Description
Role Summary
Response Engineer within the Cloudflare Managed Defense Center (CMDC) provides front-line technical monitoring and threat mitigation for Cloudflare's premium enterprise customers. In this role, you will proactively monitor internal alerting systems to identify, analyze, and mitigate real-time security events across OSI Layers 3, 4, and 7. Working alongside senior engineers and operational teams, you will execute established runbooks to protect complex customer infrastructure from sophisticated DDoS and application-layer attacks.
Role Responsibilities
- Monitor and investigate proactive security alerts via internal telemetry systems to rapidly identify ongoing infrastructure and application-layer attacks.
- Apply appropriate mitigation steps and filter malicious traffic using Cloudflare's core security tools, including Magic Transit, Web Application Firewall (WAF), and Rate Limiting.
- Review incoming alerts to determine urgency, scope, and validity, while accurately maintaining incident tracking tickets for necessary escalations.
- Communicate technical updates clearly and professionally with enterprise customers via chat, email, and phone during active security incidents.
- Adhere to strict customer SLAs for alert response times, event analysis, and ongoing operational communications.
- Maintain and update customer-specific runbooks, threshold rules, and escalation matrices to ensure seamless incident execution.
- Collaborate with internal Engineering and Product teams to provide feedback on tools and suggest improvements for alert rules.
Role Requirements (Must-Have Skills)
- A minimum of 2–5 years of relevant hands-on experience in a Security Operations Center (SOC), technical support engineering, or network operations environment.
- Strong foundational understanding of networking principles and internet protocols, including TCP/IP, UDP, ICMP, DNS, and BGP.
- Experience analyzing network traffic data for anomaly detection and executing basic mitigation protocols against L3/L4 or L7 attacks.
- Professional proficiency using the command line (Bash shell) alongside general system administration literacy across Linux, Mac, or Windows environments.
- Proven customer-facing technical support experience, with the communication skills required to assist stakeholders during high-pressure incidents.
Nice-to-Have Skills
- Hands-on experience with packet capture and network analysis tools such as tcpdump or Wireshark.
- Foundational scripting skills (Python preferred) to assist in automating basic operational workflows.
- Familiarity with querying datasets via APIs/GraphQL or monitoring performance metrics inside Prometheus and Grafana dashboards.
- Relevant industry certifications, such as CompTIA Security+, CCNA, or foundational GIAC credentials (e.g., GCIA).
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/cloudflare/jobs/8037628