← Back to results

Vulnerability Defense Software Engineer, Cloudforce One

Join Cloudflare as a Vulnerability Defense Software Engineer to build scalable systems that enhance internet security.

Location
Washington D.C., District of Columbia, United States
Compensation
$150k–$206k/yr
Level
mid
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 5 hours ago

Last verified on the company career page 5 hours ago

What you'll build

  • Design, build, run, and scale distributed tools and services
  • Partner with security practitioners to understand workflows
  • Improve system design and architecture
  • Analyze and communicate complex technical concepts
  • Mentor and guide other developers

Must have

  • At least 5 years of experience building large-scale software applications
  • Prior experience writing production-ready code in Go and/or TypeScript
  • Working knowledge of cybersecurity concepts
  • Experience designing and integrating RESTful APIs and/or gRPC services

Nice to have

  • Application security experience
  • Deep understanding of DNS, TLS/SSL and HTTP
  • Experience evaluating probabilistic systems

Practical constraints

  • This role may require flexibility to be on-call outside of standard working hours

Role intensity

70% hands-on coding

AI in the day-to-day

We leverage AI to ship faster today to make it better tomorrow.

Requirements

Experience
5+ years
Visa
No sponsorship (stated in posting)

Benefits

401k Match Flexible Paid Time Off Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

In the role of Vulnerability Defense Software Engineer at Cloudflare, the individual will focus on developing and enhancing systems that assist security teams in assessing risks and prioritizing vulnerabilities. Proficiency in programming languages such as Go and TypeScript, along with experience in distributed systems and cybersecurity concepts, is essential. This position is well-suited for seasoned engineers with a strong background in software development and a keen interest in security practices. The team operates within Cloudflare's threat operations, leveraging extensive data to combat cyber threats effectively.

Joblaze insights

  • Listed today — first seen on Joblaze October 4, 2026. Last confirmed on Cloudflare's careers page October 4, 2026.
  • Salary band is below the typical range for Security roles (median ~$170,000).
  • Starts above 61% of 23 comparable mid security roles in United States that list Go we track (median $143,700 across 10 companies). See Go salary trends
  • Go appears in 17.6% of 199 comparable mid security roles in United States; Kafka appears in 0.5% of 199 comparable mid security roles in United States.

Quick facts

Is the Vulnerability Defense Software Engineer, Cloudforce One role remote?
It's hybrid — Cloudflare expects some on-site time in Washington D.C., District of Columbia, United States.
What's the salary range?
Cloudflare lists $150,000–$206,000 for this role.
How much experience is required?
At least 5 years of relevant experience for this Vulnerability Defense Software Engineer, Cloudforce One role.
Where is the role based?
Cloudflare is hiring for this position in Washington D.C., District of Columbia, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: Go, Kafka, Kubernetes, PostgreSQL, Redis, Rust.
What seniority level is this role?
Cloudflare targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Vulnerability Defense Software Engineer, Cloudforce One role at Cloudflare.

From the original posting

About Us

Available Locations: Austin,TX and Washington, D.C.

Role Summary

Cloudforce One is Cloudflare’s threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world’s largest global networks can provide. The team is able to analyze these unique data points, at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers.

As a Software Engineer on this team, you build and evolve systems that help security practitioners assess technical risk, investigate complex systems, prioritize issues, and deliver actionable guidance to engineering teams. You will be responsible for translating complex security requirements and investigative methods into robust, scalable, and high-performance applications that have a direct impact on making the internet better, safer, and more powerful every day.

Role Responsibilities

While the majority of our services are now written in Go and TypeScript, you will also work with technologies such as Rust, Kafka, Redis, Kubernetes, Terraform, and PostgreSQL. We also pride ourselves in dogfooding our own products and services so you will be extensively working with Cloudflare’s developer platform as well. We are looking for great engineers regardless of experience with any of these specific technologies.

Responsibilities include:

  • Design, build, run, and scale distributed tools and services that translate security tradecraft into scalable, evidence-based systems and workflows.
  • Partner with security practitioners to understand workflows, bottlenecks, and opportunities for automation.
  • Improve system design and architecture to ensure stability, performance, and maintainability of both internal and customer-facing services.
  • Analyze, communicate, and help prioritize complex technical concepts across teams.
  • Mentor and guide other developers in the team, helping to build collective technical expertise and promote best practices for writing well-tested, modular, and reusable code.

This role may require flexibility to be on-call outside of standard working hours to address technical issues as needed.

Desirable Skills and Experience

  • Working knowledge of cybersecurity concepts such as threat modeling, attack techniques, trust boundaries, exploitability, and defensive controls
  • Familiarity with incident response workflows, network containment, and remediation
  • Practical experience in vulnerability research/exploit development and translating findings into actionable mitigations
  • Experience with AI-assisted development and designing agentic AI workflows
  • At least 5 years of experience building large-scale software applications, preferably distributed systems
  • Experience designing and integrating RESTful APIs and/or gRPC services
  • Knowledge of SQL and common relational database systems such as PostgreSQL
  • Ability to independently define and deliver solutions in ambiguous problem spaces
  • Prior experience writing production-ready code in Go and/or TypeScript
  • Excellent debugging and optimization skills
  • Expertise in writing well-tested code
  • Interest in opportunities to be a technical mentor for teammates

Bonus/Nice-to-Have Skills

  • Application security, security research, or security automation experience
  • Deep understanding of DNS, TLS/SSL and HTTP
  • Experience evaluating probabilistic systems

Compensation

Compensation may be adjusted depending on work location.

  • For Washington D.C. based hires: Estimated annual salary of $150,000 - $206,000

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun! The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

Standard company text repeated across Cloudflare's postings is omitted here.

Similar positions