Incident Response Analyst - ReactActive

The opportunity

Cloudflare is a system spanning the globe, on a mission to make the internet safer and more powerful everyday. To help fulfill this mission, we are seeking a talented Incident Response Analyst to join us in growing our Cloudforce One REACT organization.

What you'll do

  • Active Edge Mitigation: Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability. This includes deploying custom WAF rules, implementing L3/L4 DDoS shunning, and performing real-time traffic filtering to neutralize attacks before they reach the customer's origin.

  • Support Full IR Lifecycle Management: Support and execute the end-to-end incident response process for clients (investigation, containment, remediation, and recovery). Review technical deliverables and coordinate sessions with customer stakeholders to ensure high-quality service and resolution.

  • Incident Remediation: Build a strong understanding of targeted attacks to create and execute customized tactical and strategic remediation plans for compromised organizations.

  • Education: Bachelor's degree in Computer Science, Information Systems,: Cybersecurity, a related technical field, or equivalent training/practical experience.

  • Experience: 5+ years of overall experience in cybersecurity, including 2+: years of dedicated Incident Response OS & Cloud Environments: In-depth understanding of Windows operating systems and general knowledge of Unix, Linux, and Mac environments. Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies.

  • Network and Web Attack Knowledge: Strong understanding of common L3/L4/L7 attack patterns, including SYN floods, UDP floods, DNS amplification, HTTP floods, credential stuffing, scraping, API abuse, account enumeration, and checkout abuse.

What they're looking for

  • Experience with JA3/JA4 fingerprinting, bot detection, behavioral traffic: analysis, or API abuse investigations.
  • Experience supporting customers during live DDoS, bot, or application-layer attack events.
  • Solid understanding of MITRE ATT&CK and NIST Cyber Security Frameworks.
  • Communications: English Fluency, Excellent verbal and written communication skills with a proven ability to establish relationships and clearly explain tasks, guidance, and complex technical findings to executive and technical clients.