About the Role
The Response Senior Engineer - CMDC serves as a high-tier technical lead within the proactive security team. This position is built for a practitioner who thrives at the intersection of deep protocol-level investigation and strategic technical partnership. The role is responsible for architecting responses to sophisticated threats across OSI Layers 3, 4, and 7, ensuring global customers remain resilient against large-scale DDoS attacks and complex application-layer anomalies.
Acting as a primary technical anchor, this individual provides advanced assistance and strategic intelligence across Cloudflare's most sophisticated customer environments. This involves deep mastery of the full security stack from Magic Transit (Infrastructure Protection), Advanced TCP/DNS Protection, and Magic Firewall, to application-layer defenses including the WAF, Bot Management, API Security, and Rate Limiting. The role focuses on:
- Technical Mentorship: Elevating the team's collective skill set by acting as a "player-coach," providing hands-on technical guidance during live incidents and reviewing complex mitigation strategies.
- Deep-Dive Investigation: Analyzing threats using advanced internal telemetry and dashboards to engineer informed mitigation strategies, often implementing these directly on the edge for mission-critical customer traffic.
- Infrastructure & Tooling Evolution: Partnering closely with Product and Engineering teams to transform real-world attack data into automated defenses and enhanced platform capabilities.
- Strategic Technical Communication: Serving as the authoritative technical voice during active attacks, providing clarity and architectural guidance to stakeholders.
The ideal candidate would move beyond following runbooks to creating them, transforming raw security telemetry into actionable mitigation strategies and automated defenses.
Key Responsibilities
- Technical Escalation: Acting as the technical authority for the CMDC during complex security incidents, providing hands-on intervention when standard protocols are exceeded.
- Technical Coaching: Mentoring the CMDC team on advanced traffic analysis and security best practices, ensuring a high technical bar across the CMDC.
- Incident Architecture: Leading the technical response to large-scale, sophisticated threats (e.g., volumetric DDoS and protocol-based attacks) and validating the efficacy of mitigation rules.
- Technical Communications: Driving high-touch technical dialogue with customer engineering teams during critical incidents, translating complex attack data into actionable architectural advice.
- Operational Engineering: Designing and refining technical CMDC workflows, playbooks, and alerting thresholds to improve the team's detection and response capabilities.
- Forensics & Analysis: Utilizing internal telemetry, GraphQL, and specialized monitoring tools to perform deep-dive forensics on novel attack vectors.
Qualifications
- Experience: A minimum of 8 years of relevant hands-on experience in a Security Operations, Infrastructure Security, or a highly technical incident response environment.
- Protocol Sovereignty: A profound understanding of internet protocols (TCP/IP, UDP, ICMP, BGP, and GRE) and the ability to deconstruct anycast traffic flows.
- Security Mastery: Proven ability to mitigate complex attacks (e.g., volumetric DDoS, slowloris, SQLi, and Credential Stuffing) using edge-based security controls.
- Tooling & Automation: Proficiency in Python, Go, or Bash to automate security workflows and integrate security monitoring tools via APIs.
- Technical Writing: The ability to produce high-fidelity Root Cause Analysis (RCA) reports and technical briefings for sophisticated engineering audiences.
- System Literacy: Experience with Prometheus/Grafana monitoring and querying large datasets via GraphQL or similar APIs to operationalize contextual security data.
- Certifications: Advanced security credentials such as CISSP, CISM, or GIAC (GCIH, GCIA) are highly valued.
Top Skills
What We Do
Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company on a mission to help build a better Internet. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.
Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.
Why Work With Us
Cloudflare employees come from all walks of life. We are mission-driven, and our team is energized by a collaborative, creative environment that celebrates our differences and fosters new ways to grow together.
Gallery
Cloudflare Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We are committed to developing a global team that is distributed with a flexible working approach. Doing this equitably and inclusively is essential to our success. Visit our careers site for more on 'How & Where We Work.'