnataka, India ProPMO Services Private Limited Full time

    Role : CI/CD EngineerExperience : 7+ years Relevant: 6 years must Location : Bangalore - Work From Office mandatoryEmployment type: Permanent role Automotive Engineering Service CompanyJob Description :- Strong 7+ years of IT experience in DevOps CI/CD - Review and modify CI/CD principles - Maintain CI/CD tools/platforms - Develop and maintain pipeline...

  • Senior Data Engineer

    3 weeks ago


    Bangalore, Karnataka, India GLAXOSMITHKLINE ASIA PVT. LTD Full time

    A new world-leading consumer health company. Shaped by all who join us. Together, we're improving everyday health for billions of people. By growing and innovating our global portfolio of category-leading brands including Sensodyne, Panadol, Advil, Voltaren, Theraflu, Otrivin, and Centrum through a unique combination of deep human understanding and...

  • Engineering Manager

    2 weeks ago


    Bangalore, Karnataka, India VAYUZ Technologies Full time

    JOB DESCRIPTION :WHAT YOU'LL BE DOING :- Lead and coach a group of engineers in delivering scalable, flexible and secure features to our customers - Leading engineering teams composed of backend, frontend, developers and QA.- Deep dive into work of your team, review the code submitted by your team, and resolve the root cause of problems.- Coach your team...


  • Bangalore, Karnataka, India Whizz HR Full time

    We are seeking a dynamic Lead ML Engineer to join our team in a remote capacity, operating within the UK shift timings of 2pm to 11pm IST.As the Lead ML Engineer, you will be responsible for leading the development and implementation of machine learning solutions to address complex business :Lead a team of data scientists and machine learning engineers in...


  • Bangalore, Karnataka, India Transformhub Full time

    Required Experience & Skills :- 5+ years of previous experience as DevOps/ DevSecOps- Proficient knowledge working with AWS, Azure security- Hands-on experience with ECS, EKS, API gateway, RDS, S3, CloudWatch, CloudFormation, IAC, Code Pipeline, Code Build, Bitbucket- Proficient Unix, PowerShell knowledge- Degree in Computer Science, IT or other equivalent...


  • Bangalore, Karnataka, India Pluralsight Full time

    Job Description : Working at Pluralsight Founded in 2004 and trusted by Fortune 500 companies, Pluralsight is the technology skills platform organizations and individuals in 150+ countries count on to create progress for the world. Our platform helps technologists master their craft and take control of their careers. We empower businesses everywhere to build...

  • Saviynt Architect

    1 month ago


    Bangalore, Karnataka, India IT Full time

    Job Description: We are seeking a talented and experienced Saviynt Architect to join our dynamic team. The ideal candidate will have a deep understanding of identity governance and cloud security principles, along with extensive hands-on experience in implementing and architecting solutions using the Saviynt platform. As a Saviynt Architect, you will play a...


  • Bangalore, Karnataka, India Codersbrain technology pvt ltd Full time

    GCP Architect. Exp : 9 to 13 yrs. Loc : Hyderabad/Bangalore/Chennai.NP : Immediate.Job Description :Cloud Architect (GCP Infrastructure) Position Overview : We are seeking a highly skilled Google Cloud Platform (GCP) Specialist with hands-on experience in GCP services related to infrastructure and strong architectural skills. The ideal candidate will play a...

  • Principal Engineer

    1 month ago


    Bangalore, Karnataka, India XANDER CONSULTING AND ADVISORY PRIVATE LIMITED Full time

    What Success Will Look Like :- Design, build and maintain the stream processing, time-series analysis system which is at the heart of Data Platform's products- Responsible for architecture of the platform- Build features, enhancements, new services and bug fixing in Scala and Rust on a Jenkins based pipeline to be deployed as Docker containers on...


  • Bangalore, Karnataka, India MangoApps Full time

    Job Description :MangoApps is looking for a Senior QA - Mobile for our Enterprise SaaS platform/product. Working as part of the Engineering team, and with a goal to provide a world-class customer experience consistently, you will take up the complete end-to-end ownership of the native mobile apps (both iOS and Android).- You will collaborate with Product...


  • Bangalore, Karnataka, India Varite India Full time

    Job Description :- Provides direct technical support in planning designing and implementing the solution.- Minimum 6 years of experience in designing, configuring, and implementing enterprise-class network solutions.- Hands on working experience on Client switches Catalyst 9k , 3k Nexus-3K & 5k,7k,9k Client RoutersISR 3900, 4300, ASR 1000.- Hands on working...

  • Saviynt Implementer

    1 month ago


    Bangalore, Karnataka, India IT Full time

    Job Description :We are seeking a skilled Saviynt Implementer to join our team. The Saviynt Implementer will be responsible for configuring, customizing, and deploying the Saviynt platform to meet our clients' identity governance, access management, and cloud security needs. The ideal candidate will have a strong technical background, hands-on experience...

  • Senior NLP Engineer

    2 weeks ago


    Bangalore, Karnataka, India WIZSTAFFING PRIVATE LIMITED Full time

    Job Description :We at Captain Fresh, are building smart supply chain to deliver the highest quality seafood and meat for the Indian consumer. Our innovations in process management and workforce orchestration along with strong industry credentials are enabling us to deliver the fastest harvest-to-fork in the industry.Our endeavor is to leverage experience...

  • Target Corporation

    3 weeks ago


    Bangalore, Karnataka, India Target Full time

    About us : . Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture. Learn more about Target here :As a lead engineer, you serve as the technical anchor for the engineering team that supports a product.- You create, own and are responsible for the application architecture...