AI Security Research & Red Team EngineerPosted today$166K–$208K

Hybrid · HybridTechnology

The opportunity

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.

What you'll do

  • AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflare’s products and services.

  • Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively.

  • Adversary Simulation: Execution of full-chain red team operations targeting Cloudflare’s global infrastructure, corporate networks, and product ecosystems.

  • Efficacy Testing: Establish a rigorous framework for testing "Security Efficacy"—measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures).

  • Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements.

  • Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflare’s security posture.

What they're looking for

  • Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most.
  • Security Incident Response Team (SIRT): You will act as the "sparring partner" for SIRT. By conducting unannounced exercises, you help them refine their playbooks, test their on-call rotations, and ensure their forensic tooling is effective under pressure.
  • Threat Detection & Threat Engineering: You will partner closely with these teams to bridge the gap between adversary simulation and defensive coverage. You will proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks to test and tune detections against emerging TTPs.
  • Product Engineering/SRE: We operate as "Customer Zero" of our own products, your red teaming findings will drive resilience in processes and implementations, ultimately making Cloudflare and its customers more secure.
AI Security Research & Red Team Engineer at Cloudflare | Role Match