Product Security Engineer

Hybrid

Posted 10d ago

Job Location

Hybrid

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

Cloudflare is seeking a Product Security Engineer to support security assessments and vulnerability operations for its core software products. In this role, you will analyze system architecture, threat model new features, and ensure product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within SLAs. You will conduct security reviews, triage bug bounty submissions, and collaborate with engineering teams to resolve vulnerabilities from various sources. A key aspect of this role involves identifying process bottlenecks and leveraging AI/LLM solutions to automate initial triage and data enrichment, building tools to handle security findings at scale. This position sits at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling, ideally with experience in academic/vulnerability research focused on systems security.

Responsibilities

  • Implement AI Security Solutions: Build AI-driven tools or scripts to automate code analysis, optimize triage, and streamline Product Security workflows.
  • Conduct security reviews and threat modeling sessions for product features, defining security requirements early in the development lifecycle.
  • Manage the operational lifecycle of product security findings, ensuring vulnerabilities are verified, mapped to owners, and tracked to mitigation within SLAs.
  • Perform technical triage and validation of external Bug Bounty submissions, verifying exploitability and evaluating business risk.
  • Support internal and external penetration testing engagements by reviewing findings and assisting development teams with remediation.
  • Collaborate with DevOps and product teams, acting as a security point of contact and promoting secure coding practices.

Requirements

  • 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Demonstrated ability to build production-grade automation scripts and tools, with hands-on engineering experience leveraging AI/LLMs for operational or technical challenges.
  • Competency in threat modeling methodologies and the ability to evaluate code flaws for their engineering and security impact.
  • Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups against defined SLAs.
  • Ability to collaborate effectively across teams, clearly communicating technical security risks and resolving ownership ambiguity.
  • Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Experience scaling crowdsourced security programs or optimizing agile project management workflows.
  • Experience integrating hardware security features into production code bases.

Benefits

  • Equity

About Cloudflare

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.