SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Cloudflare is seeking a Vulnerability Management Engineer to serve as the technical authority for the company's vulnerability management program. Reporting to the Director of Vulnerability Management, you will focus on architecture, systems design, and long-term technology strategy for Cloudflare's vulnerability management capabilities across global infrastructure and cloud environments.
Key responsibilities include:
- Serve as primary technical lead for the Vulnerability Management team, providing architectural guidance and mentoring on complex technical challenges
- Lead architecture, systems design, technology evaluation, and systems integration for the global VM program
- Oversee advanced vulnerability scanning, validation of findings, triage, and prioritization of critical risks
- Collaborate with technology owners and engineering teams to drive remediation of complex vulnerabilities
- Strategically manage remediation backlog and track risk reduction progress
- Design and implement AI-driven solutions to automate the vulnerability lifecycle
- Contribute to continuous improvement of global vulnerability management standards and playbooks
- Act as primary technical liaison for GRC team, translating technical vulnerabilities into compliance context
- Own technical reporting and evidence generation for internal and external audits (SOC-2, PCI-DSS, FedRAMP)
- Interpret regulatory requirements into actionable technical scanning policies
Required experience includes 5+ years in Vulnerability Management in a senior or lead technical capacity, solid understanding of security frameworks (SOC-2, NIST, PCI), and hands-on experience with vulnerability scanning platforms. Bachelor's degree in Computer Science, Information Security, or related security certifications preferred. Strong communication skills and ability to collaborate across technical and non-technical teams essential. Role may require on-call flexibility outside standard working hours.