# Product Security Engineer

**Company**: Cloudflare
**Location**: Bengaluru, India
**Work arrangement**: onsite
**Experience**: senior
**Job type**: full-time
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/cloudflare/jobs/8053116?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_994d4ad3-a75

## Description

As a Product Security Engineer at Cloudflare, you will support security assessments and vulnerability operations for Cloudflare's core software products.

In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within established SLAs.

Your responsibilities will include:

- Implementing AI-driven tools to automate code analysis, optimize triage, and streamline Product Security workflows.

- Conducting structured security reviews and threat modeling sessions across product features, defining security requirements early in the development lifecycle.

- Managing the operational lifecycle of product security findings, ensuring vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation.

- Performing technical triage and validation of external Bug Bounty submissions, verifying exploitability and evaluating business risk.

- Supporting internal and external penetration testing engagements by reviewing findings and assisting development teams with remediation strategies.

- Partnering closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices.

Requirements:

- 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.

- Demonstrated ability to build production-grade automation scripts and tools, with hands-on engineering experience leveraging AI/LLMs.

- Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact.

- Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs.

- Strong collaboration and communication skills, with the ability to clearly communicate technical security risks to software engineers.

Nice-to-have skills:

- Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.

- Experience scaling crowdsourced security programs or optimizing agile project management workflows.

- Experience integrating hardware security features into production code bases.

## Skills

### Required
- Product Security
- Application Security
- AI/LLMs
- Threat Modeling
- Vulnerability Management
- Collaboration

### Nice to have
- Offensive Security
- Program Management
- Hardware Security

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/cloudflare/jobs/8053116?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
