AI Security Research & Red Team Engineer

Cloudflare
New York, Austin
Workplace: HybridFull timeUSD 166,000 - 208,000 annuallyFunction: Research & Scientific (R&D)Experience: 4+ yearsSkills: ["Technical leadership","Communication","Collaboration","Ethical hacking","Risk-based thinking"]

Join the Red Team within Cloudflare’s Security Threat Detection, Response and Emulation org to conduct AI-focused security research and adversary simulation. You’ll perform agentic and LLM attack testing, execute full-chain red team operations across infrastructure and products, and validate detection efficacy of WAF/EDR/SIEM against real TTPs. Partner with Blue Team for purple teaming and deliver risk-based executive reporting while mentoring and driving continuous security improvements.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
14 hours ago

AI Security Research & Red Team Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Join the Red Team within Cloudflare’s Security Threat Detection, Response and Emulation org to conduct AI-focused security research and adversary simulation. You’ll perform agentic and LLM attack testing, execute full-chain red team operations across infrastructure and products, and validate detection efficacy of WAF/EDR/SIEM against real TTPs. Partner with Blue Team for purple teaming and deliver risk-based executive reporting while mentoring and driving continuous security improvements.
Location: New York, Austin
Workplace: Hybrid
Employment Type: Full time
Job Function: Research & Scientific (R&D)
Seniority: Mid level

Key Responsibilities

  • •Conduct AI security and vulnerability research, identifying AI-specific vulnerabilities and risks across products and services.
  • •Run agentic testing and adoption to identify AI-related attack surfaces and define requirements and implementation guidance.
  • •Execute full-chain red team operations targeting Cloudflare’s infrastructure, corporate networks, and product ecosystems.
  • •Establish and run an efficacy testing framework to measure how well WAF/EDR/SIEM detections perform against known TTPs.
  • •Collaborate in purple teaming with the Blue Team and translate findings into risk-based narratives for leadership; mentor others and act as a sparring partner for SIRT.

Pay and Benefits

Salary: USD 166,000 - 208,000 annually
Equity and Bonus:Equity

Key Requirements

  • •4+ years of experience in offensive security, application security, or a relevant field.
  • •Deep knowledge of AI, coding agents, LLMs, prompt engineering, and AI attack vectors such as prompt injection and jailbreaking.
  • •Background in manual penetration testing, exploit development, or cloud security (AWS, GCP, or bare metal).
  • •Experience using the MITRE ATT&CK framework to map defensive coverage and identify blind spots in telemetry.
  • •Ability to communicate complex “0-day” exploits to non-technical stakeholders and partner effectively with engineering teams.
Experience:4+ yearsOffensive securityApplication securityAI securityRed teamingCloud security
Skills:Technical leadershipCommunicationCollaborationEthical hackingRisk-based thinking
Tech Stack:AILLMsPrompt engineeringAgentsPrompt injectionJailbreakingMITRE ATT&CKWAFEDRSIEMBAS toolsPayload deliveryC2 infrastructureAWSGCPExploit developmentPenetration testing

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn