Cloudflare
Response Engineer - Cloudflare Managed Defense Center (CMDC)
Hybrid · hybrid
Company's own board4–7 yrs
First seen Sep 25 · seen live today · from Cloudflare's own Greenhouse board
Skills mentioned
pythongraphqlrestlinux
The posting, as published
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Available Locations: London, United Kingdom
About the Department
Cloudforce One is Cloudflare's threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation.
Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world's largest global networks can provide. The team analyzes these unique data points at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers.
About INTERDICT
I.N.T.E.R.D.I.C.T. (Identify, Neutralize, Triage, Engage, Respond, Disrupt, Integrate, Contain, Threat Hunting) is Cloudforce One's unified operational security organization responsible for identifying, analyzing, and responding to threats targeting Cloudflare and its customers. INTERDICT encompasses three main sub-functions:
PhishGuard: Email Managed Detection and Response (MDR) service.
Cloudflare Managed Defense (CMD, Formerly SOCaaS): 24/7 monitoring, detection, and mitigation of security events across Cloudflare products.
Detection Engineering: Develops, maintains, and deploys Cloudflare’s threat detection logic across email, application, and network telemetry.
Through the combined capabilities of CMD, PhishGuard, and Detection Engineering, INTERDICT delivers a cohesive operational security function that provides continuous, proactive protection against network, application, and email-based threats. This integrated structure ensures rapid detection, coordinated response, and improved security outcomes for Cloudflare and its customers.
About the Role
The Response Engineer within the Cloudflare Managed Defense Center acts as a primary technical responder for Cloudflare's premium enterprise customers. You will autonomously investigate complex threat telemetry, handle live incident response for sophisticated volumetric DDoS and application-layer attacks, and analyze traffic anomalies during high-pressure events.
Customers contact the Managed Defense Center for assistance and intelligence across Cloudflare's security portfolio, focused on two core pillars: Web Application Security (WAF and Bot Management) and DDoS mitigation across network and application layers.
Managed Defense Response Engineers use customer-facing dashboards and internal tools to make detailed and informed suggestions for mitigation, and may implement mitigation strategies directly on behalf of the customer. The team provides continuous proactive monitoring and analysis of security events through internal alerting systems.
We are looking for an analytical security practitioner who thrives in this always-on operational environment and bridges the gap between deep technical analysis and premium customer advisory.
Role Responsibilities
Implement robust mitigation strategies for complex attacks across OSI Layers 3, 4, and 7 using Cloudflare's suite (Magic Transit, Magic Firewall, Advanced TCP Protection, Advanced DNS Protection, WAF, Custom Rules, IP Access Rules, Bot Management, and Rate Limiting)
Monitor and investigate proactive alerts, performing near real-time packet and traffic flow analysis and correlation to detect protocol exhaustion and application-layer exploitation, translating findings into custom, highly targeted mitigation rules
Review alerts to determine relevancy and urgency, proactively escalate customer-impacting incidents, and adhere to Customer SLAs for alert response and customer communication
Act as the primary technical contact for customers during active security incidents, driving high-touch, consultative communication (via phone, chat, email) with customers' technical engineering teams to neutralize threats while ensuring stable traffic delivery
Continuously tune and optimize existing security monitoring rules and alerting thresholds to improve the operational signal-to-noise ratio and reduce false positives
Lead managed customer onboarding sessions, maintain customer-specific runbooks, and deliver highly technical monthly security posture reviews and post-incident reports
Partner directly with internal engineering, product, and threat intelligence teams to provide actionable feedback on attack trends, tooling gaps, and product enhancements
Role Requirements
4–7 years of direct, hands-on experience in Managed Detection and Response (MDR), advanced Security Operations, or high-level Technical Support/Incident Response for enterprise infrastructure
Proven capability to handle both Application Security (including knowledge of OWASP Top 10 vulnerabilities, L7 WAF, HTTP/S anomalies, Bot mitigation) and Network Security (L3/L4 volumetric DDoS, protocol abuse)
Working knowledge of threat frameworks such as MITRE ATT&CK to classify adversary behavior and inform detection and mitigation strategies
Operational understanding of internet protocols including TCP, UDP, ICMP, GRE, BGP, DNS, with the ability to quickly diagnose attack fingerprints and infrastructure impact during volumetric DDoS attacks
Hands-on experience with packet capture (e.g., tcpdump, Wireshark, tshark) or HTTP traffic inspection (e.g., HAR, Burp Suite) to analyze malicious traffic
Extensive experience managing technical communications with enterprise customers during high-stress, active attacks, with the ability to remain calm under pressure and translate complex attack data into clear actionable advice
Ability and willingness to work 24x7 rotating shifts to support global operations
Knowledge of industry security technologies (e.g., enterprise CDNs, cloud-based DDoS scrubbing centers, Next-Gen WAFs, and edge network firewalls) (Preferred)
Proficiency in Linux/Unix environments and strong scripting skills (Bash, Python preferred) for workflow automation (including experience leveraging agentic AI environments or LLMs to optimize operations) and experience interacting with REST APIs or GraphQL to pull and correlate operational data (Preferred)
Experience building or querying dashboards in Prometheus and Grafana for performance and attack metrics (Prefer