Incident Response Analyst
Core
Respond to customer security incidents across on-premises, cloud, and hybrid environments by executing immediate defensive maneuvers, managing the full incident response lifecycle, and creating customized remediation plans.
Role type
Incident Response Analyst (Consultant)
Builds
Proactive and threat intelligence-driven protection for Cloudflare and its customers
Domain
Cybersecurity / Internet Infrastructure
Deliverable
client delivery
Required skills
Incident response lifecycle management, Active Edge Mitigation (WAF rules, DDoS shunning, traffic filtering), Threat analysis and triage, Cross-functional collaboration with forensic/threat teams, Customer stakeholder engagement (Executive to Engineering levels), OS/Cloud environment expertise (Windows, Unix/Linux/Mac, AWS/Azure/GCP), Network attack pattern knowledge (L3/L4/L7, SYN/UDP/HTTP floods, credential stuffing, API abuse), MITRE ATT&CK and NIST frameworks proficiency
Preferred skills
Python or Golang scripting, Yara rule writing, Malware analysis (static/dynamic/reverse engineering), Networking fundamentals (BGP, Anycast, DNS, TCP/IP, RPKI, IRR), Bash command-line analysis
Technologies
WAF, L3/L4/L7 filtering, AWS, Azure, O365, Google Cloud, Cloudflare, MITRE ATT&CK, NIST, Python, Golang, Yara, Bash, BGP, Anycast, DNS, TCP/IP, GRE/IPsec
Responsibilities
Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability; Support and execute the end-to-end incident response process for clients (investigation, containment, remediation, and recovery); Build and execute customized tactical and strategic remediation plans for compromised organizations
Seniority
Mid-Senior, hands-on IC