← Back to results

Product Security Engineer

Join Cloudflare as a Product Security Engineer to enhance security assessments and automate vulnerability operations in a dynamic environment.

Location
Hybrid
Compensation
Not disclosed
Level
senior
Type
full time · On-site

Posted by employer 2 months ago

First seen on Joblaze 2 months ago

Last verified on the company career page 6 hours ago

AI in the day-to-day

You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment.

Requirements

Experience
5+ years

Not disclosed in this posting: compensation, visa sponsorship.

Benefits

401k Match Flexible Paid Time Off Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

In the role of Product Security Engineer at Cloudflare, the individual will conduct security assessments and manage vulnerabilities for the company's software products, ensuring that security findings are effectively triaged and addressed. Key skills include expertise in application security, automation engineering, and threat modeling, with a strong emphasis on leveraging AI tools to enhance workflows. This position is ideal for seasoned professionals with a background in systems security and a collaborative mindset, as they will work closely with engineering teams to implement secure coding practices.

Joblaze insights

  • Listed about 2 months ago — first seen on Joblaze August 5, 2026. Last confirmed on Cloudflare's careers page October 8, 2026.
  • AI/ML appears in 7.4% of 323 comparable senior security roles in United States; Automation appears in 0.6% of 323 comparable senior security roles in United States.

Quick facts

Is the Product Security Engineer role remote?
No — this is an on-site role in Hybrid.
How much experience is required?
At least 5 years of relevant experience for this Product Security Engineer role.
Where is the role based?
Cloudflare is hiring for this position in Hybrid.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI/ML, Automation, Threat Modeling, Vulnerability Management, security.
What seniority level is this role?
Cloudflare targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Product Security Engineer role at Cloudflare.

From the original posting

About Us

Available Locations: Austin (US), London (UK)

Role Summary

As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.

On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Responsibilities

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to help automate code analysis, optimize triage, and streamline Product Security workflows.
  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features, defining security requirements early in the development lifecycle.
  • Product Vulnerability Management: Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation in alignment with established SLAs.
  • Bug Bounty Triage: Perform the technical triage and validation of Cloudflare’s external Bug Bounty submissions, verifying exploitability and evaluating business risk.
  • Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies.
  • Engineering Collaboration: Partner closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices.

Desirable Skills, Knowledge, and Experience

  • Product/AppSec Expertise: 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Threat Modeling & Risk Analysis: Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact.
  • Vulnerability Lifecycle Operations: Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs.
  • Strong Collaboration & Communication: Ability to collaborate effectively across teams, clearly communicating technical security risks to software engineers and resolving ownership ambiguity constructively.

Bonus points

  • Offensive Security Tooling: Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun! The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

Standard company text repeated across Cloudflare's postings is omitted here.

Similar positions

Cloudflare
Cloudflare
Cloudflare
Systems Engineer
Cloudflare · Hybrid
Cloudflare