Find jobs
Pricing
Free Resume Checker
Sign in
Sign up
FIND JOBSPRICINGFREE RESUME CHECKERSIGN INSIGN UP
Jobs
/Security Engineer jobs
Thehartford

IND Lead Engineer, Security - Web Application and API Protection Security Engineer

LocationIndia GCC-Puppalaguda Village
Typefull-time
SeniorityLead
Experience3+ yrs
DepartmentInformation Security
Company size10,000+ people
First seenOct 8, 2026 · 3d ago
Verified live1d ago
At a glanceSummarised by Seekless from the posting.
Must have10
Bachelor's degree in Information Security, Computer Science, Cybersecurity, or related field (or equivalent experience)
3+ years of experience in application security, web security, network security, or a related cybersecurity role
Hands-on experience with WAAP technologies such as Akamai WAF & API Security, Apigee API Management, AWS WAF, Google Cloud Armor
Strong understanding of OWASP Top 10, OWASP API Security Top 10
Strong understanding of Authentication and Authorization (OAuth2, OIDC, SAML)
Strong understanding of REST, GraphQL, and SOAP APIs
Strong understanding of TLS/SSL
Strong understanding of SPA, MPA and Web Application architectures
Experience with API discovery, API inventory management, and API security monitoring
Experience with SIEM, security monitoring, and log analysis platforms
Nice to have3
Experience implementing enterprise WAF and API security programs
Knowledge of Secure Software Development Lifecycle (SSDLC) practices
Industry certifications such as CISSP, AWS Certified Security Specialty
Skills
Akamai WAF & API Security
Apigee API Management
AWS WAF
Google Cloud Armor
OAuth2
OIDC
SAML
REST
GraphQL
SOAP
TLS/SSL
SIEM
IND Lead Engineer, Security - GCC041
About the company
We’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals – and to help others accomplish theirs, too. Join our team as we help shape the future.
Job Posting: Web Application and API Protection (WAAP) Engineer
Overview
We are seeking a highly skilled Web Application and API Protection (WAAP) Engineer to join our Information Security team. This role is responsible for designing, implementing, and managing enterprise-scale protections for web applications and APIs. The ideal candidate will have deep expertise in web application security, API security, web application firewalls (WAF), bot mitigation, DoS protection, and modern cloud-native security architectures.
As a WAAP Engineer, you will work closely with application development, cloud engineering, network security, and cybersecurity teams to protect critical business services from evolving threats while enabling secure digital innovation.
Key Responsibilities
•
Provide operational support and maintenance for The Hartford’s enterprise WAF and API security platforms
•
Design, deploy, and maintain WAAP solutions including
•
Threat Detection and Prevention
•
Vulnerability Detection and Prevention
•
Bot Management and Account Protection
•
DoS mitigation technologies
•
Develop and manage security policies to protect web applications, mobile applications, and APIs from OWASP Top 10 and OWASP API Top 10 threats
•
Monitor, analyze, and respond to application-layer attacks, malicious bot activity, and API abuse
•
Conduct rule tuning, false-positive analysis, and security policy optimization
•
Support cloud-native WAAP deployments across environments such as AWS, Azure, GCP
•
Create dashboards, metrics, and reports demonstrating security posture, attack trends, and risk reduction
•
Stay current on emerging web, API, and application security threats, vulnerabilities, and industry best practices
•
Participate in security incident response activities involving web applications and APIs
Required Qualifications
•
Bachelor’s degree in Information Security, Computer Science, Cybersecurity, or related field (or equivalent experience)
•
3+ years of experience in application security, web security, network security, or a related cybersecurity role
•
Hands-on experience with WAAP technologies such as
•
Akamai WAF & API Security
•
Apigee API Management
•
AWS WAF
•
Google Cloud Armor
•
Strong understanding of
•
OWASP Top 10
•
OWASP API Security Top 10
•
Authentication and Authorization (OAuth2, OIDC, SAML)
•
REST, GraphQL, and SOAP APIs
•
TLS/SSL
•
SPA, MPA and Web Application architectures
•
Experience with API discovery, API inventory management, and API security monitoring
•
Experience with SIEM, security monitoring, and log analysis platforms
Preferred Qualifications
•
Experience implementing enterprise WAF and API security programs
•
Knowledge of Secure Software Development Lifecycle (SSDLC) practices
•
Industry certifications such as:
•
CISSP
•
AWS Certified Security Specialty
About Us | Our Culture | What It’s Like to Work Here
More roles at Thehartford
Associate Risk AnalystBusiness Insurance Auto Claims InternActuarial Analyst - Small Business Workers CompensationAssociate, Finance Leadership Development ProgramClaim Consultant Cyber & Technology
Seekless
Seek less: one search across companies' own career pages, instead of a dozen job boards.
Product
Find jobsCompaniesPricingFree Resume CheckerBlog
Legal
AboutPrivacyTermsCookies
© 2026 SEEKLESS. ALL RIGHTS RESERVED.BUILT WITH CARE