Description
At Cloudflare, we're on a mission to help build a better Internet. We're looking for a Senior Product Security Engineer to lead security assessments and vulnerability operations for Cloudflare's core software products.
As a Senior Product Security Engineer, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.
Responsibilities:
- Autonomously drive AI security innovation, identifying gaps in current capabilities and architecting, building, and deploying AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
- Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
- Own the lifecycle of product security findings, ensuring vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
- Oversee the technical triage and validation of Cloudflare's external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
- Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
- Act as a force-multiplier for security across Cloudflare, mentoring junior engineers, cultivating security champions within engineering organizations, and establishing modern, paved-road developer guardrails.
Desirable Skills, Knowledge, and Experience:
- Senior-level Product/AppSec expertise with extensive experience in large-scale distributed cloud environments or SaaS platforms.
- Practical AI and automation engineering experience, with hands-on experience leveraging AI/LLMs to solve operational or technical challenges.
- Advanced threat modeling and risk analysis skills, with mastery of threat modeling methodologies like STRIDE.
- Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
- Superb cross-functional leadership skills, with the ability to confidently influence senior engineering leaders and champion security initiatives.
Benefits:
- Medical, dental, and vision insurance
- 401(k) plan with company match
- Flexible paid time off
- Fertility and family-forming benefits
Equity: This role is eligible to participate in Cloudflare's equity plan.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/cloudflare/jobs/8079931