Hiring || Azure Cloud WAF Engineer
Posted:
8 August 2026 (4 hours ago)
Application Deadline:
5 November 2026
Vacancies:
1 Vacancy
Job Summary
Summary:
The Azure Cloud WAF Engineer plays a pivotal role within the ECB Programme driving the deployment and management of Web Application Firewall (WAF) solutions across all client-facing and internal web applications to meet stringent regulatory requirements. Operating as part of the Run the Bank team this role leverages Agile methodologies to collaborate closely with Global Business Teams ensuring effective implementation of custom WAF rules exception handling and accurate false positive analysis. The engineer will lead baseline policy updates maintain strategic relationships with vendor partners and HSBC Cloud Platform Leads and support seamless service delivery by managing multiple requests concurrently. Responsibilities include resolving service issues coordinating with Change Teams and advancing DevSecOps practices through automation pipeline maintenance and process optimization. This role demands strong technical expertise in WAF and cloud security along with proactive stakeholder engagement to identify risks report status and escalate issues when necessaryensuring a secure compliant and resilient web application environment.
Location: Pune/Mumbai/Bangalore/Chennai/Hyderabad/Noida
Responsibilities:
- Deploy and manage WAF solutions across internet-facing and internal web applications in alignment with regulatory and security standards.
- Collaborate with Global Business Teams to develop test and implement custom WAF rules and exceptions.
- Conduct thorough analysis of false positives and support baseline policy tuning for optimal security and performance.
- Serve as a key liaison between internal teams vendors and HSBC Cloud Platform Leads to ensure consistent WAF governance and operational excellence.
- Manage and prioritize multiple WAF service requests coordinating with Change Teams and stakeholders for timely resolution.
- Provide DevSecOps support by maintaining automation pipelines and identifying opportunities for process automation.
- Proactively identify and escalate risks ensuring timely status reporting and alignment with project timelines.
- Support incident response efforts by interfacing with the SOC during WAF-related security events.
- Maintain and document WAF processes configurations and version control mechanisms.
- Ensure secure implementation of HTTPS inspection certificate management and access control via IDAM protocols.
- Apply rate limiting and other security controls within WAF configurations to mitigate threats.
- Monitor and manage network connectivity and service-level issues impacting WAF functionality.
Requirements
- Proven experience (615 years) in cloud security with a focus on WAF implementation and management.
- Mandatory expertise in WAF solutions: Akamai or Cloudflare (primary) with strong familiarity in F5 WAF and DDoS protection.
- In-depth knowledge of Azure cloud services and their associated WAF controls.
- Demonstrated experience with edge cloud and on-premises WAF deployments.
- Strong understanding of web application attack vectors (e.g. OWASP Top 10) and corresponding mitigation strategies.
- Proficiency in WAF rule development tuning and configuration backed by solid web security fundamentals.
- Experience designing and documenting bespoke WAF processes and policies.
- Skilled in analyzing and aligning systems with MVP and baseline configurations using WAF capabilities and constraints.
- Hands-on experience with DevSecOps pipelines including automation for WAF deployments and updates.
- Familiarity with IDAM protocols and secure access management for WAF administration.
- Solid grasp of HTTPS termination certificate lifecycle management and secure communication practices.
- Practical experience with rate limiting and traffic control mechanisms in WAF environments.
- Experience with version control systems and update mechanisms for WAF configurations.
- Ability to identify document and leverage logging solutions for security monitoring in cloud environments.
- Track record of effective collaboration with SOC teams during security incidents.
- Strong problem-solving and service management skills with a focus on resolving network and connectivity issues.
Required Skills:
Mandatory Skills : WAF DDoS-Akamai WAF DDoS-F5 Primary Skills: WAF Akamai (or) Cloudflare AZURE Secondary Skills: Networking Cloud Security
Required Education:
Someone that has extensive experience with Web Application Security log analysis and that is derived from a Cyber SOC/CSIRT work background who is willing to up-skill into a WAF Engineering SME across CN WAF (Azure) and Multi-Vendor WAF products (F5 Akamai etc.)