Senior Response Engineer - Cloudflare Managed Defense Center (CMDC)Active
The opportunity
Acting as a primary technical anchor for network defense, you will provide advanced assistance and strategic intelligence across Cloudflare’s most sophisticated customer environments. This involves deep mastery of infrastructure protection components (spanning Cloudflare’s…
What you'll do
Technical Mentorship: Elevating the team’s collective skill set by acting as a "player-coach" providing hands-on technical guidance during live incidents and reviewing complex mitigation strategies.
Deep-Dive Investigation & Mitigation: Analyzing infrastructure threats using advanced internal telemetry to engineer informed mitigation strategies—specifically focusing on DDoS vectors, BGP routing anomalies, and GRE encapsulation issues—implementing defenses directly on the edge for mission-critical traffic.
Detection Engineering & Tuning: Continuously designing and refining detection mechanisms, security controls, and alerting thresholds to ensure highly accurate, rapid identification of sophisticated network attacks with minimal false positives.
Infrastructure & Tooling Evolution (AI-Driven): Partnering closely with Product, Engineering, and AI teams to transform real-world DDoS attack data into AI-powered automated network defenses, dynamic mitigation models, and enhanced platform capabilities.
Strategic Technical Communication: Serving as an authoritative technical voice during active volumetric attacks, providing clarity and architectural routing guidance to both internal stakeholders and external customer engineering teams.
Technical Escalation & Response: Acting as a subject matter expert for the Managed Defense Center during complex network security incidents, providing hands-on intervention for large-scale volumetric and protocol-based DDoS attacks when standard protocols are exceeded.
What they're looking for
- Incident Architecture: Leading the technical response to sophisticated infrastructure threats, validating the efficacy of network mitigation rules, and ensuring stable, clean traffic delivery via BGP and GRE mechanisms.
- Detection Engineering: Designing, deploying, and tuning network attack detection logic, utilizing attack telemetry to stay consistently ahead of evolving DDoS methodologies and adversary tactics.
- Technical Communications: Driving high-touch technical dialogue with customer network teams during critical incidents, translating complex routing and attack flow data into actionable architectural advice.
- Operational Engineering & AI Integration: Designing and refining technical Managed Defense workflows, building AI-driven automated troubleshooting playbooks (particularly around BGP/GRE), and tuning alerting thresholds to create self-healing infrastructure responses.