Job Title: Security ConsultantRole SummaryWe are seeking a Security Consultant to join our team as a hands-on technical specialist in automated threats and application security. In this role, you will be responsible for implementing, tuning, and maintaining security controls that protect our e-commerce platform and customer experience.You will collaborate closely with Security Engineers and Architects, while acting as a technical bridge to Application, DevOps, and Operations teams - providing execution and advisory support across the security lifecycle. Key Responsibilities1. Bot Traffic Management & Edge SecurityDetect and mitigate advanced automated traffic, including headless browsers and human-mimicking bots.Analyze traffic patterns to identify and block threats such as credential stuffing, ATO, inventory scalping, and scraping.Implement and maintain edge protections including Akamai Bot Manager Premier (BMP), WAF, Content Protection Rules (CPR), and CDN configurations.2. Application Security Through Entire SDLCEmbed SAST (SonarQube) and DAST (Invicti) within the CI/CD pipeline in collaboration with DevOps.Triage vulnerabilities, reduce false positives, and ensure actionable remediation guidance for developers.Conduct targeted application and API security assessments using Burp Suite.3. Security Enablement & Operational SupportPartner with Application Teams to remediate vulnerabilities aligned with OWASP Top 10 and API security best practices.Support Production Operations by troubleshooting security incidents, tuning controls, and minimizing false positives or performance impact.Contribute to identifying and prioritizing security debt in coordination with business and engineering teams. Technical ProfileExperience: 5+ years in application security, web security, or security incident management preferably in e-commerce or high-traffic environments.Threat Knowledge: Strong understanding of OWASP Automated Threats (OAT) and common attack patterns targeting online retail platforms.Tools & Platforms: Hands-on experience with one or more of the following: Invicti, Burp Suite, SonarQube, and bot mitigation tools (e.g., Akamai BMP, QuietAI).Technical Foundations: Familiarity with CDN/WAF architectures, API protocols (REST/GraphQL), and modern web application stacks.Collaboration: Ability to translate security findings into clear, actionable guidance for development and operations teams. Soft Skills· Strong communication skills with the ability to explain security risks and remediation clearly to technical and non-technical stakeholders.· Collaborative mindset with experience working across development, DevOps, and operations teams.· Analytical thinking and problem-solving skills, especially when investigating complex or ambiguous security issues.· Ability to prioritize effectively in a fast-paced, production-driven environment.· Proactive and ownership-driven approach to improving security posture and processes. Team DynamicsThis role is focused on execution, analysis, and enablement. You will operate within the frameworks defined by Security Architects and Engineers, while serving as a key partner to application, DevOps, and operations teams to ensure security controls are effective and sustainable.RequirementsGraduationJob Title: Security ConsultantRole SummaryWe are seeking a Security Consultant to join our team as a hands-on technical specialist in automated threats and application security. In this role, you will be responsible for implementing, tuning, and maintaining security controls that protect our e-commerce platform and customer experience.You will collaborate closely with Security Engineers and Architects, while acting as a technical bridge to Application, DevOps, and Operations teams - providing execution and advisory support across the security lifecycle. Key Responsibilities1. Bot Traffic Management & Edge SecurityDetect and mitigate advanced automated traffic, including headless browsers and human-mimicking bots.Analyze traffic patterns to identify and block threats such as credential stuffing, ATO, inventory scalping, and scraping.Implement and maintain edge protections including Akamai Bot Manager Premier (BMP), WAF, Content Protection Rules (CPR), and CDN configurations.2. Application Security Through Entire SDLCEmbed SAST (SonarQube) and DAST (Invicti) within the CI/CD pipeline in collaboration with DevOps.Triage vulnerabilities, reduce false positives, and ensure actionable remediation guidance for developers.Conduct targeted application and API security assessments using Burp Suite.3. Security Enablement & Operational SupportPartner with Application Teams to remediate vulnerabilities aligned with OWASP Top 10 and API security best practices.Support Production Operations by troubleshooting security incidents, tuning controls, and minimizing false positives or performance impact.Contribute to identifying and prioritizing security debt in coordination with business and engineering teams. Technical ProfileExperience: 5+ years in application security, web security, or security incident management preferably in e-commerce or high-traffic environments.Threat Knowledge: Strong understanding of OWASP Automated Threats (OAT) and common attack patterns targeting online retail platforms.Tools & Platforms: Hands-on experience with one or more of the following: Invicti, Burp Suite, SonarQube, and bot mitigation tools (e.g., Akamai BMP, QuietAI).Technical Foundations: Familiarity with CDN/WAF architectures, API protocols (REST/GraphQL), and modern web application stacks.Collaboration: Ability to translate security findings into clear, actionable guidance for development and operations teams. Soft Skills· Strong communication skills with the ability to explain security risks and remediation clearly to technical and non-technical stakeholders.· Collaborative mindset with experience working across development, DevOps, and operations teams.· Analytical thinking and problem-solving skills, especially when investigating complex or ambiguous security issues.· Ability to prioritize effectively in a fast-paced, production-driven environment.· Proactive and ownership-driven approach to improving security posture and processes. Team DynamicsThis role is focused on execution, analysis, and enablement. You will operate within the frameworks defined by Security Architects and Engineers, while serving as a key partner to application, DevOps, and operations teams to ensure security controls are effective and sustainable.
Job Title: Security Consultant
Job Title: Security ConsultantJob Title: Security Consultant
Role Summary
Role SummaryRole Summary
We are seeking a Security Consultant to join our team as a hands-on technical specialist in automated threats and application security. In this role, you will be responsible for implementing, tuning, and maintaining security controls that protect our e-commerce platform and customer experience.
We are seeking a Security Consultant to join our team as a hands-on technical specialist in automated threats and application security. In this role, you will be responsible for implementing, tuning, and maintaining security controls that protect our e-commerce platform and customer experience.
Security ConsultantYou will collaborate closely with Security Engineers and Architects, while acting as a technical bridge to Application, DevOps, and Operations teams - providing execution and advisory support across the security lifecycle.
You will collaborate closely with Security Engineers and Architects, while acting as a technical bridge to Application, DevOps, and Operations teams - providing execution and advisory support across the security lifecycle.
Security EngineersArchitectsApplicationDevOpsOperationsKey Responsibilities
Key ResponsibilitiesKey Responsibilities
1. Bot Traffic Management & Edge Security
1. Bot Traffic Management & Edge Security1. Bot Traffic Management & Edge Security
- Detect and mitigate advanced automated traffic, including headless browsers and human-mimicking bots.
Detect and mitigate advanced automated traffic, including headless browsers and human-mimicking bots.
headless browsershuman-mimicking bots- Analyze traffic patterns to identify and block threats such as credential stuffing, ATO, inventory scalping, and scraping.
Analyze traffic patterns to identify and block threats such as credential stuffing, ATO, inventory scalping, and scraping.
- Implement and maintain edge protections including Akamai Bot Manager Premier (BMP), WAF, Content Protection Rules (CPR), and CDN configurations.
Implement and maintain edge protections including Akamai Bot Manager Premier (BMP), WAF, Content Protection Rules (CPR), and CDN configurations.
Akamai Bot Manager Premier (BMP)WAFContent Protection Rules (CPR)CDN2. Application Security Through Entire SDLC
2. Application Security Through Entire SDLC2. Application Security Through Entire SDLC
- Embed SAST (SonarQube) and DAST (Invicti) within the CI/CD pipeline in collaboration with DevOps.
Embed SAST (SonarQube) and DAST (Invicti) within the CI/CD pipeline in collaboration with DevOps.
SAST (SonarQube)DAST (Invicti)DevOps- Triage vulnerabilities, reduce false positives, and ensure actionable remediation guidance for developers.
Triage vulnerabilities, reduce false positives, and ensure actionable remediation guidance for developers.
- Conduct targeted application and API security assessments using Burp Suite.
Conduct targeted application and API security assessments using Burp Suite.
Burp Suite3. Security Enablement & Operational Support
3. Security Enablement & Operational Support3. Security Enablement & Operational Support
- Partner with Application Teams to remediate vulnerabilities aligned with OWASP Top 10 and API security best practices.
Partner with Application Teams to remediate vulnerabilities aligned with OWASP Top 10 and API security best practices.
Application TeamsOWASP Top 10- Support Production Operations by troubleshooting security incidents, tuning controls, and minimizing false positives or performance impact.
Support Production Operations by troubleshooting security incidents, tuning controls, and minimizing false positives or performance impact.
Production Operations- Contribute to identifying and prioritizing security debt in coordination with business and engineering teams.
Contribute to identifying and prioritizing security debt in coordination with business and engineering teams.
security debtTechnical Profile
Technical ProfileTechnical Profile
- Experience: 5+ years in application security, web security, or security incident management preferably in e-commerce or high-traffic environments.
Experience:Experience:5+ years in application security, web security, or security incident management preferably in e-commerce or high-traffic environments.
- Threat Knowledge: Strong understanding of OWASP Automated Threats (OAT) and common attack patterns targeting online retail platforms.
Threat Knowledge:Threat Knowledge:Strong understanding of OWASP Automated Threats (OAT) and common attack patterns targeting online retail platforms.
OWASP Automated Threats (OAT)- Tools & Platforms: Hands-on experience with one or more of the following: Invicti, Burp Suite, SonarQube, and bot mitigation tools (e.g., Akamai BMP, QuietAI).
Tools & Platforms:Tools & Platforms:Hands-on experience with one or more of the following: Invicti, Burp Suite, SonarQube, and bot mitigation tools (e.g., Akamai BMP, QuietAI).
InvictiBurp SuiteSonarQubeAkamai BMPQuietAI- Technical Foundations: Familiarity with CDN/WAF architectures, API protocols (REST/GraphQL), and modern web application stacks.
Technical Foundations:Technical Foundations:Familiarity with CDN/WAF architectures, API protocols (REST/GraphQL), and modern web application stacks.
- Collaboration: Ability to translate security findings into clear, actionable guidance for development and operations teams.
Collaboration:Collaboration:Ability to translate security findings into clear, actionable guidance for development and operations teams.
Soft Skills
Soft SkillsSoft Skills
· Strong communication skills with the ability to explain security risks and remediation clearly to technical and non-technical stakeholders.
··Strong communication skills with the ability to explain security risks and remediation clearly to technical and non-technical stakeholders.
· Collaborative mindset with experience working across development, DevOps, and operations teams.
··Collaborative mindset with experience working across development, DevOps, and operations teams.
developmentDevOpsoperations· Analytical thinking and problem-solving skills, especially when investigating complex or ambiguous security issues.
··Analytical thinking and problem-solving skills, especially when investigating complex or ambiguous security issues.
· Ability to prioritize effectively in a fast-paced, production-driven environment.
··Ability to prioritize effectively in a fast-paced, production-driven environment.
· Proactive and ownership-driven approach to improving security posture and processes.
··Proactive and ownership-driven approach to improving security posture and processes.
Team Dynamics
Team DynamicsTeam Dynamics
This role is focused on execution, analysis, and enablement. You will operate within the frameworks defined by Security Architects and Engineers, while serving as a key partner to application, DevOps, and operations teams to ensure security controls are effective and sustainable.
This role is focused on execution, analysis, and enablement. You will operate within the frameworks defined by Security Architects and Engineers, while serving as a key partner to application, DevOps, and operations teams to ensure security controls are effective and sustainable.
execution, analysis, and enablementSecurity ArchitectsEngineers