Security Engineer - Cloud and Network Security

United States Digital Space LLC

San Francisco (CA)

Hybrid

USD 210,000 - 270,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC seeks a Security Engineer to lead edge and network security strategy, owning Cloudflare-based defenses and Zero Trust rollouts. You’ll design, implement, and automate security controls at scale, partnering with infra and product teams to reduce risk and accelerate velocity.

The role emphasizes hands-on Cloudflare expertise, policy-as-code, and incident response with AI-native tooling.

Qualifications

  • 10+ years hands-on security engineering experience at scale.
  • Deep production-grade expertise with Cloudflare's security stack (WAF, DDoS, Bot Management, WARP, Gateway, Access).
  • Strong network architecture skills across edge and cloud: TLS/mTLS, VPC, NACLs, egress controls, DDoS resilience.
  • Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane a plus.
  • Generalist foundation across cloud security, IAM, container security, and detection engineering.
  • AI-native working style with Claude Code and agentic tooling; track record of AI-assisted workflows.
  • Excellent written and verbal communication; explain perimeter tradeoffs to diverse stakeholders.
  • Relevant certifications (AWS/Security, Cloudflare, CKS) a plus.

Responsibilities

  • Design and operate edge security stack (Cloudflare WAF, DDoS, Bot Management, WARP, Gateway, Access); tune rules against real traffic.
  • Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, egress filtering; codified in Terraform / Crossplane.
  • Develop policy-as-code patterns for WAF rules and network policies; ship changes via PRs with tests and rollback paths.
  • Build detections and alerting from edge/network telemetry (Cloudflare logs, VPC Flow Logs, CloudTrail) flowing into Panther; lead incident response.
  • Contribute across security engineering surface: cloud posture, container security, IAM, vulnerability mgmt, on-call.
  • Operate as an AI-native engineer using Claude Code, MCP tooling, and agentic workflows.
  • Prototype and ship agents, MCP servers, and LLM-assisted automations that compress work from days to minutes.

Skills

Edge security engineering
Cloudflare WAF
DDoS protection
Zero Trust
Policy-as-code
Terraform
CI/CD security
Incident response
AI-native tooling
LLM automations

Education

Tools

Cloudflare
Wiz
CrowdStrike
Panther
Tines
Terraform
Crossplane

Job description

About the company

At the company, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build the company should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy.

AI is a fundamental part of how work gets done at the company. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

About the Role:

We're looking for a Security Engineer to lead the company's edge and network security strategy, owning the design and operation of our Cloudflare WAF, DDoS protection, Zero Trust, and broader perimeter controls. The ideal candidate brings deep, hands-on Cloudflare expertise and a proven track record of hardening edge and network architectures at scale, including tuning WAF rulesets, defending through live DDoS events, and shipping Zero Trust rollouts engineers actually adopt. You think in terms of layered defense, measurable risk reduction, and automation over manual toil. In this role, you'll serve as a force multiplier across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound over time.

About the Team:

The the company's Enterprise Security Engineering team, a small but high-leverage group responsible for cloud security posture, edge and network defense, container security, secrets management, and endpoint protection across the company. The team runs a modern stack including Cloudflare, Wiz, CrowdStrike, Panther, and Tines, scaling impact through automation, IaC, and AI-augmented tooling. The work carries real stakes, protecting the payroll, benefits, and HR systems that hundreds of thousands of small businesses and their employees rely on every day. The team is engineering-first, with most of the roadmap living in code and a strong emphasis on partnering with infrastructure and product teams rather than gatekeeping them.

Here’s what you’ll do day-to-day:
  • Design and operate the company's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
  • Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
  • Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
  • Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
  • Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
  • Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
  • Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own.
Here’s what we're looking for:
  • 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
  • Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
  • Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs.
  • Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
  • Solid generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience on edge and network telemetry in a modern SIEM.
  • AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output.
  • Excellent written and verbal communication; you can take a complex perimeter decision and explain the tradeoffs to a staff engineer, a PM, and a VP without changing the substance.
  • Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent.

Our cash compensation amount for this role is targeted at $210,000/yr to $230,000/yr in Denver & most remote locations, $230,000/yr to $270,000/yr for San Francisco, New York & Seattle. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

the company has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, the company's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a the company office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at the company.

the company is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. the company considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. the company is also committed to providing reasonable

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Principal Software Engineer - Security Platform
Staff/Principal Software Engineer - Security Platform

Cloudflare • New York (NY)

On-site
USD 185,000 - 275,000
Medical/Rx Insurance
401(k) Retirement Savings Plan
Flexible paid time off
Product Security Engineer
Product Security Engineer

Cloudflare • Austin (TX)

On-site
USD 140,000 - 210,000
Equity plan
Medical Insurance
401(k) Retirement Savings
+1
Engineering Manager - Security Platform
Engineering Manager - Security Platform

Cloudflare • Washington

Hybrid
USD 190,000 - 237,000
Equity
Medical, dental, and vision insurance
401(k) plan with company match
Software Engineer, Network Firewall
Software Engineer, Network Firewall

Triwill Group • United States

Hybrid
USD 140,000 - 200,000
Software Engineer, Network Firewall
Software Engineer, Network Firewall

CloudFlare • Austin (TX)

On-site
USD 120,000 - 190,000
Senior Threat Intelligence Engineer
Senior Threat Intelligence Engineer

Cloudflare • Austin (TX)

On-site
USD 140,000 - 190,000
Equity plan
Health insurance
401(k)
Senior Customer Engineer, Named
Senior Customer Engineer, Named

AI Chopping Block • Philadelphia

On-site
USD 140,000 - 190,000
Medical/Rx Insurance
Dental Insurance
Vision Insurance
+3
Senior Customer Engineer, Named
Senior Customer Engineer, Named

Worky • Philadelphia

On-site
USD 140,000 - 200,000
Health Insurance
401(k) Plan
Paid Time Off
Senior Customer Engineer, Commercial
Senior Customer Engineer, Commercial

Triwill Group • United States

Hybrid
USD 212,000 - 292,000
Health insurance
401(k) plan
Equity
Senior Systems Engineer
Senior Systems Engineer

Cloudflare • Washington

On-site
USD 185,000 - 254,000
Medical/Rx Insurance
401(k) Retirement Savings Plan
Employee Stock Participation Plan
+2