Senior Product Security Engineer

Cloudflare
Austin, London
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Cross-functional leadership","Communication","Mentorship","Analytical mindset","Autonomous problem-solving"]

Lead security assessments and vulnerability operations for Cloudflare’s core software products. You’ll perform security architecture reviews and threat modeling, triage and route product security findings to the right engineering owners, and drive remediation within SLAs. Work across sources including bug bounties, SAST, fuzzing, and penetration tests, while building AI/LLM-powered automation to scale triage and data enrichment. Mentor engineers and champion security best practices.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
1 month ago

Senior Product Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Lead security assessments and vulnerability operations for Cloudflare’s core software products. You’ll perform security architecture reviews and threat modeling, triage and route product security findings to the right engineering owners, and drive remediation within SLAs. Work across sources including bug bounties, SAST, fuzzing, and penetration tests, while building AI/LLM-powered automation to scale triage and data enrichment. Mentor engineers and champion security best practices.
Location: Austin, London
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Autonomously identify gaps and architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale product security workflows.
  • •Conduct deep-dive security reviews and complex threat modeling across distributed systems, embedding security requirements into product designs before development.
  • •Own the lifecycle of product security findings by triaging, routing to correct engineering owners, and ensuring mitigation within established SLAs.
  • •Oversee technical triage and validation for Cloudflare’s external Bug Bounty program, prioritizing submissions by exploitability and business risk.
  • •Shape the scope of internal and external penetration testing engagements and serve as the technical liaison to ensure findings are understood and remediated by development teams.

Pay and Benefits

Equity and Bonus:Equity
Perks:Health InsuranceDentalVision401kPaid LeaveFertility Benefits

Key Requirements

  • •Extensive Product/Application Security experience in large-scale distributed cloud environments or SaaS platforms.
  • •Hands-on ability to build production-grade automation using AI/LLMs to solve operational or technical challenges.
  • •Mastery of threat modeling methodologies (e.g., STRIDE) and translating theoretical risks into prioritized, actionable business context.
  • •Proven experience owning the vulnerability lifecycle—managing, routing, and driving remediation across multiple engineering stakeholders while enforcing SLAs.
  • •Strong cross-functional communication skills to influence senior engineering leaders and resolve ownership ambiguity without formal authority.
Experience:CybersecurityProduct securityApplication securityDistributed systemsSaaSVulnerability research
Skills:Cross-functional leadershipCommunicationMentorshipAnalytical mindsetAutonomous problem-solving
Languages:English
Tech Stack:AILLMsCode analysisThreat modelingSTRIDESASTFuzzingPenetration testsBug bountiesBug bounty triageVulnerability triageHackerOneBugcrowdJIRAAI security automation

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn