Senior Response Engineer

CloudflareSan Francisco, CA
1d

About The Position

The Senior Response Engineer - CMDC serves as a high-tier technical lead within the proactive security team. This position is built for a practitioner who thrives at the intersection of deep protocol-level investigation and strategic technical partnership. The role is responsible for architecting responses to sophisticated threats across OSI Layers 3, 4, and 7, ensuring global customers remain resilient against large-scale DDoS attacks and complex application-layer anomalies. Acting as a primary technical anchor, this individual provides advanced assistance and strategic intelligence across Cloudflare’s most sophisticated customer environments. This involves deep mastery of the full security stack from Magic Transit (Infrastructure Protection), Advanced TCP/DNS Protection, and Magic Firewall, to application-layer defenses including the WAF, Bot Management, API Security, and Rate Limiting. The role focuses on: Technical Mentorship: Elevating the team’s collective skill set by acting as a "player-coach," providing hands-on technical guidance during live incidents and reviewing complex mitigation strategies. Deep-Dive Investigation: Analyzing threats using advanced internal telemetry and dashboards to engineer informed mitigation strategies, often implementing these directly on the edge for mission-critical customer traffic. Infrastructure & Tooling Evolution: Partnering closely with Product and Engineering teams to transform real-world attack data into automated defenses and enhanced platform capabilities. Strategic Technical Communication: Serving as the authoritative technical voice during active attacks, providing clarity and architectural guidance to stakeholders. The ideal candidate would move beyond following runbooks to creating them, transforming raw security telemetry into actionable mitigation strategies and automated defenses.

Requirements

  • Experience: A minimum of 8 years of relevant hands-on experience in a Security Operations, Infrastructure Security, or a highly technical incident response environment.
  • Protocol Sovereignty: A profound understanding of internet protocols (TCP/IP, UDP, ICMP, BGP, and GRE) and the ability to deconstruct anycast traffic flows.
  • Security Mastery: Proven ability to mitigate complex attacks (e.g., volumetric DDoS, slowloris, SQLi, and Credential Stuffing) using edge-based security controls.
  • Tooling & Automation: Proficiency in Python, Go, or Bash to automate security workflows and integrate security monitoring tools via APIs.
  • Technical Writing: The ability to produce high-fidelity Root Cause Analysis (RCA) reports and technical briefings for sophisticated engineering audiences.
  • System Literacy: Experience with Prometheus/Grafana monitoring and querying large datasets via GraphQL or similar APIs to operationalize contextual security data.

Nice To Haves

  • Certifications: Advanced security credentials such as CISSP, CISM, or GIAC (GCIH, GCIA) are highly valued.

Responsibilities

  • Technical Escalation: Acting as the technical authority for the CMDC during complex security incidents, providing hands-on intervention when standard protocols are exceeded.
  • Technical Coaching: Mentoring the CMDC team on advanced traffic analysis and security best practices, ensuring a high technical bar across the CMDC.
  • Incident Architecture: Leading the technical response to large-scale, sophisticated threats (e.g., volumetric DDoS and protocol-based attacks) and validating the efficacy of mitigation rules.
  • Technical Communications: Driving high-touch technical dialogue with customer engineering teams during critical incidents, translating complex attack data into actionable architectural advice.
  • Operational Engineering: Designing and refining technical CMDC workflows, playbooks, and alerting thresholds to improve the team's detection and response capabilities.
  • Forensics & Analysis: Utilizing internal telemetry, GraphQL, and specialized monitoring tools to perform deep-dive forensics on novel attack vectors.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service