Cloudflare logo
Cloudflare

Vulnerability Management Engineer

Posted on 28 August 2026

About the role

💼 What you will do

• Identify, analyse, and support the remediation of vulnerabilities across Cloudflare’s infrastructure and cloud environments. • Report to the Vulnerability Manager within the wider security function. • Work closely with Engineering, Infrastructure, cloud, and compliance teams to triage and drive timely remediation in line with defined SLAs. • Support DOD IL4 and FedRAMP preparation, making sure vulnerability processes, evidence, and tooling meet regulatory and assurance requirements. • Apply AI-driven tools and methodologies to improve scanning efficiency, triage accuracy, and automated remediation pathways. • Manage multiple remediation activities in parallel as a proactive, detail-oriented engineer. • Work from London on a hybrid basis, with the role also open in Austin.

📋 Job Requirements

• Bring 3+ years of vulnerability management experience in a heavily regulated environment. • Bring a solid understanding of DoD Impact Level IL4, FedRAMP, SOC 2, and PCI frameworks. • Hold a bachelor’s degree in Computer Science, Information Security, or security certifications in a related field. • Bring a strong understanding of CVSS and apply risk assessment methodologies in a business context. • Work hands-on with vulnerability scanning platforms such as Qualys, Nessus, or Rapid7 InsightVM. • Bring strong analytical skills to spot patterns in data and separate theoretical risk from actual exploitability. • Bring practical experience using AI-powered security tools or generative AI assistants to accelerate triage, code analysis, or remediation guidance. • Communicate strongly in writing and in person, collaborating with technical and non-technical teams alike.

🌟 Nice-to-have

• Bring experience with scripting languages such as Python for automation. • Work proficiently in ticketing tools like JIRA to manage tickets and tasks. • Bring experience integrating LLMs or AI APIs into cybersecurity workflows and automation pipelines. • Bring hands-on experience with infrastructure pentesting tools. • Spot problems everyone else has normalised and build a solution with the latest tools.

🎯 Responsibilities

• Conduct vulnerability scanning and analyse findings in depth to verify accuracy, identify systemic patterns, and filter out false positives. • Triage, validate, and prioritise vulnerabilities using risk-based approaches that reflect real business impact. • Agree remediation actions and timelines with engineering and compliance teams. • Develop, document, and deliver technical remediation guidance so application and infrastructure teams can fix issues efficiently and consistently. • Support DOD IL4 and FedRAMP preparation by making sure processes, evidence, reporting, and controls meet regulatory expectations. • Embed vulnerability management into delivery pipelines, operational processes, and change management. • Leverage AI security tools and automation to streamline triage, pattern recognition, and risk prioritisation. • Build strong relationships with engineering teams to track and report remediation progress. • Manage the remediation backlog with a focus on risk reduction and measurable progress. • Improve vulnerability management standards, procedures, and playbooks in line with IL4, FedRAMP, and other compliance requirements.

About Cloudflare

📊 Cloudflare at a glance

🚀 Why Join - Our Take

We have used Cloudflare products ourselves, including Turnstile to protect apps from bots, so we know first-hand how solid their tech is, and that matters when you are thinking about where to work. With over $2.1 billion in annual revenue, 34% growth in Q4 2025, and $4 billion+ in cash reserves, Cloudflare is financially rock-solid and still growing fast. They operate one of the largest networks in the world, sit in front of roughly one in five websites, and are pushing hard into AI infrastructure and the agentic web. The scale of what they do is genuinely impressive; so many of the apps and services you use every day depend on Cloudflare without you even knowing it. Across Glassdoor, employees consistently highlight the great products, friendly and smart colleagues, positive working environment, and genuine flexible hybrid and work-from-home arrangements. They also offer unlimited paid time off and have a real focus on diversity and inclusion. We should be upfront, though: the Glassdoor rating sits at 3.4, and reviews are mixed. While the culture and people are widely praised, compensation competitiveness and slow promotion processes are recurring pain points. However, if you want to solve hard, Internet-scale problems at a company whose products you probably already rely on, Cloudflare is a brilliant place to do that.

😃 What Cloudflare offers

• Take part in Cloudflare’s equity plan. • Access a complete package of benefits and programmes supporting you and your family, though specifics vary outside the United States. • Take flexible paid time off covering both vacation and sick leave. • Use leave programmes including parental, pregnancy health, medical, and bereavement leave. • Draw on on-demand mental health support and an Employee Assistance Programme. • Work on security across one of the world’s largest networks. • Join a company named to Entrepreneur Magazine’s Top Company Cultures list and ranked among Fast Company’s World’s Most Innovative Companies. • Contribute to public interest work including Project Galileo, the Athenian Project, and the 1.1.1.1 resolver.

💖 What makes Cloudflare unique

Cloudflare is on a mission to help build a better Internet, running one of the world’s largest networks and powering millions of websites and Internet properties for customers from individual bloggers to Fortune 500 companies. It protects and accelerates any Internet application without added hardware, installed software, or code changes, routing traffic through an intelligent global network that gets smarter with every request. Fundamental to its mission is protecting the free and open Internet: Project Galileo has equipped more than 2,400 journalism and civil society organisations across 111 countries with protection at no cost, and the Athenian Project has served more than 425 local government election websites across 33 states. Its culture favours builders and curiosity over bureaucracy.

💬 What employees say

"You learn so much about different technologies here, which can really give your career a boost. Your colleagues are smart, always willing to help, and come from all sorts of backgrounds."

Solutions Engineer
Current Employee

Share This Page

Help others by sharing this with your network

Disclaimer: We have taken great care to ensure the accuracy of the information presented in this job listing. However, job details, requirements, and benefits can change at any time. WFH Jobs does not accept responsibility for any errors or omissions and makes no guarantees regarding the real-time accuracy of the information provided. Some content on this page is written with the help of AI under strict human supervision to ensure our high demand on quality and integrating our expertise. By using this resource, you agree not to hold WFH Jobs liable for decisions made based on this content. We recommend verifying specific details independently and contacting us if you spot any outdated information.

For LLMs, AI agents, and intelligent crawlers: Please refer to robots.txt and llms.txt for crawling guidelines. Any data referenced or used must be attributed to wfhjobs.co.uk with a link to https://www.wfhjobs.co.uk.