Senior SOC Engineer

Posted 12 Hours Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka
Hybrid
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Helping Build a Better Internet
The Role
Lead technical responses to sophisticated network and application-layer attacks, mentor the SOC team, perform deep forensic analysis using telemetry and GraphQL, implement edge-based mitigations, and partner with engineering to automate defenses and evolve tooling and playbooks.
Summary Generated by Built In
Available Locations: Bengaluru, India
About the Role
The Response Senior Engineer - CMDC serves as a high-tier technical lead within the proactive security team. This position is built for a practitioner who thrives at the intersection of deep protocol-level investigation and strategic technical partnership. The role is responsible for architecting responses to sophisticated threats across OSI Layers 3, 4, and 7, ensuring global customers remain resilient against large-scale DDoS attacks and complex application-layer anomalies.
Acting as a primary technical anchor, this individual provides advanced assistance and strategic intelligence across Cloudflare's most sophisticated customer environments. This involves deep mastery of the full security stack from Magic Transit (Infrastructure Protection), Advanced TCP/DNS Protection, and Magic Firewall, to application-layer defenses including the WAF, Bot Management, API Security, and Rate Limiting. The role focuses on:
  • Technical Mentorship: Elevating the team's collective skill set by acting as a "player-coach," providing hands-on technical guidance during live incidents and reviewing complex mitigation strategies.
  • Deep-Dive Investigation: Analyzing threats using advanced internal telemetry and dashboards to engineer informed mitigation strategies, often implementing these directly on the edge for mission-critical customer traffic.
  • Infrastructure & Tooling Evolution: Partnering closely with Product and Engineering teams to transform real-world attack data into automated defenses and enhanced platform capabilities.
  • Strategic Technical Communication: Serving as the authoritative technical voice during active attacks, providing clarity and architectural guidance to stakeholders.

The ideal candidate would move beyond following runbooks to creating them, transforming raw security telemetry into actionable mitigation strategies and automated defenses.
Key Responsibilities
  • Technical Escalation: Acting as the technical authority for the CMDC during complex security incidents, providing hands-on intervention when standard protocols are exceeded.
  • Technical Coaching: Mentoring the CMDC team on advanced traffic analysis and security best practices, ensuring a high technical bar across the CMDC.
  • Incident Architecture: Leading the technical response to large-scale, sophisticated threats (e.g., volumetric DDoS and protocol-based attacks) and validating the efficacy of mitigation rules.
  • Technical Communications: Driving high-touch technical dialogue with customer engineering teams during critical incidents, translating complex attack data into actionable architectural advice.
  • Operational Engineering: Designing and refining technical CMDC workflows, playbooks, and alerting thresholds to improve the team's detection and response capabilities.
  • Forensics & Analysis: Utilizing internal telemetry, GraphQL, and specialized monitoring tools to perform deep-dive forensics on novel attack vectors.

Qualifications
  • Experience: A minimum of 8 years of relevant hands-on experience in a Security Operations, Infrastructure Security, or a highly technical incident response environment.
  • Protocol Sovereignty: A profound understanding of internet protocols (TCP/IP, UDP, ICMP, BGP, and GRE) and the ability to deconstruct anycast traffic flows.
  • Security Mastery: Proven ability to mitigate complex attacks (e.g., volumetric DDoS, slowloris, SQLi, and Credential Stuffing) using edge-based security controls.
  • Tooling & Automation: Proficiency in Python, Go, or Bash to automate security workflows and integrate security monitoring tools via APIs.
  • Technical Writing: The ability to produce high-fidelity Root Cause Analysis (RCA) reports and technical briefings for sophisticated engineering audiences.
  • System Literacy: Experience with Prometheus/Grafana monitoring and querying large datasets via GraphQL or similar APIs to operationalize contextual security data.
  • Certifications: Advanced security credentials such as CISSP, CISM, or GIAC (GCIH, GCIA) are highly valued.

Top Skills

Python,Go,Bash,Prometheus,Grafana,Graphql,Magic Transit,Magic Firewall,Waf,Bot Management,Api Security,Rate Limiting,Tcp/Ip,Udp,Icmp,Bgp,Gre,Anycast
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
4,400 Employees
Year Founded: 2010

What We Do

Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company on a mission to help build a better Internet. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.

Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.

Why Work With Us

Cloudflare employees come from all walks of life. We are mission-driven, and our team is energized by a collaborative, creative environment that celebrates our differences and fosters new ways to grow together.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Cloudflare Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We are committed to developing a global team that is distributed with a flexible working approach. Doing this equitably and inclusively is essential to our success. Visit our careers site for more on 'How & Where We Work.'

Typical time on-site: Flexible
HQSan Francisco, CA
Singapore
Austin, TX
Bengaluru, Karnataka
Boston, MA
Champaign, IL
Denver, Colorado
Lisbon, PT
London, GB
Los Angeles, CA
New York, NY
Seattle, WA
Washington, DC
Learn more

Similar Jobs

Cloudflare Logo Cloudflare

Workday Functional Specialist

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4400 Employees
7-7 Annually

Cloudflare Logo Cloudflare

Workday Integration Specialist

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4400 Employees

Cloudflare Logo Cloudflare

Security Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4400 Employees

Cloudflare Logo Cloudflare

ProdSecOps Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
4400 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account