Response Engineer - Cloudflare Managed Defense Center (CMDC)New
The opportunity
The Response Engineer within the Cloudflare Managed Defense Center acts as a primary technical responder for Cloudflare's premium enterprise customers. You will autonomously investigate complex threat telemetry, handle live incident response for sophisticated volumetric DDoS and…
What you'll do
PhishGuard: Email Managed Detection and Response (MDR) service.
Cloudflare Managed Defense (CMD, Formerly SOCaaS): 24/7 monitoring, detection, and mitigation of security events across Cloudflare products.
Detection Engineering: Develops, maintains, and deploys Cloudflare’s threat detection logic across email, application, and network telemetry.
Implement robust mitigation strategies for complex attacks across OSI Layers: 3, 4, and 7 using Cloudflare's suite (Magic Transit, Magic Firewall, Advanced TCP Protection, Advanced DNS Protection, WAF, Custom Rules, IP Access Rules, Bot Management, and Rate Limiting)
Monitor and investigate proactive alerts, performing near real-time packet: and traffic flow analysis and correlation to detect protocol exhaustion and application-layer exploitation, translating findings into custom, highly targeted mitigation rules
Review alerts to determine relevancy and urgency, proactively escalate: customer-impacting incidents, and adhere to Customer SLAs for alert response and customer communication
What they're looking for
- Act as the primary technical contact for customers during active security: incidents, driving high-touch, consultative communication (via phone, chat, email) with customers' technical engineering teams to neutralize threats while ensuring stable traffic delivery
- Continuously tune and optimize existing security monitoring rules and: alerting thresholds to improve the operational signal-to-noise ratio and reduce false positives
- Lead managed customer onboarding sessions, maintain customer-specific: runbooks, and deliver highly technical monthly security posture reviews and post-incident reports
- Partner directly with internal engineering, product, and threat intelligence: teams to provide actionable feedback on attack trends, tooling gaps, and product enhancements