Response Engineer - Cloudflare Managed Defense Center (CMDC)

Cloudflare
London
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 4-7 yearsSkills: ["Analytical thinking","Incident response","Customer communication","Calm under pressure","Troubleshooting"]

Respond to complex threats for premium enterprise customers in the Cloudflare Managed Defense Center. Independently investigate threat telemetry and lead live incident response for volumetric DDoS and application-layer attacks, using customer-facing dashboards and internal tools to propose and sometimes implement mitigations. Continuously tune monitoring rules, manage customer incidents and runbooks, and collaborate with engineering and threat intelligence to improve tooling, detection logic, and security outcomes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cloudflare
Cloudflare
17 hours ago

Response Engineer - Cloudflare Managed Defense Center (CMDC)

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 10 hours agoStatus: Live

Job Summary

Respond to complex threats for premium enterprise customers in the Cloudflare Managed Defense Center. Independently investigate threat telemetry and lead live incident response for volumetric DDoS and application-layer attacks, using customer-facing dashboards and internal tools to propose and sometimes implement mitigations. Continuously tune monitoring rules, manage customer incidents and runbooks, and collaborate with engineering and threat intelligence to improve tooling, detection logic, and security outcomes.
Location: London
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Implement robust mitigations for complex attacks across OSI Layers 3, 4, and 7 using Cloudflare security products and controls.
  • •Monitor and investigate alerts using near real-time packet and traffic flow analysis and correlation to detect protocol exhaustion and application-layer exploitation.
  • •Review and prioritize alerts, escalate customer-impacting incidents, and meet Customer SLAs for response and customer communication.
  • •Serve as the primary technical contact during active incidents, coordinating with customer engineering teams via phone, chat, and email to neutralize threats while maintaining stable traffic delivery.
  • •Continuously tune monitoring rules and alert thresholds, lead customer onboarding sessions, maintain runbooks, and deliver security posture reviews and post-incident reports.

Key Requirements

  • •4–7 years hands-on experience in MDR, advanced Security Operations, or technical incident response for enterprise infrastructure.
  • •Proven application and network security expertise, including OWASP Top 10, L7 WAF, HTTP/S anomalies, bot mitigation, and L3/L4 volumetric DDoS/protocol abuse.
  • •Working knowledge of threat frameworks such as MITRE ATT&CK to classify adversary behavior for detection and mitigation.
  • •Strong operational understanding of internet protocols (TCP, UDP, ICMP, GRE, BGP, DNS) to diagnose attack fingerprints and infrastructure impact.
  • •Hands-on packet capture/traffic inspection experience (e.g., tcpdump, Wireshark, tshark, HAR, Burp Suite) and strong, high-stress customer communications for active incidents.
Experience:4-7 yearsCybersecurityMDRSecurity operations
Skills:Analytical thinkingIncident responseCustomer communicationCalm under pressureTroubleshooting
Certifications:GIAC (GCIA, GCIH, GCFA, GCFE)Cisco CCNACisco CCNP
Tech Stack:Cloudflare Managed Defense Center (CMDC)Cloudflare Managed DefenseMagic TransitMagic FirewallAdvanced TCP ProtectionAdvanced DNS ProtectionWAFCustom RulesIP Access RulesBot ManagementRate LimitingOSI Layer 3OSI Layer 4OSI Layer 7MITRE ATT&CKTCPUDPICMPGREBGP

Company Brief

Cloudflare
Provides a global network and cloud platform that delivers security, performance, and reliability services for web applications, APIs, and Internet properties, including CDN, DDoS protection, DNS, and zero-trust security solutions.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2009
WebsiteLinkedIn