Job Summary
The Web Application & DDoS Security Administrator will administer, maintain, and optimize web application security and DDoS protection solutions supporting public-facing applications, APIs, and web platforms. The role requires deep hands-on expertise with Imperva Cloud WAF (CWAF), WAF policy management, DDoS mitigation, and web application and API security, while balancing security, performance, and business requirements in a fast-paced environment.
Key Responsibilities
• Administer and maintain Imperva Cloud WAF (CWAF) and DDoS protection platforms.
• Manage advanced security controls, including Bot Management, API Security, Client-Side Protection, and Account Takeover (ATO) Prevention.
• Implement, monitor, and tune WAF policies, rules, and security signatures.
• Execute security-related changes, service requests, and incident response activities.
• Partner with application, infrastructure, and security teams to design and implement web security controls.
• Evaluate applications, APIs, networks, and hosting environments and recommend security improvements.
• Troubleshoot complex application security, network security, and web performance issues.
• Support ongoing security reviews, vulnerability remediation, and compliance initiatives.
Required Qualifications
• Hands-on experience with Imperva Cloud WAF (CWAF) and DDoS mitigation technologies.
• Strong knowledge of web application security and API security.
• Strong understanding of HTTP/S, DNS, TCP/IP, and networking concepts.
• Knowledge of web hosting and application architectures.
• Experience analyzing and tuning WAF rules and security policies.
• Strong troubleshooting and problem-solving skills across application and network security domains.
• Ability to communicate effectively with both technical and non-technical stakeholders.
Preferred Qualifications
• Experience with AWS, Azure, or Google Cloud.
• Knowledge of DevSecOps and modern web application architectures.
• Experience balancing security, performance, and business requirements in a fast-paced environment.
Certifications
• CISSP, Security+, CEH, GIAC, or equivalent security certification.