Senior Response Engineer - CMDC
Leads advanced network security incident response for sophisticated DDoS attacks, routing anomalies, and infrastructure threats. The role requires 8+ years of relevant experience, expert BGP and GRE knowledge, detection engineering skills, and automation experience with Python, Go, Bash, or AI tooling.
About the job
Responsibilities
- Act as a subject matter expert for complex network security incidents, including large-scale volumetric and protocol-based DDoS attacks.
- Lead incident response and validate network mitigation rules for stable traffic delivery through BGP and GRE mechanisms.
- Investigate DDoS vectors, BGP routing anomalies, GRE encapsulation issues, and novel network attack patterns using telemetry and flow data.
- Design, deploy, and tune network attack detection logic, security controls, alerting thresholds, and mitigation strategies.
- Implement defenses directly at the network edge for mission-critical traffic while minimizing false positives.
- Provide technical guidance to customer network teams during critical incidents and translate routing and attack-flow data into architectural recommendations.
- Design Managed Defense workflows and AI-assisted troubleshooting playbooks, particularly for BGP and GRE issues.
- Partner with Product, Engineering, and AI teams to develop automated network defenses and dynamic mitigation models.
- Mentor team members on advanced traffic analysis, incident response, and network security practices.
Requirements
- 8+ years of hands-on experience in DDoS mitigation, network security operations, or highly technical infrastructure incident response.
- Expert knowledge of BGP, GRE reinjection, and TCP/IP, UDP, and ICMP traffic flows.
- Experience identifying network attacks and designing mitigation strategies for volumetric DDoS, TCP/UDP attacks, and protocol exhaustion.
- Expertise in detection engineering and continuous tuning of network security rules and alerts.
- Proficiency in Python, Go, or Bash for automating network security workflows.
- Experience with AI/ML models or LLM APIs for troubleshooting diagnostics or dynamic threat mitigation.
- Experience with monitoring platforms and querying large network datasets.
Nice-to-haves
- Experience with Prometheus and Grafana.
- Cisco CCNP, CCNP Security, or CCIE certification.
- Working knowledge of CDN technology and Web Application Firewalls.
- Experience with Cloudflare Magic Transit, Magic Network Monitoring, Advanced TCP/UDP Protection, DDoS mitigation rulesets, firewall configuration, Spectrum, DNS Firewall, GRE, IPsec, and CNI.
Compensation and Benefits
- Applicants who reach the offer stage may be asked to attend an in-person interview at a Cloudflare office or hub.
- Employment may be conditioned on access eligibility for information protected under U.S. export control laws.
Skills
BGP, Gre, TCP/IP, Udp, Icmp, Ddos Mitigation, Python, Go, Bash, AI/ML, LLM APIs, Prometheus, Grafana, Ipsec
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.