Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job Description: L3 Security Engineer – F5 WAF (Advanced Web Application Firewall)
Location: Mumbai
Employment Type: Full-Time
Experience Level: 5–7 Years
Department: Information Security / Cybersecurity Operations
Position Summary
We are seeking a detail-oriented and experienced L2 Security Engineer with specialized, hands-on expertise in F5 Web Application Firewall (WAF) / Advanced WAF (ASM) solutions. In this role, you will be responsible for the day-to-day administration, health monitoring, policy tuning, alert handling, and troubleshooting of our enterprise web application security infrastructure. You will work closely with application development, network, and SOC teams to safeguard web applications against advanced threats, mitigate vulnerabilities, and ensure seamless user access.
Key Responsibilities
Infrastructure & Operations
Manage, administer, and maintain enterprise F5 WAF/ASM infrastructure to ensure high availability and robust web application security.
Configure, implement, and maintain WAF security policies, custom signatures, profiles, and attack signatures.
Support the secure onboarding of new web applications into the F5 WAF environment.
Proactively perform policy tuning, rule adjustments, and optimization to minimize false positives without compromising security posture.
Support SSL/TLS certificate installation, binding, and lifecycle management.
Security Operations & Incident Management
Monitor real-time WAF alerts, web traffic patterns, and anomalous security events.
Investigate suspicious web traffic, application-layer attacks, and security incidents.
Support Security Operations Center (SOC) and Incident Response teams during security investigations, log analysis, and event correlation.
Escalate critical application security incidents efficiently to L3 engineering or specialized security teams.
Ensure all WAF configurations and policies strictly align with corporate security standards.
Platform Support & Troubleshooting
Diagnose and resolve complex WAF policy, routing, connectivity, and application access impediments.
Support system installations, software patching, major upgrades, and preventive maintenance routines.
Monitor F5 device health, resource utilization, storage capacity, and operational performance.
Execute configuration backups and disaster recovery restoration procedures as scheduled.
Coordinate cross-functionally with application, server, and network teams to expedite root-cause analysis and issue resolution.
Compliance & Governance
Support compliance requirements and auditing controls related to web application security.
Maintain comprehensive audit logs, traffic records, and periodic WAF monitoring reports.
Support internal and external audits aligned with frameworks such as ISO 27001, PCI-DSS, and internal regulatory controls.
Ensure meticulous documentation and evidence collection to meet stringent audit mandates.
Required Qualifications & Technical Skills
Education: Bachelor’s Degree in Computer Science, Information Security, Information Technology, or a related field.
Experience:
3 to 6 years of total professional experience in cybersecurity, network security, or WAF administration.
Minimum of 2+ years of dedicated, hands-on F5 WAF/ASM support and configuration experience.
Core Technical Competencies:
Proven, practical experience with F5 WAF and F5 Advanced WAF (ASM) solutions.
Deep knowledge of web application security concepts and the OWASP Top 10 vulnerability framework.
Strong expertise in WAF policy management, signature handling, and fine-tuning rules.
Solid understanding of core networking and web protocols, including HTTP/HTTPS, SSL/TLS, DNS, TCP/IP, and load balancing principles.
Demonstrated capability in troubleshooting web application access and security enforcement issues.
Functional proficiency in Windows and Linux operating system environments.
Strong analytical, diagnostic, and communication skills.
Preferred Certifications
F5 Certified Administrator (F5-CA)
F5 Certified Technology Specialist (ASM / WAF specialization)
CompTIA Security+ or CEH (Plus)
Good-to-Haves
Practical experience integrating WAF logs with SIEM platforms such as Splunk, IBM QRadar, or Microsoft Sentinel.
Basic scripting and automation skills using PowerShell, Python, or Bash.
Hands-on exposure to cloud environments (e.g., AWS, Azure, GCP) and cloud-native security tools.
Working knowledge of broader compliance frameworks and regulatory audit requirements.
Skills: f5 waf,application security,web application security,ddos
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.