Job Summary The Web Application & DDoS Security Administrator will administer, maintain, and optimize web application security and DDoS protection solutions supporting public-facing applications, APIs, and web platforms. The role requires deep hands-on expertise with Imperva Cloud WAF (CWAF), WAF policy management, DDoS mitigation, and web application and API security, while balancing security, performance, and business requirements in a fast-paced environment. Key Responsibilities
- Administer and maintain Imperva Cloud WAF (CWAF) and DDoS protection platforms.
- Manage advanced security controls, including Bot Management, API Security, Client-Side Protection, and Account Takeover (ATO) Prevention.
- Implement, monitor, and tune WAF policies, rules, and security signatures.
- Execute security-related changes, service requests, and incident response activities.
- Partner with application, infrastructure, and security teams to design and implement web security controls.
- Evaluate applications, APIs, networks, and hosting environments and recommend security improvements.
- Troubleshoot complex application security, network security, and web performance issues.
- Support ongoing security reviews, vulnerability remediation, and compliance initiatives. Required Qualifications
- Hands-on experience with Imperva Cloud WAF (CWAF) and DDoS mitigation technologies.
- Strong knowledge of web application security and API security.
- Strong understanding of HTTP/S, DNS, TCP/IP, and networking concepts.
- Knowledge of web hosting and application architectures.
- Experience analyzing and tuning WAF rules and security policies.
- Strong troubleshooting and problem-solving skills across application and network security domains.
- Ability to communicate effectively with both technical and non-technical stakeholders. Preferred Qualifications
- Experience with AWS, Azure, or Google Cloud.
- Knowledge of DevSecOps and modern web application architectures.
- Experience balancing security, performance, and business requirements in a fast-paced environment. Certifications
- CISSP, Security+, CEH, GIAC, or equivalent security certification.