Incident Response Engineer
CloudflareIn-3w ago
Engineeringremotecurated-jd
Job description
Incident Response Engineer at Cloudflare.
About the role
You will serve as a primary human intelligence layer for the PhishGuard service, focusing on the detection and mitigation of complex email threats like vendor fraud and Business Email Compromise. This position involves direct collaboration with internal security teams to hunt adversaries and refine detection models using data from our global network.
Key facts
What you'll do
- Monitor email threat queues in real-time to analyze attacks flagged by automated systems.
- Investigate customer submissions and conduct proactive threat hunting to remove malicious emails.
- Provide data to Detection Engineering to improve machine learning models and threat intelligence repositories.
- Correlate technical telemetry with behavioral indicators to create threat dossiers.
- Manage crisis communications for customers regarding high-stakes BEC and insider threats.
- Perform technical onboarding for new customers, including setting up custom detection rules and block lists.
- Assist customers with DMARC implementation and SPF/DKIM alignment audits.
Requirements
- Undergraduate degree in Computer Science, Information Security, Information Systems, or equivalent practical experience.
- 5+ years of experience analyzing cyber campaigns using domains, IP addresses, and email headers.
- Expertise in defending against phishing, invoice fraud, and Business Email Compromise.
- Working knowledge of email authentication protocols including SPF, DKIM, and DMARC.
- Hands-on experience using AI LLM tools like OpenCode or Windsurf to automate workflows.
- Strong English verbal and written communication skills for reporting to executive stakeholders.
Nice to have
- Industry certifications such as GCIH, GCIA, CEH, or Security+.
- Proficiency with regular expressions, YARA rules, SQL, and analysis of malicious file formats like PDF or Microsoft Office documents.
- Experience in managed security services or customer-facing security consulting.
- Familiarity with Cloudflare Email Security, WAF, and Zero Trust architectures.
Skills & tools
- Email Security Protocols (SPF, DKIM, DMARC)
- AI LLM Tools (OpenCode, Windsurf)
- Threat Hunting & Forensic Analysis
- Business Email Compromise (BEC) Defense
- SQL, YARA, Regular Expressions
Practical notes
- Applicants reaching the offer stage may be required to attend an in-person interview at a Cloudflare office or hub.
- This role may require access to information subject to U.S. export control laws. Offers may be conditioned on the ability to receive controlled technology without the need for an export license sponsorship.