Cloudflare Logo

Cloudflare

Senior Security Researcher & Analyst - WAF Application Security Experts

Reposted 10 Days Ago
Be an Early Applicant
Remote or Hybrid
4 Locations
Junior
Remote or Hybrid
4 Locations
Junior
As a WAF Application Security Expert, you will research and improve detection logic, analyze vulnerabilities, develop WAF rules, and automate workflows.
The summary above was generated by AI
Available Locations: London, United Kingdom, Bengaluru India, Singapore & Austin, USA
About the Department
Cloudflare's Application Security organization builds and operates the systems that detect, classify, and mitigate malicious or abusive HTTP traffic across one of the largest networks on the Internet. Our products - including the Web Application Firewall (WAF), Bot Management, and Fraud Detection - protect millions of Internet properties from attacks and abuse in real time.
We combine large-scale data analytics, cutting-edge AI and ML models, and expert threat research to continuously evolve Cloudflare's detection and protection capabilities. The team brings together security researchers, analysts, and engineers who collaborate to identify new attack vectors, create innovative mitigations, and deliver protection at Internet scale.
What You'll Do
As a WAF Application Security Expert, you'll focus on researching, designing, and improving detection logic and rules that protect customer applications from the latest web threats.
  • Analyze web exploits and vulnerability patterns (RCE, SQLi, XSS, SSRF, deserialization, etc.) and build corresponding WAF mitigations.
  • Collaborate with product engineering and data teams to tune detection efficacy - reducing false positives/negatives across large-scale, high-volume traffic.
  • Develop, test, and deploy WAF managed rules and exploit signatures based on public CVEs, threat intelligence, and internal telemetry.
  • Perform targeted penetration testing and red-team style assessments to uncover gaps in Cloudflare's WAF coverage and propose mitigations.
  • Leverage strong coding skills to automate rule validation, testing pipelines, and data analysis workflows.
  • Conduct research on attacker behaviors, evolving exploit chains, and web attack automation trends.
  • Produce internal and external research reports summarizing Internet-wide attack trends and WAF efficacy insights.
  • Collaborate closely with Bot Management, Fraud, and ML teams to design cross-signal detection frameworks that unify WAF and behavioral defenses.
  • Communicate complex technical findings clearly to both engineering and non-technical audiences.
What You Bring
  • Bachelor's or Master's degree in Computer Science, Information Security, or equivalent practical experience.
  • 2+ years of experience in Web Application Security, WAF rule development, incident detection, or threat research.
  • Deep understanding of web protocols (HTTP/HTTPS), common web vulnerabilities, and exploitation techniques (OWASP Top 10).
  • Proven experience writing and optimizing WAF rules or custom detection logic.
  • Hands-on experience with vulnerability analysis, exploit reproduction, or reverse engineering.
  • Strong analytical mindset and comfort working with large data sets (SQL, ClickHouse, BigQuery, etc.).
  • Proficiency in at least one programming language such as Python, Go, or Rust for building automation tools or analysis scripts.
  • Familiarity with Grafana or equivalent visualization tools to track rule performance and attack trends.
  • Strong written and verbal communication skills - able to document, present, and collaborate effectively.
  • Experience working in fast-paced environments with production-scale systems.
Bonus Points
  • Experience with columnar databases like ClickHouse and advanced SQL query optimization.
  • Familiarity with machine learning for security analytics (feature extraction, anomaly detection, model evaluation).
  • Solid understanding of Linux/UNIX systems, TCP/IP networking, and proxy architectures.
  • Prior publications or conference presentations (e.g., Black Hat, DEF CON, BSides).
  • Contributions to open-source WAF projects or web security tools.
  • Knowledge of WAF and bypassing WAF products with novel techniques.
  • Experience on bug bounty/CTF is plus.

Top Skills

BigQuery
Clickhouse
Go
Grafana
Python
Rust
SQL

Cloudflare Denver, Colorado, USA Office

Denver, Colorado, United States, 80014

Similar Jobs at Cloudflare

11 Hours Ago
Remote or Hybrid
2 Locations
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Collaborate with Design Engineers to develop frontend experiences improving developer experience, focusing on coding, aesthetics, and user interactions.
Top Skills: FigmaReactTypescript
11 Hours Ago
Remote or Hybrid
3 Locations
186K-268K Annually
Expert/Leader
186K-268K Annually
Expert/Leader
Cloud • Information Technology • Security • Software • Cybersecurity
The Principal Technical Engagement Manager drives technical adoption of solutions, resolves challenges, and enhances customer satisfaction through strategic leadership and partnership in China.
Top Skills: Advanced NetworkingComplianceCross-Border ConnectivityEdge ComputingHybrid CloudIcp ComplianceLocal Cloud EcosystemsNetwork IntegrationPerformance OptimizationSaseTraffic AccelerationZtna
11 Hours Ago
Remote or Hybrid
3 Locations
231K-300K Annually
Senior level
231K-300K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead a technical team to drive sales strategy for Cloudflare's Developer Platform, mentor architects, enhance product offerings, and collaborate with executives and departments.
Top Skills: Ai/MlCi/CdCloud ArchitectureCloud ComputingDistributed Serverless PlatformsWeb Technologies

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account