Senior Staff Security Engineer
Job description
About Gusto
At Gusto, we are on a mission to grow the small business economy. We handle the hard stuff - payroll, health insurance, 401(k)s, and HR - so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve. All full-time employees receive competitive base pay, benefits, and equity (RSUs) - because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy. AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.
About the Role
The role owns the end-to-end design, operation, and evolution of Gusto's edge and network security posture, with primary accountability for Cloudflare WAF, DDoS mitigation, Zero Trust, and perimeter controls. You will partner closely with infrastructure and product teams to translate business risk into hardened architectural patterns and policy-as-code implementations. You are expected to act as a force multiplier, raising the security baseline through automation, measurable risk reduction, and hands-on response during live incidents. The position demands deep, hands-on fluency with modern security tooling and the ability to prototype AI-augmented workflows that compress manual effort. You will own the full lifecycle of security features from design through on-call remediation and continuous improvement. This role shapes how engineers and operations teams interact with the network and edge securely.
What You'll Do
- Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
- Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
- Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
- Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
- Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
- Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
- Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own.
- Serve as a technical leader and mentor, elevating the craft of security engineering through code reviews, design documents, and hands-on pairing with infrastructure and product teams.
- Champion reliability and operational excellence for security controls, ensuring that defensive mechanisms are observable, testable, and resilient under load and during active incidents.
- Drive adoption of security standards by building reusable modules, contributing to internal platforms, and evangelizing secure-by-default practices across product teams.
Requirements
- 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
- Deep, production-grade expertise with Cloudflare's platform, including WAF, DDoS protection, Workers, and Zero Trust services.
- Strong experience hardening edge and network architectures, tuning WAF rulesets, and defending through live DDoS events while maintaining availability.
- Expertise in cloud networking on AWS, including VPC design, subnets, routing, NACLs, security groups, and integration with Cloudflare.
- Solid understanding of security and networking fundamentals such as TLS, certificates, DNS, HTTP/S, and common protocols and threats.
- Experience with policy-as-code, infrastructure as code, and configuration management using tools such as Terraform, Crossplane, and similar frameworks.
- Proven ability to build detections, alerting, and incident response playbooks, with fluency in log analysis, telemetry, and SIEMs like Panther.
- Comfort operating in a fast-paced, high-stakes environment where security controls must scale reliably and evolve with product velocity.
Location, Engagement, and Compensation
Location: USA
Engagement: Full-time (40 hours per week). Compensation details were not provided in the source material.