SlipstreamJobsFresh Startup & VC-Backed Jobs

Product Security Engineer

Cloudflare - Austin, TX, United States - Hybrid - posted 2026-08-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Cloudflare is seeking a Product Security Engineer to support security assessments and vulnerability operations for its core software products. You will analyze system architecture, threat model new features, and ensure product-related security findings are accurately triaged, routed to engineering owners, and mitigated within SLAs. Day-to-day responsibilities include conducting deep-dive security reviews on new feature designs, triaging complex bug bounty submissions, and working directly with engineering teams to resolve vulnerabilities from bug bounties, SAST, fuzzing, and penetration tests. A key aspect of this role is identifying manual process bottlenecks and writing code to integrate AI/LLM solutions for automating initial triage and data enrichment, building tools to handle security findings at scale. Your work sits at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Key responsibilities: - Implement AI-driven tools and scripts to automate code analysis, optimize triage, and streamline Product Security workflows - Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features - Manage the operational lifecycle of product security findings, ensuring vulnerabilities are verified, mapped to correct owners, and tracked to mitigation - Perform technical triage and validation of external Bug Bounty submissions, verifying exploitability and evaluating business risk - Support internal and external penetration testing engagements by reviewing findings and assisting development teams with remediation - Partner closely with DevOps and product teams as a reliable security point of contact Ideal candidates have 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms, demonstrated ability to build production-grade automation scripts leveraging AI/LLMs, competency in threat modeling methodologies, experience tracking and driving vulnerability remediation across engineering groups, and strong cross-functional collaboration skills.

Similar roles