职位介绍
Job Description
GCP WAF / Cloud Armor Implementation Design, deploy, and maintain Google Cloud Armor security policies for applications behind External HTTP(S) Load Balancers Implement preconfigured WAF rules based on OWASP Mod Security CRS (SQLi, XSS, LFI, RFI, RCE, protocol attacks)Configure custom security rules, IP allow/deny lists, geo‑blocking, and adaptive protection Apply WAF policies to workloads hosted on GKE, Cloud Run (Serverless NEG), Managed Instance Groups, and App EngineWAF Tuning & Traffic Analysis Analyze Cloud Armor logs to identify false positives and false negatives Tune CRS sensitivity levels, rule priorities, and regex patterns Move rules from preview / log‑only mode to enforcement mode safely Work with application teams to troubleshoot legitimate traffic blocks Automation & Dev Sec Ops Automate WAF deployments using Terraform (IaC) and gcloud CLIIntegrate WAF controls into CI/CD pipelines as part of Dev Sec Ops Maintain version‑controlled security policies and policy‑as‑code standards Security Operations & Monitoring Integrate Cloud Armor logs with SIEM platforms (Cloud Logging, Chronicle, Splunk, Sentinel, etc.)Support application‑layer DDoS mitigation and incident response Develop and maintain runbooks, SOPs, and operational documentation Collaborate with SOC, Network Security, and Platform teams Governance & Compliance Ensure WAF configurations align with enterprise security baselines and Zero Trust architecture Support audit and compliance requirements (PCI DSS, SOC 2, ISO 27001, RBI / BFSI standards as applicable)Required Skills & Experience Must‑Have Skills Hands‑on experience with Google Cloud Armor (GCP WAF)Strong knowledge of OWASP Top 10 and web attack patterns Experience protecting workloads behind External HTTP(S) Load Balancers Expertise in WAF tuning, false‑positive reduction, and traffic inspection Terraform / Infrastructure‑as‑Code for security policy automation Understanding of HTTP/HTTPS, REST APIs, TLS, DNSNice‑to‑Have Skills Experience with multi‑cloud WAFs (AWS WAF, Azure WAF, Cloudflare, Akamai)Exposure to IDS/IPS, bot protection, API security Scripting using Python or Bash Familiarity with SIEM and SOC workflowsGCP Services & Technologies Google Cloud Armor (WAF & DDoS)External HTTP(S) Load BalancerGKE, Cloud Run, Compute Engine Cloud Logging & Monitoring Terraform, gcloud CLICI/CD tools (GitHub, GitLab, Azure DevOps, etc.)Certifications (Preferred)Google Professional Cloud Security EngineerCISSP / CCSP (Nice to have)
͏
͏
福利待遇
•Learning Budget
•医疗保险
•股权
必备技能
Cybersecurity
Security monitoring
Incident analysis
关于Wipro
Hyderabad
总部位置
