Senior Incident Response Analyst - REACT

Cloudflare
Lisbon
Workplace: HybridFull timeEUR 54,000 - 75,000 annuallyFunction: Solutions Engineering & Sales EngineeringExperience: 3+ yearsEducation: bachelorsSkills: ["Detail-oriented","Self-starting","Problem-solving","Communication","Relationship-building","Triaging"]

Build a proactive, threat-intelligence-driven incident response program within Cloudflare’s Cloudforce One REACT team. You’ll respond to customer security incidents across on-prem, cloud, and hybrid environments—mitigating threats at the Cloudflare edge, containing attackers, and executing end-to-end IR lifecycle activities. Collaborate with forensic analysts and detection teams to preserve evidence, deliver crisis solutions aligned to ISO 27001/NIST/CIS, and produce high-fidelity incident reporting enhanced by AI-powered analysis.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
1 month ago

Senior Incident Response Analyst - REACT

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Build a proactive, threat-intelligence-driven incident response program within Cloudflare’s Cloudforce One REACT team. You’ll respond to customer security incidents across on-prem, cloud, and hybrid environments—mitigating threats at the Cloudflare edge, containing attackers, and executing end-to-end IR lifecycle activities. Collaborate with forensic analysts and detection teams to preserve evidence, deliver crisis solutions aligned to ISO 27001/NIST/CIS, and produce high-fidelity incident reporting enhanced by AI-powered analysis.
Location: Lisbon
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Execute active edge mitigation to protect customer availability using custom WAF rules, L3/L4 DDoS shunning, and real-time traffic filtering.
  • •Support end-to-end incident response lifecycle for clients, including investigation, containment, remediation, and recovery, and coordinate with customer stakeholders.
  • •Create and execute tailored incident remediation plans for compromised organizations.
  • •Conduct forensic evidence preservation (logs, volatile memory, disk images) following forensic standards and support legal/regulatory/insurance needs.
  • •Develop and enhance client-facing crisis and incident response solutions aligned to ISO 27001, NIST, and CIS; produce incident reports and communications with AI-assisted analysis.

Pay and Benefits

Salary: EUR 54,000 - 75,000 annually
Equity and Bonus:Equity

Key Requirements

  • •3+ years of cybersecurity experience, including 2+ years of Incident Response / Digital Forensics and 1+ year in a customer-facing role.
  • •Strong knowledge of Windows and general familiarity with Unix, Linux, and Mac environments, plus cloud IR experience across AWS, Azure, O365, Google Cloud, or Cloudflare.
  • •Network forensic skills covering protocols and design patterns such as TCP/IP, HTTPS, FTP/SFTP, SSH, RDP, CIFS/SMB, and NFS, including experience with Bro/Zeek or Suricata and network log analysis.
  • •Solid understanding of MITRE ATT&CK and NIST Cyber Security Frameworks.
  • •Bachelor’s degree in Computer Science/Information Systems/Cybersecurity (or equivalent training/practical experience).
Experience:3+ yearsCybersecurityIncident responseDigital forensicsCustomer-facing
Education:Bachelor's in Computer Science, Information Systems, Cybersecurity
Skills:Detail-orientedSelf-startingProblem-solvingCommunicationRelationship-buildingTriaging
Languages:English
Tech Stack:WAFDDoS shunningL3L4Real-time traffic filteringWindowsUnixLinuxMacAWSAzureO365Google CloudCloudflareISO 27001NISTCISAILog summarizationTCP/IP

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn