Cloudflare is on a mission to help build a better Internet and is seeking a Product Security Engineer. In this role, you will support security assessments and vulnerability operations for Cloudflare’s core software products, analyze system architecture, and ensure that product-related security findings are accurately triaged and mitigated.
Responsibilities:
- Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to help automate code analysis, optimize triage, and streamline Product Security workflows
- Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features, defining security requirements early in the development lifecycle
- Product Vulnerability Management: Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation in alignment with established SLAs
- Bug Bounty Triage: Perform the technical triage and validation of Cloudflare’s external Bug Bounty submissions, verifying exploitability and evaluating business risk
- Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies
- Engineering Collaboration: Partner closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices
Requirements:
- 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms
- Demonstrated ability to build production-grade automation scripts and tools
- Hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges
- Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact
- Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs
- Ability to collaborate effectively across teams, clearly communicating technical security risks to software engineers and resolving ownership ambiguity constructively
- Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities
- Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA
- Experience in integrating hardware security features into production code bases