Job Summary
L2 Web Application Security Engineer (FortiWeb WAF - Primary | Position Title L2 Security Engineer - FortiWeb WAF Location Noida Experience Required 4-6 Years Employment Type Full-Time
Position Summary We are looking for an experienced L2 Security Engineer with strong hands-on expertise in Fortinet FortiWeb (Web Application Firewall) as the primary The candidate will be responsible for day-to-day operations, incident handling, troubleshooting, change implementation, policy administration, performance monitoring, and security management of enterprise web application security and cloud security environments. The role requires interaction with application teams, infrastructure teams, and security operations teams to ensure secure and uninterrupted business operations.
Key Responsibilities
Key Responsibilities FortiWeb WAF Administration (Primary Skill) • Provide L2 operational support for FortiWeb Web Application Firewall environments, Monitor WAF alerts, logs, and security events. • Configure and maintain: o Web Protection Profiles, Server Policies, URL Access Policies, IP Reputation and Geo-IP Controls, Bot Mitigation Policies o API Protection Policies ,SSL Offloading , HTTP/HTTPS Security Policies, Virtual Patching Rules • Monitor and tune WAF signatures to reduce false positives, Support application onboarding activities, Assist application teams with troubleshooting blocked transactions, Validate and implement approved firewall and WAF changes, Support firmware upgrades and patching activities, Generate reports and security dashboards. Required Technical Skills Primary Skill (Mandatory) FortiWeb WAF • FortiWeb Administration , WAF Policy Management, Attack Signature Management, SSL Certificate Management, Reverse Proxy Architecture • Protect web applications against: o OWASP Top 10 attacks o SQL Injection (SQLi) o Cross-Site Scripting (XSS) o CSRF o File Inclusion Attacks o Command Injection o Bot Attacks o Credential Stuffing • Configure: o Web Protection Profiles o Signature-Based Protection o Machine Learning Profiles o API Security o Bot Mitigation o Rate Limiting • Traffic Analysis and Log Interpretation, WAF Troubleshooting • Monitor WAF alerts, logs, and security events. • Analyze attack patterns and identify false positives. • Investigate security incidents and provide remediation recommendations. • Support P1/P2 incident handling and root cause analysis. Networking Knowledge Required Candidates should possess good understanding of: • TCP/IP, Routing and Switching Fundamentals, DNS, DHCP, HTTP/HTTPS, Protocols, SSL/TLS Certificates, Load Balancers, Reverse Proxy Concepts, VPN Technologies, Authentication Protocols , Network Traffic Analysis Monitoring & Troubleshooting Skills Experience with: • Packet Capture Analysis, Browser Developer Tools, FortiAnalyzer, Syslog Analysis, SIEM Integration, Event Log Analysis, SSL Handshake Troubleshooting, Application Access Troubleshooting Required Experience • 4-6 years of Information Security or Network Security experience, Minimum 3 years of hands-on experience with FortiWeb WAF Experience supporting production environments, Experience handling incidents and change requests, Familiarity with ITIL processes.
Skill Requirements
Other Requirements
NA