Skip to content
CloudflareCloudflare

Senior Product Security Engineer

Lead security assessments, threat modeling, and vulnerability operations for Cloudflare's core products. Drive AI-powered automation for triage and workflows while mentoring teams in large-scale distributed environments.

About the job

Responsibilities

  • Autonomously Drive AI Security Innovation: Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling: Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management: Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership: Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support: Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship: Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.

Desirable Skills, Knowledge, and Experience

  • Senior-Level Product/AppSec Expertise: Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis: Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership: Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication: Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.

Bonus Points

  • Offensive Mastery: Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases.

Compensation & Benefits

This role is eligible to participate in Cloudflare’s equity plan. Cloudflare offers a complete package of benefits and programs to support you and your family, including medical, dental, and vision insurance, a 401(k) plan with company match, flexible paid time off, and fertility & family-forming benefits.

Skills

Application Security, Threat Modeling, Vulnerability Management, Bug Bounty, Penetration Testing, AI, LLMs, Automation, Stride, Offensive Security, Jira, Hardware Security

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.