SlipstreamJobsFresh Startup & VC-Backed Jobs

Response Engineer - Cloudflare Managed Defense Center (CMDC)

Cloudflare - London, United Kingdom - Hybrid - posted 2026-09-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Cloudflare is seeking a Response Engineer to join the Cloudflare Managed Defense Center (CMDC), part of Cloudforce One's INTERDICT operational security organization. This role is a primary technical responder for Cloudflare's premium enterprise customers, handling complex threat investigations, live incident response for sophisticated DDoS and application-layer attacks, and traffic anomaly analysis during high-pressure events. You will work across Cloudflare's security portfolio, focusing on Web Application Security (WAF and Bot Management) and DDoS mitigation across network and application layers. Using customer-facing dashboards and internal tools, you will make detailed mitigation recommendations and may implement mitigation strategies directly on behalf of customers. The team provides continuous proactive monitoring and analysis of security events through internal alerting systems. Key Responsibilities: - Implement robust mitigation strategies for complex attacks across OSI Layers 3, 4, and 7 using Cloudflare's suite (Magic Transit, Magic Firewall, Advanced TCP Protection, Advanced DNS Protection, WAF, Custom Rules, IP Access Rules, Bot Management, Rate Limiting) - Monitor and investigate proactive alerts, performing near real-time packet and traffic flow analysis to detect protocol exhaustion and application-layer exploitation, translating findings into custom mitigation rules - Review alerts to determine relevancy and urgency, proactively escalate customer-impacting incidents, and adhere to Customer SLAs - Act as primary technical contact for customers during active security incidents, driving consultative communication via phone, chat, and email with customers' technical teams - Continuously tune and optimize existing security monitoring rules and alerting thresholds to improve signal-to-noise ratio and reduce false positives - Lead managed customer onboarding sessions, maintain customer-specific runbooks, and deliver technical monthly security posture reviews and post-incident reports - Partner with internal engineering, product, and threat intelligence teams to provide actionable feedback on attack trends, tooling gaps, and product enhancements Requirements: - 4–7 years of direct, hands-on experience in Managed Detection and Response (MDR), advanced Security Operations, or high-level Technical Support/Incident Response for enterprise infrastructure - Proven capability to handle both Application Security (OWASP Top 10 vulnerabilities, L7 WAF, HTTP/S anomalies, Bot mitigation) and Network Security (L3/L4 volumetric DDoS, protocol abuse) - Working knowledge of threat frameworks such as MITRE ATT&CK to classify adversary behavior - Operational understanding of internet protocols including TCP, UDP, ICMP, GRE, BGP, DNS, with ability to diagnose attack fingerprints and infrastructure impact during volumetric DDoS attacks - Hands-on experience with packet capture tools (tcpdump, Wireshark, tshark) or HTTP traffic inspection (HAR, Burp Suite) - Extensive experience managing technical communications with enterprise customers during high-stress, active attacks, remaining calm under pressure - Ability and willingness to work 24x7 rotating shifts to support global operations - Preferred: Knowledge of industry security technologies (enterprise CDNs, cloud-based DDoS scrubbing centers, Next-Gen WAFs, edge network firewalls) - Preferred: Proficiency in Linux/Unix environments and strong scripting skills (Bash, Python) for workflow automation, including experience with agentic AI environments or LLMs, and experience with REST APIs or GraphQL - Preferred: Experience building or querying dashboards in Prometheus and Grafana - Preferred: Security and networking certifications such as GIAC (GCIA, GCIH, GCFA, GCFE), Cisco CCNA/CCNP, or equivalent hands-on incident response credentials

Similar roles