Skip to content
CloudflareCloudflareUnited States

Senior Product Security Engineer

Lead security assessments, threat modeling, and vulnerability operations for Cloudflare's core products. Drive AI-powered automation for triage and workflows while mentoring teams in large-scale distributed environments.

Salary not listed
Hybrid7+ YOESecurity Engineering

About the role

Responsibilities

  • Autonomously Drive AI Security Innovation: Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling: Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management: Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support: Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship: Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.

Desirable Skills, Knowledge, and Experience

  • Senior-Level Product/AppSec Expertise: Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis: Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership: Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication: Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.

Bonus Points

  • Offensive Mastery: Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases.

Compensation & Benefits

This role is eligible to participate in Cloudflare’s equity plan. Cloudflare offers a complete package of benefits and programs to support you and your family, including medical, dental, and vision insurance, a 401(k) plan with company match, flexible paid time off, and fertility & family-forming benefits.

Skills

Application SecurityThreat ModelingVulnerability Managementbug bountyPenetration TestingAILLMsAutomationstrideoffensive securityJirahardware security
Forterra

Senior DoD Product Security Engineer

ForterraClarksburg, MD

Senior individual contributor owning end-to-end product security for DoD autonomous systems programs. Leads RMF/ATO processes, defines security architecture and requirements for hardware/software (including air-gapped/embedded), performs threat modeling, STIG compliance, and supply-chain security.

Salary not listed
On-site5+ YOESecurity Engineering
Coalition Security

Senior Threat Engineer

Coalition SecurityUnited States

Senior Threat Engineer designs, builds, and improves detection, decisioning, and response workflows for the Wirespeed Verdict Engine. Requires significant cybersecurity operations experience, strong analytical skills, and ability to translate threat research into scalable automations.

100k – 150k/yr
Remote5+ YOESecurity Engineering
Cloudflare

Senior Security Compliance Specialist

CloudflareUnited States

Lead Cloudflare's CCCS CSP ITS assessment and maintain CCCS requirements in the Common Control Framework. Requires 5+ years in security compliance, deep CCCS knowledge, and cross-functional collaboration with engineering, legal, and product teams.

Salary not listed
Remote5+ YOESecurity Engineering
Komodo Health

Senior IAM Engineer

Komodo HealthNew York, NY

Senior IAM Engineer building integration and orchestration infrastructure to secure AI and data systems at Komodo Health. Design automated identity lifecycle processes, RBAC/ABAC, SSO/MFA, and custom automations with Okta, Workato, and Python while ensuring SOC2/HIPAA compliance.

150k – 210k/yr
Remote5+ YOESecurity Engineering
Illumio

Sr. Software Engineer

IllumioSunnyvale, CA

Develop containerized microservices in Go for a multi-tenant cloud security platform that processes real-time cloud telemetry to deliver insights and risk minimization. Own full SDLC, design, operations, and mentoring while partnering with Product on requirements.

170k – 196k/yr
On-site4+ YOESecurity Engineering