About the role
Security Operations Center Engineers provide premium-level support for Cloudflare's security products and features. Our largest and most technically sophisticated customers will contact SOC for assistance and intelligence in dealing with threats or attacks on their infrastructure at OSI Layers 3, 4, and 7. This spans the range of Cloudflare security products from Magic Transit Infrastructure Protection, DDoS mitigation (including Advanced TCP Protection and Advanced DNS Protection), and Magic Firewall, to using the Web Application Firewall (WAF), Spectrum, Bot Management, API Security, and Rate Limiting to help customers.
Security Operations Center Analysts/Engineers analyze threats using customer-facing dashboards and internal tools, make detailed and informed suggestions for mitigation, and may implement mitigation strategies directly on behalf of the customer with appropriate approval. The team provides 24x7x365 proactive monitoring via our internal alerting systems, near real-time analysis of security events, and attack reporting beyond Cloudflare's self-service reports.
Responsibilities
- Monitor and investigate proactive alerts to identify attacks
- Work with Engineering and Operations teams to mitigate attacks, suggest steps to mitigate, and apply the appropriate mitigation when applicable
- Work with Engineering and Product teams to improve products and tools
- Communicate with customers via chat, email, and phone
- Review alerts to determine relevancy and urgency; create tracking tickets for incidents requiring review or escalation
- Adhere to SOC SLAs for alert response and customer communication
- Configure and manage security monitoring rules; contribute to tool and threshold improvements
- DDoS mitigation for OSI Layers 3, 4, & 7: filter malicious traffic using Cloudflare tools including Magic Transit, Magic Firewall, Advanced TCP Protection, WAF, Custom Rules, IP Access Rules, and Rate Limiting
- Maintain customer-specific SOC runbooks and escalation matrices
- Support SOC customer onboarding and deliver monthly security reviews
Key Skill Sets
- Strong understanding of internet protocols (TCP, UDP, ICMP, GRE, BGP)
- Networking fundamentals are crucial for success
- Analysis of traffic for attack anomaly detection and creation of mitigation rules
- Experience handling attack mitigation with knowledge of L3/4 and L7 attacks
- Command line / Bash shell proficiency
- Customer Facing or Technical support experience is mandatory
- Strong communication skills, including with VIP customers during active attacks
- Ability to remain calm under pressure
- Ability to work 24x7 rotating shifts
- Sysadmin skills - Linux, Mac, or Windows (Preferred)
- Knowledge of Cloudflare Security Products & Features (Preferred)
- Scripting skills, Python preferred (Preferred)
- Prometheus/Grafana monitoring experience (Preferred)
- Packet capture tools such as tcpdump or Wireshark (Preferred)
- API/GraphQL experience (Nice to have)
- Security certifications: GCIA, GCIH, GCFA, GCFE, CISSP equivalent (Strongly preferred)
- Network certifications: CCNA, CCNP (Nice to have)
Top Skills
What We Do
Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company on a mission to help build a better Internet. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.
Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.
Why Work With Us
Cloudflare employees come from all walks of life. We are mission-driven, and our team is energized by a collaborative, creative environment that celebrates our differences and fosters new ways to grow together.
Gallery
Cloudflare Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We are committed to developing a global team that is distributed with a flexible working approach. Doing this equitably and inclusively is essential to our success. Visit our careers site for more on 'How & Where We Work.'