# Senior Staff Security Engineer - Network Security
**Company:** [Gusto](https://hotfix.jobs/companies/gusto)
**Location:** San Francisco, CA
**Salary:** $230K-$270K
**Experience:** 10+ years
**Skills:** Cloudflare Waf, Cloudflare Ddos, Cloudflare Zero Trust, Terraform, Aws Vpc, Aws Network Firewall, Aws Shield, Cloudfront, Panther Siem, Crowdstrike, Wiz, Tines, Crossplane, Policy-As-Code, CI/CD
**Posted:** 2026-05-08
> Leads edge and network security strategy, owning Cloudflare WAF, DDoS protection, Zero Trust, and AWS perimeter controls. Partners with teams to implement layered defenses, policy-as-code, detections, and AI-assisted automations. Requires 10+ years experience with deep Cloudflare and network expertise.
## Job Description
## Responsibilities

- Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
- Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
- Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
- Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
- Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
- Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
- Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own.

## Requirements

- 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
- Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
- Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs.
- Fluency with policy-as-code, **Terraform**, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
- Solid generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience on edge and network telemetry in a modern SIEM.
- AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output.
- Excellent written and verbal communication; you can take a complex perimeter decision and explain the tradeoffs to a staff engineer, a PM, and a VP without changing the substance.
- Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent.

## Compensation

- Cash compensation targeted at $230,000/yr to $270,000/yr for San Francisco.
- Stock equity is additional.
**Apply:** https://hotfix.jobs/jobs/senior-staff-security-engineer-network-security-at-gusto-b3535b21-0e8c-4e69-aecd-b17494a88ef6
**Canonical:** https://hotfix.jobs/jobs/senior-staff-security-engineer-network-security-at-gusto-b3535b21-0e8c-4e69-aecd-b17494a88ef6