Response Engineer - Cloudflare Managed Defense Center (CMDC)New

The opportunity

The Response Engineer within the Cloudflare Managed Defense Center acts as a primary technical responder for Cloudflare's premium enterprise customers. You will autonomously investigate complex threat telemetry, handle live incident response for sophisticated volumetric DDoS and…

What you'll do

  • PhishGuard: Email Managed Detection and Response (MDR) service.

  • Cloudflare Managed Defense (CMD, Formerly SOCaaS): 24/7 monitoring, detection, and mitigation of security events across Cloudflare products.

  • Detection Engineering: Develops, maintains, and deploys Cloudflare’s threat detection logic across email, application, and network telemetry.

  • Implement robust mitigation strategies for complex attacks across OSI Layers: 3, 4, and 7 using Cloudflare's suite (Magic Transit, Magic Firewall, Advanced TCP Protection, Advanced DNS Protection, WAF, Custom Rules, IP Access Rules, Bot Management, and Rate Limiting)

  • Monitor and investigate proactive alerts, performing near real-time packet: and traffic flow analysis and correlation to detect protocol exhaustion and application-layer exploitation, translating findings into custom, highly targeted mitigation rules

  • Review alerts to determine relevancy and urgency, proactively escalate: customer-impacting incidents, and adhere to Customer SLAs for alert response and customer communication

What they're looking for

  • Act as the primary technical contact for customers during active security: incidents, driving high-touch, consultative communication (via phone, chat, email) with customers' technical engineering teams to neutralize threats while ensuring stable traffic delivery
  • Continuously tune and optimize existing security monitoring rules and: alerting thresholds to improve the operational signal-to-noise ratio and reduce false positives
  • Lead managed customer onboarding sessions, maintain customer-specific: runbooks, and deliver highly technical monthly security posture reviews and post-incident reports
  • Partner directly with internal engineering, product, and threat intelligence: teams to provide actionable feedback on attack trends, tooling gaps, and product enhancements