SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 150,000 - 185,000 / annual
Cloudflare's Detection department is seeking a Researcher focused on Web Security Detection to identify and combat automated, fraudulent, and malicious activity across the Internet. You will work at the intersection of security research and detection engineering, translating adversary behavior into actionable defense signals.
Key Responsibilities:
- Reverse-engineer bot tools, automation frameworks, and fraud kits to understand attack mechanisms and evolution patterns
- Conduct adversarial testing against Cloudflare's own detection systems, identifying gaps and staying ahead of attacker adaptation
- Track the bot and fraud ecosystem through tooling, marketplaces, and emerging techniques; convert intelligence into detection signals
- Develop heuristics, signatures, and detection concepts grounded in real adversary behavior, collaborating with Data Scientists and Engineers
- Design mitigations that neutralize attackers while preserving detection signals—avoiding tipping off adversaries to evasion techniques
- Automate manual investigation and rule-writing processes to scale detection capabilities
You will be part of Cloudflare's Engineering team, which handles a significant proportion of Internet traffic and operates at massive scale. The Detection department sits at the heart of protecting millions of websites and Internet properties ranging from individual bloggers to Fortune 500 companies.
Requirements:
- Deep expertise in web technologies: HTTP, TLS, browser internals, fingerprinting, CAPTCHA mechanisms, and evasion techniques
- Demonstrated knowledge of bots, automation frameworks, and tooling used to attack web applications at scale
- Strong ethical hacking and reverse-engineering background with an adversarial mindset
- Ability to translate research findings into concrete detection signals for defenders
- Understanding of how to act on attackers without burning the signals that make them detectable
- Proficiency scripting in languages such as Python or JavaScript to build proofs-of-concept and tooling
- Excellent communication skills for explaining complex attacker behavior to both technical and non-technical audiences