Response Engineer
Posted 7 days 11 hours ago by CloudFlare
Available Locations: London, UK
About the roleCloudflare Managed Defense Center provides premium-level support for Cloudflare's security products and features. Our largest and most technically sophisticated customers will contact our Managed Defense Center for assistance and intelligence in dealing with threats or attacks on their infrastructure at OSI Layers 3, 4, and 7. This spans the range of Cloudflare security products from Magic Transit Infrastructure Protection, DDoS mitigation (including Advanced TCP Protection and Advanced DNS Protection), and Cloudflare Network Firewall, to using the Web Application Firewall (WAF), Spectrum, Bot Management, API Security, and Rate Limiting to help customers.
Managed Defense Response Analysts/Engineers analyze threats using customer-facing dashboards and internal tools, make detailed and informed suggestions for mitigation, and may implement mitigation strategies directly on behalf of the customer with appropriate approval. The team provides 24x7x365 proactive monitoring via our internal alerting systems, near real-time analysis of security events, and attack reporting beyond Cloudflare's self-service reports.
Responsibilities- Monitor and investigate proactive alerts to identify attacks
- Work with Engineering and Operations teams to mitigate attacks, suggest steps to mitigate, and apply the appropriate mitigation when applicable
- Work with Engineering and Product teams to improve products and tools
- Communicate with customers via chat, email, and phone
- Review alerts to determine relevancy and urgency; create tracking tickets for incidents requiring review or escalation
- Adhere to Customer SLAs for alert response and customer communication
- Configure and manage security monitoring rules; contribute to tool and threshold improvements
- DDoS mitigation for OSI Layers 3, 4, & 7: filter malicious traffic using Cloudflare tools including Magic Transit, Magic Firewall, Advanced TCP Protection, WAF, Custom Rules, IP Access Rules, and Rate Limiting
- Maintain customer-specific runbooks and escalation matrices
- Support managed customer onboarding and deliver monthly security reviews
- Strong understanding of internet protocols (TCP, UDP, ICMP, GRE, BGP)
- Networking fundamentals are crucial for success
- Analysis of traffic for attack anomaly detection and creation of mitigation rules
- Experience handling attack mitigation with knowledge of L3/4 and L7 attacks
- Command line / Bash shell proficiency
- Customer-facing or Technical support experience is mandatory
- Strong communication skills, including with VIP customers during active attacks
- Ability to remain calm under pressure
- Ability to work 24x7 rotating shifts
- Sysadmin skills: Linux, Mac, or Windows (Preferred)
- Knowledge of Cloudflare Security Products & Features (Preferred)
- Scripting skills, Python preferred (Preferred)
- Prometheus/Grafana monitoring experience (Preferred)
- Packet capture tools such as tcpdump or Wireshark (Preferred)
- API/GraphQL experience (Nice to have)
- Security certifications: GCIA, GCIH, GCFA, GCFE, CISSP, CISM equivalent (Strongly preferred)
- Network certifications: CCNA, CCNP (Nice to have)
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Equal Employment OpportunityCloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
AccommodationsCloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at or via mail at 101 Townsend St. San Francisco, CA 94107.