Product Security Engineer

Cloudflare
Austin
Workplace: HybridFull timeFunction: CybersecurityExperience: 5+ yearsSkills: ["Collaboration","Communication","Autonomy","Risk analysis"]

Support security assessments and vulnerability operations for Cloudflare’s core software products. You’ll analyze system architecture and threat model new features, triage and route security findings to the right engineering owners, and drive mitigations within SLAs. Day to day, you’ll review feature designs, validate bug bounty submissions, coordinate pentests, and collaborate with engineering teams. You’ll also build AI/LLM-assisted automation to scale triage and data enrichment.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
1 day ago

Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Support security assessments and vulnerability operations for Cloudflare’s core software products. You’ll analyze system architecture and threat model new features, triage and route security findings to the right engineering owners, and drive mitigations within SLAs. Day to day, you’ll review feature designs, validate bug bounty submissions, coordinate pentests, and collaborate with engineering teams. You’ll also build AI/LLM-assisted automation to scale triage and data enrichment.
Location: Austin
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Build AI-driven tools or scripts to automate code analysis, optimize triage, and streamline Product Security workflows.
  • •Conduct structured security reviews and threat modeling sessions across product features, defining security requirements early in development.
  • •Manage the operational lifecycle of product security findings, ensuring verification, correct owner mapping, and SLA-aligned mitigation.
  • •Perform technical triage and validation of external Bug Bounty submissions, verifying exploitability and evaluating business risk.
  • •Support internal and external penetration testing engagements by reviewing findings and helping teams with remediation strategies.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kPaid LeaveParental LeaveDisability InsuranceLife Insurance

Key Requirements

  • •5+ years of experience in Product or Application Security in large-scale distributed cloud environments or SaaS platforms.
  • •Hands-on experience building production-grade automation scripts and tools, including using AI/LLMs to solve operational or technical challenges.
  • •Competency in threat modeling methodologies and evaluating code flaws to determine engineering and security impact.
  • •Experience tracking, routing, and driving remediation of software vulnerabilities across engineering groups while working against defined SLAs.
  • •Ability to collaborate across teams and clearly communicate security risks to software engineers, resolving ownership ambiguity constructively.
Experience:5+ yearsCloud securitySaaSProduct securityVulnerability management
Skills:CollaborationCommunicationAutonomyRisk analysis
Languages:English
Tech Stack:AILLMSTRIDESASTFuzzingPenetration testingBug bountyHackerOneBugcrowdJIRA

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn