Cloudflare logo
Cloudflare·Verified

Product Security Engineer - Cloudflare

Hybrid remoteFull-timeSeniorUnited StatesUnited KingdomAustin+1 more#appsecBonus

About the Role

As a Product Security Engineer at Cloudflare, you will support security assessments and vulnerability operations for our core software products. You will analyze system architecture, threat model new features, and ensure that security findings are triaged, routed, and mitigated within established SLAs.

This role sits at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. We are looking for builders who want to solve complex Internet security challenges using the latest tools.

Responsibilities

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to automate code analysis and streamline workflows.
  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling (e.g., STRIDE) to define security requirements early in the development lifecycle.
  • Product Vulnerability Management: Manage the lifecycle of security findings, ensuring they are verified, mapped to owners, and tracked to mitigation.
  • Bug Bounty Triage: Perform technical triage and validation of external Bug Bounty submissions, verifying exploitability and business risk.
  • Pentest Coordination: Support internal and external penetration testing by reviewing findings and assisting teams with remediation.
  • Engineering Collaboration: Partner with DevOps and product teams to promote secure coding practices.

Desirable Skills & Experience

  • Product/AppSec Expertise: 5+ years of experience in Product or Application Security within large-scale distributed cloud or SaaS environments.
  • Practical AI & Automation: Demonstrated ability to build production-grade automation scripts and leverage AI/LLMs to solve technical challenges.
  • Threat Modeling: Competency in threat modeling methodologies and evaluating code flaws for engineering and security impact.
  • Vulnerability Operations: Experience tracking and driving remediation of software vulnerabilities across engineering groups.
  • Communication: Ability to clearly communicate technical security risks to software engineers.

Bonus Points

  • Familiarity with offensive security tooling, fuzzing frameworks, or automated scanning.
  • Experience scaling crowdsourced security programs (HackerOne, Bugcrowd) or optimizing JIRA workflows.
  • Experience integrating hardware security features into production codebases.

Benefits

Bonus

Open to

Austin · United States · London · United Kingdom

Sign in to track applications and earn points.

More roles at Cloudflare

Similar remote roles