Senior Product Security Engineer

CloudflareSan Francisco, CA
Onsite

About The Position

As a Senior Product Security Engineer, you will lead security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs. On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Requirements

  • Senior-Level Product/AppSec Expertise: Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis: Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership: Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication: Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.

Nice To Haves

  • Offensive Mastery: Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases

Responsibilities

  • Autonomously Drive AI Security Innovation: Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling: Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management: Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support: Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship: Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.

Benefits

  • medical, dental, and vision insurance
  • a 401(k) plan with company match
  • flexible paid time off
  • fertility & family-forming benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service