Join Cloudflare as a senior AI Security Research & Red Team Engineer to enhance security against AI-related threats.
Posted by employer 1 month ago
First seen on Joblaze 1 month ago
Last verified on the company career page 20 hours ago
Not disclosed in this posting: work arrangement, visa sponsorship.
Joblaze summary
In the role of AI Security Research & Red Team Engineer at Cloudflare, the individual will engage in proactive security research and simulate real-world attacks to enhance the company's defenses against emerging threats. Key skills include expertise in AI vulnerabilities, penetration testing, and familiarity with the MITRE ATT&CK framework. This position is ideal for someone with over four years of experience in offensive security, particularly those who thrive in a collaborative environment focused on continuous improvement. The role emphasizes a culture of curiosity and ethical hacking, contributing to Cloudflare's mission of building a safer Internet.
Quick facts
- What's the salary range?
- Cloudflare lists $166,000–$208,000 for this role.
- How much experience is required?
- At least 4 years of relevant experience for this AI Security Research & Red Team Engineer role.
- What's the tech stack?
- Joblaze extracted these technologies from the posting: AI, Agentic concepts, Breach and Attack Simulation, EDR, LLMs, MITRE ATT&CK.
- What seniority level is this role?
- Cloudflare targets senior candidates for this position.
- Is this full-time or contract?
- Full-time for this AI Security Research & Red Team Engineer role at Cloudflare.
From the original posting
About Us
The Role:
We are seeking a highly skilled AI Security Research & Red team engineer to join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvements in Cloudflare’s security posture focusing on AI, Agents, harnesses and LLM’s.
Key Responsibilities:
- AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflare’s products and services.
- Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively.
- Adversary Simulation: Execution of full-chain red team operations targeting Cloudflare’s global infrastructure, corporate networks, and product ecosystems.
- Efficacy Testing: Establish a rigorous framework for testing "Security Efficacy"—measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures).
- Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements.
- Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflare’s security posture.
- Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most.
Partnerships
- Security Incident Response Team (SIRT): You will act as the "sparring partner" for SIRT. By conducting unannounced exercises, you help them refine their playbooks, test their on-call rotations, and ensure their forensic tooling is effective under pressure.
- Threat Detection & Threat Engineering: You will partner closely with these teams to bridge the gap between adversary simulation and defensive coverage. You will proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks to test and tune detections against emerging TTPs.
- Product Engineering/SRE: We operate as "Customer Zero" of our own products, your red teaming findings will drive resilience in processes and implementations, ultimately making Cloudflare and its customers more secure.
- Governance, Risk, and Compliance (GRC): You will bridge the gap between "paper security" and "technical reality." By providing empirical evidence of control effectiveness, you help GRC move away from manual audits and toward continuous, automated compliance validation.
Required Qualifications:
- Experience: 4+ years in offensive security, application security or other relevant field
- Deep knowledge: AI, Coding agents, LLMs, prompt engineering, AI-related attack vectors (e.g., prompt injection, jailbreaking), and Agentic concepts all for use in the red team but also testing Cloudflare uses.
- Technical Roots: A strong background in manual penetration testing, exploit development, or cloud security (AWS/GCP/Bare Metal).
- Operational Mindset: Experience using the MITRE ATT&CK framework to map coverage and identify "blind spots" in defensive telemetry.
- Communication Skills: The ability to explain a complex "0-day" exploit to a non-technical stakeholder while maintaining the respect of a deep-dive engineering team.
- Tooling Familiarity: Knowledge of automated breach and attack simulation (BAS) tools, as well as custom-built frameworks for payload delivery and C2 infrastructure.
Compensation
Compensation may be adjusted depending on work location.
- For New York based hires: Estimated annual salary of $166,000 - $208,000.
Equity
This role is eligible to participate in Cloudflare’s equity plan.
What Makes Cloudflare Special?
Standard company text repeated across Cloudflare's postings is omitted here.