Response Engineer - Cloudflare Managed Defense Center (CMDC)
Core
Primary technical responder for premium enterprise customers, investigating complex threat telemetry and handling live incident response for sophisticated volumetric DDoS and application-layer attacks.
Role type
Senior IC Security Response Engineer (Managed Defense)
Builds
Continuous proactive monitoring, analysis, and mitigation of security events for Cloudflare customers.
Domain
Cybersecurity, Threat Operations, Cloud Infrastructure
Deliverable
client delivery
Required skills
Managed Detection and Response (MDR), Incident Response, Web Application Security (WAF, Bot Management), Network Security (DDoS, L3/L4), Threat Frameworks (MITRE ATT&CK), Internet Protocols (TCP, UDP, ICMP, BGP, DNS), Packet Capture (tcpdump, Wireshark), Linux/Unix, Scripting (Bash, Python), REST APIs, GraphQL, Customer Communication under pressure
Preferred skills
Enterprise CDN knowledge, Cloud-based DDoS scrubbing, Next-Gen WAFs, Edge network firewalls, Prometheus, Grafana, Agentic AI/LLMs
Technologies
Cloudflare Magic Transit, Magic Firewall, Advanced TCP Protection, Advanced DNS Protection, WAF, Custom Rules, IP Access Rules, Bot Management, Rate Limiting, tcpdump, Wireshark, tshark, Burp Suite, Prometheus, Grafana
Responsibilities
Implement robust mitigation strategies for complex attacks across OSI Layers 3, 4, and 7; Monitor and investigate proactive alerts performing near real-time packet and traffic flow analysis; Review alerts to determine relevancy and urgency, escalating customer-impacting incidents; Act as primary technical contact for customers during active security incidents; Continuously tune and optimize security monitoring rules and alerting thresholds; Lead managed customer onboarding sessions and deliver monthly security posture reviews.
Seniority
Senior, hands-on IC
