Qualifications
B.E./B.Tech or Masters degree in Computer Science or related field from a recognized/accredited university
Minimum of 3-6 years of combined experience in the Information Security / Cybersecurity domain
Hands on experience working with few of the following data protection technologies:
Data Loss Prevention (DLP) technology
Data Access Governance technology
Data Discovery, Retention and Destruction technologies
Data Classification and Rights Management technology
Cloud Access Security Broker (CASB) technology
Web Security and SSL Decryption technology
Web Application Firewall (WAF) technology
SSL Certificate and Encryption Key Lifecycle Management technology
Secure Browser/Browser Isolation solutions like Prisma Access Browser (PAB)
Experience with troubleshooting issues and assisting end users to mitigate issues
Familiarity with change management and deployment processes in large IT organizations
Working knowledge with common IT technologies such as Windows Server, Linux/Unix, Databases, Active Directory/LDAP, virtualization, end-user devices etc.
Working knowledge of IT / security principles such as encryption, identity, cloud, etc.
Experience with PowerShell command-line scripting is a plus
Professional security certification desirable, such as Security+ or CISSP
Skills/abilities:
Setting up and updating the WAF rules and policies, based on the web application's functionality, requirements, and threat landscape.
Monitoring and analyzing the WAF logs and reports, to identify and respond to any potential or actual attacks, anomalies, or errors.
Testing and optimizing the WAF performance, to ensure that it does not affect the web application's availability, speed, or user experience.
Keeping abreast of the latest web application security trends, standards, and regulations, and applying them to the WAF configuration as needed.
Understanding of networking and core networking protocols (e.g. TCP/IP, UDP, DNS, SMTP, HTTP, and distributed networks)
Knowledge in different types of VPN, Encryption Standards, Certificates
Strong understanding of security controls in public cloud environments (i.e. Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform) and SaaS services hardening.
Ability to write technical reports and communicate technical content to business users
Strong written, oral communication and interpersonal skills are a must
Ability to write technical reports and communicate technical content to business users