SlipstreamJobsFresh Startup & VC-Backed Jobs

AI Security Research & Red Team Engineer

Cloudflare - San Francisco, CA, United States - Hybrid - posted 2026-08-10

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Cloudflare is seeking a highly skilled AI Security Research & Red Team Engineer to join its Security Threat Detection, Response and Emulation organization. This role sits at the intersection of offensive security and AI safety, focusing on identifying vulnerabilities in AI systems, agents, and LLMs before they impact customers. Key responsibilities include conducting deep-dive AI security research to identify emerging threats and vulnerabilities specific to AI implementations; performing rigorous agentic testing and LLM adoption analysis to uncover attack surfaces; executing full-chain red team operations against Cloudflare's global infrastructure and product ecosystems; establishing frameworks for testing security efficacy across WAF, EDR, and SIEM detections; and fostering purple team collaboration with the Blue Team (Detection & Response) to translate findings into defensive improvements. You will act as a technical sparring partner for the Security Incident Response Team (SIRT), conducting unannounced exercises to refine playbooks and test forensic tooling. You'll partner closely with Threat Detection and Threat Engineering teams to bridge adversary simulation and defensive coverage, proactively identifying detection gaps and establishing validation frameworks. As "Customer Zero" of Cloudflare's own products, your red teaming findings will drive resilience improvements that benefit both the company and its customers. Additionally, you will provide executive reporting that translates complex technical exploits into risk-based narratives for leadership, mentor team members in ethical hacking and security research, and bridge the gap between technical reality and compliance requirements by providing empirical evidence of control effectiveness to the Governance, Risk, and Compliance team. Required qualifications include 4+ years in offensive security, application security, or related field; deep knowledge of AI, coding agents, LLMs, and prompt engineering; and demonstrated expertise in identifying and exploiting AI-specific vulnerabilities. The ideal candidate combines technical depth in security research with the ability to communicate findings to both technical and executive audiences.

Similar roles