Principal Engineer - Cloudforce One
Hybrid
Posted 10d ago
Remote Work Policy
On-site
Categories
Applied AI Engineer
About the job
Cloudforce One is Cloudflare's threat operations and research team, focused on identifying and disrupting cyber threats from criminal activity to nation-state sponsored attacks. The team collaborates with external organizations and internal Cloudflare teams to develop operational tradecraft and expand threat intelligence for expedited threat hunting and remediation. Members leverage vast data from Cloudflare's global network to analyze unique data points at scale, synthesizing findings into actionable threat intelligence to protect customers. This role involves working across the full breadth of Cloudflare Products, tackling critical problems like redesigning detection pipelines, deploying edge capabilities, building agentic AI workflows, and architecting massive data systems. The ideal candidate is an architect, threat analyst, and disruptor who can rethink how threats are detected, analyzed, and neutralized across a global network.
Responsibilities
- Drive architectural direction and technical strategy for threat operations and research engineering.
- Identify and resolve technical bottlenecks and architectural debt to improve threat detection and abuse response.
- Design and build data pipelines and services for collecting, enriching, and analyzing threat intelligence and abuse signals at scale.
- Act as a technical force multiplier across concurrent projects involving threat intelligence platforms, abuse detection, legal tooling, and security products.
- Incorporate a threat-informed perspective into engineering decisions, understanding adversary adaptation and building systems to stay ahead of evolving attacks.
- Collaborate with researchers, analysts, product, legal, and engineering teams to translate requirements into scalable solutions.
- Mentor and elevate engineering talent within the team.
Requirements
- Deep technical expertise in distributed systems architecture.
- Deep understanding of threat actor tactics, techniques, procedures, and infrastructure.
- Ability to think like an attacker and build robust production systems.
- Experience with production incidents and a track record of shipping complex solutions.
- Ability to context-switch between various security and engineering domains.
- Flexibility for on-call duties outside standard working hours.