Response Engineer (Application & Network Security)

Cloudflare

Bengaluru

On-site

INR 1,200,000 - 2,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cloudflare Bengaluru is seeking a skilled Security Operations Center professional to monitor, analyze, and respond to real-time threats affecting enterprise customers. You will work with CMDC tooling to mitigate DDoS and application-layer attacks while maintaining incident tickets and customer communications.

The role requires hands-on experience in SOC or network operations, strong networking knowledge, and scripting abilities (Python preferred).

Qualifications

  • 3–5 years of experience in SOC, technical support engineering, or network operations environment.
  • Foundational networking concepts including TCP/IP, UDP, ICMP, DNS and BGP.
  • Proficiency with command line and system administration across Linux, macOS, or Windows.
  • Customer-facing technical support experience with strong communication during high-pressure incidents.

Responsibilities

  • Monitor and investigate proactive security alerts to rapidly identify ongoing infrastructure and application-layer attacks.
  • Apply mitigation steps and filter malicious traffic using Cloudflare security tools (Magic Transit, WAF, Rate Limiting).
  • Review alerts to determine urgency, scope, and validity; maintain incident tickets.
  • Communicate technical updates clearly with enterprise customers via chat, email, and phone during active security incidents.
  • Adhere to customer SLAs for alert response, analysis, and ongoing communications.
  • Maintain and update customer-specific runbooks, thresholds, and escalation matrices for seamless incident handling.
  • Collaborate with Engineering and Product teams to provide feedback on tools and suggest improvements for automation.

Skills

Networking fundamentals
TCP/IP
UDP
ICMP
DNS
BGP
Bash scripting
Python
Wireshark
tcpdump

Tools

tcpdump
Wireshark

Job description

About the Department

Cloudforce One is Cloudflare's threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world's largest global networks can provide. The team analyzes these unique data points at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our custome rs.About INTERD

ICT
I.N.T.E.R.D.I.C.T. (Identify, Neutralize, Triage, Engage, Respond, Disrupt, Integrate, Contain, Threat Hunting) is Cloudforce One's unified operational security organization responsible for identifying, analyzing, and responding to threats targeting Cloudflare and its customers. INTERDICT encompasses three main sub-functi

  • ons:
    PhishGuard: Managed email threat detection and response se
  • rviceCloudflare Managed Defense (CMD): Network and application security monitoring for 'Under Attack' mitigation sup
  • Detection Engineering: ML model development and detection optimiz

ationTogether, INTERDICT provides comprehensive 24×7×365 protection across email, application, and network threat surf

aces.
Role Sum

Response Engineer within the Cloudflare Managed Defense Center (CMDC) provides front-line technical monitoring and threat mitigation for Cloudflare’s premium enterprise customers. In this role, you will proactively monitor internal alerting systems to identify, analyze, and mitigate real-time security events across OSI Layers 3, 4, and 7. Working alongside senior engineers and operational teams, you will execute established runbooks to protect complex customer infrastructure from sophisticated DDoS and application-layer attacks. We are looking for a collaborative, analytical professional who remains calm under pressure and is eager to develop their security expertise within a fast-paced envir

onment.
Role Responsibi
  • lities:-
    Monitor and investigate proactive security alerts via internal telemetry systems to rapidly identify ongoing infrastructure and application-layer
  • attacks.Apply appropriate mitigation steps and filter malicious traffic using Cloudflare’s core security tools, including Magic Transit, Web Application Firewall (WAF), and Rate
  • Limiting.Review incoming alerts to determine urgency, scope, and validity, while accurately maintaining incident tracking tickets for necessary esc
  • alations.Communicate technical updates clearly and professionally with enterprise customers via chat, email, and phone during active security i
  • ncidents.Adhere to strict customer SLAs for alert response times, event analysis, and ongoing operational commun
  • ications.Maintain and update customer-specific runbooks, threshold rules, and escalation matrices to ensure seamless incident e
  • xecution.Collaborate with internal Engineering and Product teams to provide feedback on tools and suggest improvements for ale
rt rules.
Role Requirements (Must-Have
  • Skills):-
    A minimum of 3–5 years of relevant hands-on experience in a Security Operations Center (SOC), technical support engineering, or network operations e
  • nvironment.Strong foundational understanding of networking principles and internet protocols, including TCP/IP, UDP, ICMP, DN
  • S, and BGP.Experience analyzing network traffic data for anomaly detection and executing basic mitigation protocols against L3/L4 or
  • L7 attacks.Professional proficiency using the command line (Bash shell) alongside general system administration literacy across Linux, Mac, or Windows en
  • vironments.Proven customer-facing technical support experience, with the communication skills required to assist stakeholders during high-pressure
  • nus Points:-
    Hands-on experience with packet capture and network analysis tools such as tcpdump
  • or Wireshark.Foundational scripting skills (Python preferred) to assist in automating basic operation
  • al workflows.Familiarity with querying datasets via APIs/GraphQL or monitoring performance metrics inside Prometheus and Grafan
  • a dashboards.Relevant industry certifications, such as CompTIA Security+, CCNA, or foundational GIAC credentials
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst
Senior Incident Response Analyst

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,500,000 - 2,800,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
Cyber Security Engineer (Technical Role)
Cyber Security Engineer (Technical Role)

BDx Data Centers • Navi Mumbai

On-site
INR 1,500,000 - 2,500,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
SOC Specialist
SOC Specialist

METRO/MAKRO • Pune District

On-site
INR 4,000,000 - 7,000,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

Larsen & Toubro • Chennai District

On-site
INR 2,500,000 - 4,000,000
Cyber Security Engineer (Technical Role)
Cyber Security Engineer (Technical Role)

BDx Data Centers • Navi Mumbai

On-site
INR 1,200,000 - 2,000,000
Security Engineer / Cybersecurity Specialist
Security Engineer / Cybersecurity Specialist

Codvo.ai • Pune District

On-site
INR 800,000 - 1,200,000