# Response Engineer - PhishGuard

**Company**: Cloudflare
**Location**: Austin, TX
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/cloudflare/jobs/8041746?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_2ff889b8-a2a

## Description

## Role Summary

As a Response Engineer for PhishGuard, you will serve as the essential human intelligence layer responsible for identifying, tracking, and defeating sophisticated email-borne cyber threats like Business Email Compromise (BEC) and vendor fraud.

## Responsibilities

- Conduct continuous, real-time monitoring of email threat queues to review and analyze sophisticated attacks flagged by Cloudflare Email Security automated systems.

- Investigate customer-reported submissions, execute proactive threat hunts targeting emerging patterns, and perform manual retraction or quarantine of verified malicious emails.

- Provide critical feedback to Detection Engineering to update machine learning models and contribute novel campaign data to global intelligence repositories.

- Identify nuanced threat patterns by correlating technical telemetry with behavioral indicators, generating detailed threat dossiers for impending organisational risks.

- Deliver direct crisis intervention and proactive phone notifications to customers regarding high-dollar BEC threats and active insider risks.

- Lead technical onboarding sessions for new customers, configuring internal system instances with bespoke detection rules, thresholds, and custom allow/block lists.

- Guide customers through their multi-year DMARC implementation journey toward strict "Reject" policy enforcement by conducting SPF and DKIM alignment audits.

## Requirements

- Undergraduate degree in Computer Science, Information Security, Information Systems, or equivalent practical experience.

- 5+ years of experience tracking and analyzing complex cyber campaigns utilizing technical indicators such as Domains, IP Addresses, and email headers.

- Proven expertise analyzing, investigating, and defending against highly targeted phishing, invoice fraud, and Business Email Compromise (BEC) attacks.

- Deep working knowledge of core email authentication protocols (SPF, DKIM, DMARC) and aggregate/forensic data interpretation.

- Hands-on experience utilizing AI LLM tools (such as OpenCode or Windsurf) to develop automations for daily analysis and productivity workflows.

- Excellent verbal and written English communication skills, with a strong ability to translate complex technical threats into actionable business intelligence for executive stakeholders.

## Nice-to-Have Skills

- Relevant industry certifications such as GCIH, GCIA, CEH, Security+, or equivalent.

- Technical familiarity with regular expressions, YARA rules, SQL query formulation, and malicious file format analysis (e.g., Microsoft Office Documents, Adobe PDFs).

- Prior experience working within managed security services (MSSP) or customer-facing security consulting environments.

- Familiarity with the broader Cloudflare ecosystem, including Cloudflare Email Security, WAF, and Zero Trust architectures.

## Skills

### Required
- Computer Science
- Information Security
- Information Systems
- Domains
- IP Addresses
- email headers
- Phishing
- invoice fraud
- Business Email Compromise (BEC)
- SPF
- DKIM
- DMARC
- AI LLM tools
- OpenCode
- Windsurf

### Nice to have
- GCIH
- GCIA
- CEH
- Security+
- regular expressions
- YARA rules
- SQL query formulation
- malicious file format analysis
- managed security services (MSSP)
- customer-facing security consulting environments
- Cloudflare Email Security
- WAF
- Zero Trust architectures

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/cloudflare/jobs/8041746?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
