Product Security EngineerActive

The opportunity

As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are…

What you'll do

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to help automate code analysis, optimize triage, and streamline Product Security workflows.

  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features, defining security requirements early in the development lifecycle.

  • Product Vulnerability Management: Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation in alignment with established SLAs.

  • Bug Bounty Triage: Perform the technical triage and validation of Cloudflare’s external Bug Bounty submissions, verifying exploitability and evaluating business risk.

  • Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies.

  • Engineering Collaboration: Partner closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices.

What they're looking for

  • Product/AppSec Expertise: 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Threat Modeling & Risk Analysis: Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact.
  • Vulnerability Lifecycle Operations: Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs.