SlipstreamJobsFresh Startup & VC-Backed Jobs

Vulnerability Defense Software Engineer, Cloudforce One

Cloudflare - Remote - Hybrid - posted 2026-10-02

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 150,000 - 206,000 / annual

Cloudforce One is Cloudflare's threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). As a Software Engineer on this team, you will build and evolve systems that help security practitioners assess technical risk, investigate complex systems, prioritize issues, and deliver actionable guidance to engineering teams. You will translate complex security requirements and investigative methods into robust, scalable, and high-performance applications that have a direct impact on making the internet better, safer, and more powerful. The majority of services are written in Go and TypeScript, and you will also work with technologies such as Rust, Kafka, Redis, Kubernetes, Terraform, and PostgreSQL. You will extensively use Cloudflare's own developer platform. Key responsibilities include: - Design, build, run, and scale distributed tools and services that translate security tradecraft into scalable, evidence-based systems and workflows - Partner with security practitioners to understand workflows, bottlenecks, and opportunities for automation - Improve system design and architecture to ensure stability, performance, and maintainability of both internal and customer-facing services - Analyze, communicate, and help prioritize complex technical concepts across teams - Mentor and guide other developers in the team, helping to build collective technical expertise and promote best practices for writing well-tested, modular, and reusable code This role may require flexibility to be on-call outside of standard working hours to address technical issues as needed. QUALIFICATIONS: Desirable skills and experience include: - Working knowledge of cybersecurity concepts such as threat modeling, attack techniques, trust boundaries, exploitability, and defensive controls - Familiarity with incident response workflows, network containment, and remediation - Practical experience in vulnerability research/exploit development and translating findings into actionable mitigations - Experience with AI-assisted development and designing agentic AI workflows - At least 5 years of experience building large-scale software applications, preferably distributed systems - Experience designing and integrating RESTful APIs and/or gRPC services - Knowledge of SQL and common relational database systems such as PostgreSQL - Ability to independently define and deliver solutions in ambiguous problem spaces - Prior experience writing production-ready code in Go and/or TypeScript - Excellent debugging and optimization skills - Expertise in writing well-tested code - Interest in opportunities to be a technical mentor for teammates Bonus/nice-to-have skills: - Application security, security research, or security automation experience - Deep understanding of DNS, TLS/SSL and HTTP - Experience evaluating probabilistic systems

Similar roles