Cloudflare
Senior Security Researcher & Analyst - WAF Application Security Experts
Cloudflare, Austin, Texas, us, 78716
Senior Security Researcher & Analyst – WAF Application Security Expert
Join Cloudflare as a Senior Security Researcher & Analyst to protect customer applications with advanced Web Application Firewall (WAF) detection logic and rules.
About Us Cloudflare is on a mission to build a better Internet. We run one of the world’s largest networks that powers millions of websites and Internet properties. Our services accelerate, protect, and secure applications without adding hardware or code changes. We are committed to diversity, innovation, and impact.
Available Locations London, United Kingdom; Bengaluru, India; Singapore; Austin, USA
What You’ll Do
Research, design, and improve detection logic and rules that protect customer applications from the latest web threats.
Analyze web exploits and vulnerability patterns (RCE, SQLi, XSS, SSRF, deserialization, etc.) and build corresponding WAF mitigations.
Collaborate with product engineering and data teams to tune detection efficacy—reducing false positives and false negatives across large‑scale, high‑volume traffic.
Develop, test, and deploy WAF managed rules and exploit signatures based on public CVEs, threat intelligence, and internal telemetry.
Perform targeted penetration testing and red‑team assessments to uncover gaps in Cloudflare’s WAF coverage and propose mitigations.
Leverage coding skills to automate rule validation, testing pipelines, and data analysis workflows.
Research attacker behaviors, evolving exploit chains, and web attack automation trends.
Produce internal and external research reports summarizing Internet‑wide attack trends and WAF efficacy insights.
Collaborate closely with Bot Management, Fraud, and ML teams to design cross‑signal detection frameworks that unify WAF and behavioral defenses.
Communicate complex technical findings clearly to both engineering and non‑technical audiences.
What You Bring
Bachelor’s or Master’s degree in Computer Science, Information Security, or equivalent practical experience.
2+ years of experience in Web Application Security, WAF rule development, incident detection, or threat research.
Deep understanding of web protocols (HTTP/HTTPS), common web vulnerabilities, and exploitation techniques (OWASP Top 10).
Proven experience writing and optimizing WAF rules or custom detection logic.
Hands‑on experience with vulnerability analysis, exploit reproduction, or reverse engineering.
Strong analytical mindset and comfort working with large data sets (SQL, ClickHouse, BigQuery, etc.).
Proficiency in at least one programming language such as Python, Go, or Rust for building automation tools or analysis scripts.
Familiarity with Grafana or equivalent visualization tools to track rule performance and attack trends.
Strong written and verbal communication skills—able to document, present, and collaborate effectively.
Experience working in fast‑paced environments with production‑scale systems.
Bonus Points
Experience with columnar databases like ClickHouse and advanced SQL query optimization.
Familiarity with machine learning for security analytics (feature extraction, anomaly detection, model evaluation).
Solid understanding of Linux/UNIX systems, TCP/IP networking, and proxy architectures.
Prior publications or conference presentations (e.g., Black Hat, DEF CON, BSides).
Contributions to open‑source WAF projects or web security tools.
Knowledge of WAF bypass techniques.
Experience on bug bounty or CTF—plus.
What Makes Cloudflare Special We protect the free and open Internet. Our initiatives include Project Galileo, Athenian Project, and the public DNS resolver 1.1.1.1. Join us to help secure the Internet for people worldwide.
Legal Requirements This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Equal Employment Opportunity Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value on diversity and inclusiveness. All qualified applicants will be considered for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, or any other protected status. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Contact us at hr@cloudflare.com for accommodations.
#J-18808-Ljbffr
About Us Cloudflare is on a mission to build a better Internet. We run one of the world’s largest networks that powers millions of websites and Internet properties. Our services accelerate, protect, and secure applications without adding hardware or code changes. We are committed to diversity, innovation, and impact.
Available Locations London, United Kingdom; Bengaluru, India; Singapore; Austin, USA
What You’ll Do
Research, design, and improve detection logic and rules that protect customer applications from the latest web threats.
Analyze web exploits and vulnerability patterns (RCE, SQLi, XSS, SSRF, deserialization, etc.) and build corresponding WAF mitigations.
Collaborate with product engineering and data teams to tune detection efficacy—reducing false positives and false negatives across large‑scale, high‑volume traffic.
Develop, test, and deploy WAF managed rules and exploit signatures based on public CVEs, threat intelligence, and internal telemetry.
Perform targeted penetration testing and red‑team assessments to uncover gaps in Cloudflare’s WAF coverage and propose mitigations.
Leverage coding skills to automate rule validation, testing pipelines, and data analysis workflows.
Research attacker behaviors, evolving exploit chains, and web attack automation trends.
Produce internal and external research reports summarizing Internet‑wide attack trends and WAF efficacy insights.
Collaborate closely with Bot Management, Fraud, and ML teams to design cross‑signal detection frameworks that unify WAF and behavioral defenses.
Communicate complex technical findings clearly to both engineering and non‑technical audiences.
What You Bring
Bachelor’s or Master’s degree in Computer Science, Information Security, or equivalent practical experience.
2+ years of experience in Web Application Security, WAF rule development, incident detection, or threat research.
Deep understanding of web protocols (HTTP/HTTPS), common web vulnerabilities, and exploitation techniques (OWASP Top 10).
Proven experience writing and optimizing WAF rules or custom detection logic.
Hands‑on experience with vulnerability analysis, exploit reproduction, or reverse engineering.
Strong analytical mindset and comfort working with large data sets (SQL, ClickHouse, BigQuery, etc.).
Proficiency in at least one programming language such as Python, Go, or Rust for building automation tools or analysis scripts.
Familiarity with Grafana or equivalent visualization tools to track rule performance and attack trends.
Strong written and verbal communication skills—able to document, present, and collaborate effectively.
Experience working in fast‑paced environments with production‑scale systems.
Bonus Points
Experience with columnar databases like ClickHouse and advanced SQL query optimization.
Familiarity with machine learning for security analytics (feature extraction, anomaly detection, model evaluation).
Solid understanding of Linux/UNIX systems, TCP/IP networking, and proxy architectures.
Prior publications or conference presentations (e.g., Black Hat, DEF CON, BSides).
Contributions to open‑source WAF projects or web security tools.
Knowledge of WAF bypass techniques.
Experience on bug bounty or CTF—plus.
What Makes Cloudflare Special We protect the free and open Internet. Our initiatives include Project Galileo, Athenian Project, and the public DNS resolver 1.1.1.1. Join us to help secure the Internet for people worldwide.
Legal Requirements This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Equal Employment Opportunity Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value on diversity and inclusiveness. All qualified applicants will be considered for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, age, disability, or any other protected status. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Contact us at hr@cloudflare.com for accommodations.
#J-18808-Ljbffr