Senior Product Security Engineer

Hybrid

Posted 10d ago

Job Location

Hybrid

Tech Stack

Remote Work Policy

On-site

Categories

Applied AI Engineer

About the job

As a Senior Product Security Engineer at Cloudflare, you will be instrumental in leading security assessments and vulnerability operations for the company's core software products. This role involves analyzing system architectures, conducting threat modeling for new features, and ensuring that product-related security findings are efficiently triaged, assigned to the appropriate engineering owners, and resolved within established service level agreements (SLAs). You will have the opportunity to work autonomously to identify and improve manual processes, leveraging your skills to write code and integrate AI/LLM solutions for automating initial triage and data enrichment. Your work will be at the crucial intersection of Product Security, Vulnerability Operations, and internal AI Tooling, contributing to the security and performance of Cloudflare's global network.

Responsibilities

  • Proactively identify gaps in current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Own the lifecycle of product security findings, ensuring vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.

Requirements

  • Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Demonstrated ability to build production-grade automation scripts and tools, with hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.
  • Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Experience in program management.

About Cloudflare

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.