DEVSECOPS & SECURITY SPECIALIST
AWS WAF | SonicWall | NGINX | Freelance
Experience
3-7 Years
Location
Bangalore / Bengaluru
Work Mode
Hybrid / Remote
Engagement
Freelance / Contract
Billing
Hourly
Joining
Immediate to 15 Days
Role Overview
We are seeking a hands-on DevSecOps and Security Specialist with 3-7 years of experience in AWS security, AWS WAF, perimeter network defense and NGINX administration. The specialist will secure AWS-hosted applications and infrastructure, configure Layer 7 protection, manage SonicWall firewalls, harden NGINX reverse proxies and integrate security controls into CI/CD pipelines. This is a priority freelance engagement requiring availability for planned assignments and agreed urgent-support windows on an hourly basis.
Key ResponsibilitiesAWS Security & WAF Management
· Design, deploy and manage AWS WAF Web ACLs for Application Load Balancers, CloudFront, API Gateway and AWS AppSync.
· Configure AWS Managed Rules and custom controls against SQL injection, cross-site scripting, path traversal, malicious payloads and other OWASP Top 10 risks.
· Implement rate-based rules, geo-blocking, IP reputation controls, allowlists, blocklists and scope-down statements.
· Configure and fine-tune Bot Control and Fraud Control features where required.
· Analyze WAF logs, reduce false positives and monitor Web ACL usage, request volume, WCU consumption and cost.
Network & Perimeter Security
· Configure and administer SonicWall/SonicOS firewall appliances, including security policies, NAT, routing and network segmentation.
· Configure and troubleshoot site-to-site and remote-access VPNs.
· Manage IPS/IDS, gateway-security and threat-prevention policies, and investigate perimeter-security incidents.
NGINX & Reverse Proxy Security
· Install, configure, secure and optimize NGINX web servers and reverse proxies.
· Configure SSL/TLS termination, upstream services, load balancing, security headers, request filtering and rate limiting.
· Troubleshoot HTTP errors, SSL issues, upstream failures and reverse-proxy performance problems.
DevSecOps, Monitoring & Incident Support
· Integrate security controls into GitHub Actions, GitLab CI or Jenkins pipelines.
· Implement or maintain SAST, DAST, dependency, container and infrastructure-as-code security scanning.
· Configure and monitor GuardDuty, Security Hub, CloudTrail, AWS Config and CloudWatch.
· Audit IAM, VPC, EC2, S3, Security Groups and NACLs against CIS benchmarks and least-privilege principles.
· Analyze AWS WAF, CloudTrail, CloudWatch, NGINX and firewall logs; support incident investigation, containment, remediation and root-cause analysis.
· Maintain implementation records, operating procedures and remediation recommendations.
Required Skills & Qualifications
· 3-7 years of relevant experience in DevSecOps, cloud security or network security.
· Strong production experience with AWS WAF integrations for ALB, CloudFront and API Gateway.
· Practical knowledge of GuardDuty, Security Hub, CloudTrail, CloudWatch, IAM, VPC, EC2, S3, Security Groups and NACLs.
· Hands-on administration of SonicWall/SonicOS, including IPS/IDS, NAT, VPNs, routing and segmentation.
· Strong NGINX administration, reverse-proxy, SSL/TLS, security-header and rate-limiting experience.
· Experience with GitHub Actions, GitLab CI or Jenkins, and familiarity with SAST/DAST practices.
· Ability to analyze security logs using CloudWatch, Athena or SIEM platforms.
· Strong understanding of OWASP Top 10, CIS benchmarks and least-privilege security.
· Ability to work independently and communicate clearly during priority incidents.
Preferred Skills & Certifications
· Terraform or AWS CloudFormation; AWS Shield, Config, Inspector, Macie or Network Firewall.
· Splunk, ELK/OpenSearch or another SIEM platform; container or Kubernetes security.
· Python, Bash or PowerShell automation.
· AWS Certified Security - Specialty; AWS Solutions Architect - Associate/Professional; SonicWall Network Security Administrator (SNSA), or equivalent certification.
Ideal Candidate
The ideal candidate can quickly understand an existing AWS and network environment, independently implement practical security improvements, document changes and support both scheduled work and priority troubleshooting. Bangalore-based candidates who can provide occasional onsite support are preferred.
Application Details
· Share your updated resume and current Bangalore location.
· Mention your total and relevant experience with AWS WAF, SonicWall and NGINX.
· Provide your hourly freelance rate, availability, notice period and preferred support hours.
· Briefly describe one relevant AWS WAF or cloud-security implementation.
Send applications to: "[email protected]"
Pay: ₹565,222.50 - ₹1,800,000.00 per year
Benefits:
- Flexible schedule
- Food provided
- Health insurance
- Paid sick time
- Paid time off
- Provident Fund
Work Location: In person