New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Cloudflare

Response Engineer - PhishGuard

Cloudflare
Apply →
hybrid senior full-time Austin, TX

First indexed 3 Jul 2026

Description

Role Summary

As a Response Engineer for PhishGuard, you will serve as the essential human intelligence layer responsible for identifying, tracking, and defeating sophisticated email-borne cyber threats like Business Email Compromise (BEC) and vendor fraud.

Responsibilities

  • Conduct continuous, real-time monitoring of email threat queues to review and analyze sophisticated attacks flagged by Cloudflare Email Security automated systems.
  • Investigate customer-reported submissions, execute proactive threat hunts targeting emerging patterns, and perform manual retraction or quarantine of verified malicious emails.
  • Provide critical feedback to Detection Engineering to update machine learning models and contribute novel campaign data to global intelligence repositories.
  • Identify nuanced threat patterns by correlating technical telemetry with behavioral indicators, generating detailed threat dossiers for impending organisational risks.
  • Deliver direct crisis intervention and proactive phone notifications to customers regarding high-dollar BEC threats and active insider risks.
  • Lead technical onboarding sessions for new customers, configuring internal system instances with bespoke detection rules, thresholds, and custom allow/block lists.
  • Guide customers through their multi-year DMARC implementation journey toward strict "Reject" policy enforcement by conducting SPF and DKIM alignment audits.

Requirements

  • Undergraduate degree in Computer Science, Information Security, Information Systems, or equivalent practical experience.
  • 5+ years of experience tracking and analyzing complex cyber campaigns utilizing technical indicators such as Domains, IP Addresses, and email headers.
  • Proven expertise analyzing, investigating, and defending against highly targeted phishing, invoice fraud, and Business Email Compromise (BEC) attacks.
  • Deep working knowledge of core email authentication protocols (SPF, DKIM, DMARC) and aggregate/forensic data interpretation.
  • Hands-on experience utilizing AI LLM tools (such as OpenCode or Windsurf) to develop automations for daily analysis and productivity workflows.
  • Excellent verbal and written English communication skills, with a strong ability to translate complex technical threats into actionable business intelligence for executive stakeholders.

Nice-to-Have Skills

  • Relevant industry certifications such as GCIH, GCIA, CEH, Security+, or equivalent.
  • Technical familiarity with regular expressions, YARA rules, SQL query formulation, and malicious file format analysis (e.g., Microsoft Office Documents, Adobe PDFs).
  • Prior experience working within managed security services (MSSP) or customer-facing security consulting environments.
  • Familiarity with the broader Cloudflare ecosystem, including Cloudflare Email Security, WAF, and Zero Trust architectures.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/cloudflare/jobs/8041746