Senior Product Security Engineer

Webhosting

Austin (TX)

On-site

USD 180,000 - 240,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity plan

Job summary

Cloudflare is seeking a Senior Product Security Engineer to lead security assessments and vulnerability operations for core software products. You will analyze system architecture, model threats, and triage findings to engineers with SLAs in mind.

You will write code, integrate AI/LLMs for initial triage, and build tools to handle security findings at scale, sitting at the intersection of Product Security, Vulnerability Operations, and AI tooling.

Qualifications

  • Extensive Product/AppSec experience in large-scale cloud environments or SaaS.
  • Hands-on AI/LLMs for automation and operational solutions.
  • Threat modeling methodologies (e.g., STRIDE) with business context.
  • Lifecycle ownership of vulnerabilities across multi-stakeholder teams.
  • Strong cross-functional leadership and communication.
  • Familiarity with offensive security tooling and testing methods.
  • Experience scaling crowdsourced security programs (HackerOne/Bugcrowd) or agile workflows in JIRA.
  • Experience integrating hardware security features into production code.

Responsibilities

  • Autonomously drive AI security innovations and build automation to scale workflows.
  • Lead security architecture reviews and threat modeling across distributed systems.
  • Own vulnerability triage, routing, and remediation within SLAs.
  • Oversee bug bounty triage and validation based on exploitability and risk.
  • Shape internal pentest scope and liaise with developers for remediation.
  • Mentor engineers and foster security champions across teams.

Skills

Senior Product/AppSec
AI & Automation
Threat Modeling
Vulnerability Lifecycle
Influence & Communication
Offensive Security
Program Management
Hardware Security Integration

Tools

HackerOne
Bugcrowd
JIRA

Job description

Available Locations:

Austin, TX

About the role

As a Senior Product Security Engineer, you will lead security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.

On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Responsibilities
  • Autonomously Drive AI Security Innovation:Proactively identify gaps in our current capabilities and independently architect, build, and deploy AI-driven solutions to automate code analysis, optimize triage, and scale Product Security workflows.
  • Security Architecture & Threat Modeling:Lead deep-dive security reviews and complex threat modeling sessions across distributed systems, embedding strict security requirements into product designs before development begins.
  • Product-Focused Vulnerability Management:Own the lifecycle of product security findings. Ensure vulnerabilities are accurately triaged, mapped to the correct engineering owner, and mitigated in alignment with established SLAs.
  • Bug Bounty Leadership:Oversee the technical triage and validation of Cloudflare’s external Bug Bounty program, prioritizing submissions based on real-world exploitability and business risk.
  • Pentest Strategy & Support:Shape the scope of internal and external penetration testing engagements, serving as the technical liaison to ensure findings are deeply understood and remediated by development teams.
  • Strategic Influence & Mentorship:Act as a force-multiplier for security across Cloudflare; mentor junior engineers, cultivate security champions within engineering organizations, and establish modern, paved-road developer guardrails.
Desirable Skills, Knowledge, and Experience:
  • Senior-Level Product/AppSec Expertise:Extensive, battle-tested experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering:Demonstrated ability to build production-grade automation scripts and tools . Must possess hands‑on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Advanced Threat Modeling & Risk Analysis:Mastery of threat modeling methodologies (e.g., STRIDE) and an analytical mindset capable of translating complex theoretical risks into prioritized, actionable business context.
  • Vulnerability Lifecycle Ownership:Proven track record of managing, routing, and driving the remediation of vulnerabilities across multi-stakeholder engineering organizations while strictly enforcing SLAs.
  • High Influence & Communication:Superb cross-functional leadership skills; the ability to confidently influence senior engineering leaders, resolve ownership ambiguity, and champion security initiatives without explicit authority.
  • Offensive Mastery:Familiarity with offensive security tooling and modern exploitation techniques used during professional penetration testing.
  • Program Management Experience:Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases
Equity

This role is eligible to participate in Cloudflare’s equity plan.

Project Galileo : Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use – it is the first consumer-focused service Cloudflare has ever released. Here’s the deal – we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer – Hybrid
Product Security Engineer – Hybrid

Webhosting • Austin (TX)

On-site
USD 140,000 - 200,000
Equity plan
Health & welfare benefits
Time off
Product Security Engineer
Product Security Engineer

Cloudflare • Austin (TX)

On-site
USD 140,000 - 210,000
Equity plan
Medical Insurance
401(k) Retirement Savings
+1
Engineering Manager – Security Platform
Engineering Manager – Security Platform

Webhosting • Atlanta (GA)

Hybrid
USD 180,000 - 230,000
Equity plan
Senior Product Security Engineer
Senior Product Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 180,000 - 240,000
Equity
Medical Insurance
Dental Insurance
+4
Detection & Mitigation Engineer
Detection & Mitigation Engineer

Webhosting • Austin (TX)

On-site
USD 120,000 - 180,000
Equity plan eligibility
GRC Engineer
GRC Engineer

Webhosting • Austin (TX)

On-site
USD 140,000 - 210,000
Equity plan
Lead Vulnerability Management Engineer
Lead Vulnerability Management Engineer

AI Chopping Block • Austin (TX)

On-site
USD 140,000 - 190,000
Equity
Medical Insurance
401(k) Plan
+1
Lead Vulnerability Management Engineer
Lead Vulnerability Management Engineer

Triwill Group • United States

Hybrid
USD 160,000 - 210,000
Equity plan
Health insurance
401(k)
Senior Manager, Solutions Architecture, AI & Developer Platform
Senior Manager, Solutions Architecture, AI & Developer Platform

CloudFlare • Austin (TX)

On-site
USD 234,000 - 336,000
Equity plan
Health & Welfare Benefits
401(k) Retirement Savings Plan
+6
Systems Engineer, Product Platform Tools
Systems Engineer, Product Platform Tools

Webhosting • Austin (TX)

On-site
USD 120,000 - 180,000