engineering
Posted 2 hours agoResponse Engineer - PhishGuard
at LazyApply
On-site
Responsibilities
- Conduct continuous, real-time monitoring of email threat queues to review and analyze sophisticated attacks flagged by Cloudflare Email Security automated systems.
- Investigate customer-reported submissions, execute proactive threat hunts targeting emerging patterns, and perform manual retraction or quarantine of verified malicious emails.
- Identify nuanced threat patterns by correlating technical telemetry with behavioral indicators, generating detailed threat dossiers for impending organizational risks.
- Deliver direct crisis intervention and proactive phone notifications to customers regarding high-dollar BEC threats and active insider risks.
- Lead technical onboarding sessions for new customers, configuring internal system instances with bespoke detection rules, thresholds, and custom allow/block lists.
- Guide customers through their multi-year DMARC implementation journey toward strict "Reject" policy enforcement by conducting SPF and DKIM alignment audits. Role
Requirements
- As a result, they see significant improvement in performance and a decrease in spam and other attacks.
- We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools.
- Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up.
- If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
- Cloudforce One is Cloudflare's threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs).
- Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation.
- Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world's largest global networks can provide.
- I.N.T.E.R.D.I.C.T. (Identify, Neutralize, Triage, Engage, Respond, Disrupt, Integrate, Contain, Threat Hunting) is Cloudforce One's unified operational security organization responsible for identifying, analyzing, and responding to threats targeting Cloudflare and its customers.
- Detection Engineering: ML model development and detection optimization
- Requirements (Must-Have Skills)
- Undergraduate degree in Computer Science, Information Security, Information Systems, or equivalent practical experience. 5+ years of
- Deep working knowledge of core email authentication protocols (SPF, DKIM, DMARC) and aggregate/forensic data interpretation. Hands-on
- experience utilizing AI LLM tools (such as OpenCode or Windsurf) to develop automations for daily analysis and productivity workflows.
- Relevant industry certifications such as GCIH, GCIA, CEH, Security+, or equivalent.
- Technical familiarity with regular expressions, YARA rules, SQL query formulation, and malicious file format analysis (e.g., Microsoft Office Documents, Adobe PDFs). Prior
- experience working within managed security services (MSSP) or customer-facing security consulting environments.
- Familiarity with the broader Cloudflare ecosystem, including Cloudflare Email Security, WAF, and Zero Trust architectures.
- Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
- Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
Benefits
- All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law.
Contact
- Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.
Additional details
- At Cloudflare, we are on a mission to help build a better Internet.
- Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.
- Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code.
- Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request.
- Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
- At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with.
- The team analyzes these unique data points at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers. About INTERDICT
- PhishGuard: Managed email threat detection and response service
- Cloudflare Managed Defense (CMD): Network and application security monitoring for 'Under Attack' mitigation support.
- Together, INTERDICT provides comprehensive 24×7×365 protection across email, application, and network threat surfaces. Role Summary