• Lead security assessments and vulnerability operations for Cloudflare’s core software products.
• Analyse system architecture, threat model new features, and make sure product security findings are triaged accurately.
• Route findings to the correct engineering owners and see them mitigated within agreed SLAs.
• Run deep-dive security reviews on new feature designs, triage complex bug bounty submissions, and resolve vulnerabilities surfaced by SAST, fuzzing, and penetration tests.
• Work autonomously to spot where manual processes slow the team down.
• Write code and integrate AI and LLM solutions to automate initial triage and data enrichment, building tools that handle security findings at scale.
• Sit at the intersection of Product Security, Vulnerability Operations, and internal AI tooling.
• Work from London on a hybrid basis, with the role also open in Austin.
📋 Job Requirements
• Bring extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
• Build production-grade automation scripts and tools.
• Bring hands-on engineering experience using AI and LLMs to solve operational or technical challenges.
• Bring mastery of threat modelling methodologies such as STRIDE.
• Translate complex theoretical risks into prioritised, actionable business context.
• Show a proven track record of managing, routing, and driving remediation of vulnerabilities across multi-stakeholder engineering organisations while enforcing SLAs.
• Influence senior engineering leaders confidently, resolve ownership ambiguity, and champion security initiatives without explicit authority.
• Bring superb cross-functional leadership and communication skills.
🌟 Nice-to-have
• Bring experience conducting academic or vulnerability research focused on systems security.
• Bring familiarity with offensive security tooling and modern exploitation techniques used in professional penetration testing.
• Bring experience scaling crowdsourced security programmes such as HackerOne or Bugcrowd.
• Optimise agile project management workflows within JIRA.
• Bring experience integrating hardware security features into production codebases.
• Spot problems everyone else has normalised and build a solution with the latest tools.
🎯 Responsibilities
• Proactively identify gaps in current capabilities and independently architect, build, and deploy AI-driven solutions that automate code analysis and scale Product Security workflows.
• Lead deep-dive security reviews and complex threat modelling sessions across distributed systems, embedding security requirements into designs before development begins.
• Own the lifecycle of product security findings from triage through to mitigation within SLAs.
• Oversee the technical triage and validation of Cloudflare’s external Bug Bounty programme, prioritising submissions by real-world exploitability and business risk.
• Shape the scope of internal and external penetration testing engagements and act as technical liaison so findings are understood and remediated.
• Mentor junior engineers and cultivate security champions within engineering organisations.
• Establish modern, paved-road developer guardrails that make the secure path the easy one.
We have used Cloudflare products ourselves, including Turnstile to protect apps from bots, so we know first-hand how solid their tech is, and that matters when you are thinking about where to work. With over $2.1 billion in annual revenue, 34% growth in Q4 2025, and $4 billion+ in cash reserves, Cloudflare is financially rock-solid and still growing fast. They operate one of the largest networks in the world, sit in front of roughly one in five websites, and are pushing hard into AI infrastructure and the agentic web. The scale of what they do is genuinely impressive; so many of the apps and services you use every day depend on Cloudflare without you even knowing it. Across Glassdoor, employees consistently highlight the great products, friendly and smart colleagues, positive working environment, and genuine flexible hybrid and work-from-home arrangements. They also offer unlimited paid time off and have a real focus on diversity and inclusion. We should be upfront, though: the Glassdoor rating sits at 3.4, and reviews are mixed. While the culture and people are widely praised, compensation competitiveness and slow promotion processes are recurring pain points. However, if you want to solve hard, Internet-scale problems at a company whose products you probably already rely on, Cloudflare is a brilliant place to do that.
😃 What Cloudflare offers
• Take part in Cloudflare’s equity plan.
• Access a complete package of benefits and programmes supporting you and your family, though specifics vary outside the United States.
• Take flexible paid time off covering both vacation and sick leave.
• Use leave programmes including parental, pregnancy health, medical, and bereavement leave.
• Draw on on-demand mental health support and an Employee Assistance Programme.
• Build AI tooling yourself rather than only consuming what others provide.
• Own the bug bounty programme and penetration testing strategy for a major internet platform.
• Contribute to public interest work including Project Galileo, the Athenian Project, and the 1.1.1.1 resolver.
💖 What makes Cloudflare unique
Cloudflare is on a mission to help build a better Internet, running one of the world’s largest networks and powering millions of websites and Internet properties for customers from individual bloggers to Fortune 500 companies. It protects and accelerates any Internet application without added hardware, installed software, or code changes, routing traffic through an intelligent global network that gets smarter with every request. Fundamental to its mission is protecting the free and open Internet: Project Galileo has equipped more than 2,400 journalism and civil society organisations across 111 countries with protection at no cost, and the Athenian Project has served more than 425 local government election websites across 33 states. Its culture favours builders and curiosity over bureaucracy.
💬 What employees say
"You learn so much about different technologies here, which can really give your career a boost. Your colleagues are smart, always willing to help, and come from all sorts of backgrounds."
Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.
For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.