Product Security Engineer

Cloudflare, Inc

Confirmed live 2 days ago High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Austin, TX
Posted
38 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $181k
$119k most similar roles pay here $236k

This listing doesn't post a salary. Most similar roles pay $149,500–$213,468.

Based on 240 similar postings.

Employer

About Cloudflare, Inc

Cloudflare is a prominent cloud services and security company that provides content delivery network (CDN), DDoS mitigation, and Zero Trust security services to millions of internet properties.

Cloudflare, Inc currently has 190 open roles on FindRole.

Listed pay typically runs $215,000–$278,000 across 59 roles with salary data.

Most-posted roles

View all roles at Cloudflare, Inc

At a glance

TL;DR · Product Security Engineer

As a Product Security Engineer, you will join the team to support security assessments and vulnerability operations for core software products. You will perform deep-dive security reviews on new feature designs, conduct STRIDE threat modeling sessions, and manage the full lifecycle of product vulnerabilities to ensure they are triaged and mitigated within established SLAs. Your daily work involves technical triage of bug bounty submissions, coordinating penetration testing engagements, and collaborating with engineering teams to implement secure coding practices. To scale these operations, you will write code and integrate AI/LLM solutions to automate data enrichment and initial triage processes. The role requires expertise in product security, vulnerability management, and automation engineering within distributed cloud environments. You will utilize tools like JIRA while applying knowledge of fuzzing frameworks and systems security to protect large-scale infrastructure.

What you'll do

  • Conduct structured security reviews and threat modeling sessions for new product features.
  • Manage the full lifecycle of product security findings to ensure timely remediation within SLAs.
  • Perform technical triage and validation of external bug bounty submissions to assess risk.
  • Support internal and external penetration testing by reviewing findings and assisting with remediation.
  • Build AI-driven tools and scripts to automate code analysis and streamline security workflows.
  • Partner with engineering teams to provide security guidance and implement secure coding practices.

What we're looking for

  • Must have 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Must possess hands-on engineering experience building production-grade automation scripts and tools using AI/LLMs.
  • Experience conducting academic or vulnerability research with a focus on systems security is preferred.
  • Proficiency in threat modeling methodologies (e.g., STRIDE) and evaluating code flaws to determine impact.
  • Experience managing the full lifecycle of software vulnerabilities, including triage, routing, and remediation within SLAs.
  • Ability to perform technical triage for bug bounty submissions and coordinate penetration testing engagements.
  • Strong communication skills to collaborate with engineering teams and explain technical security risks.
  • Must be authorized to receive technology controlled under U.S. export control laws without a license.

More like this

Similar roles

Senior Product Security Engineer

Cloudflare, Inc

Austin, TX 51 days ago
Product Security Application Security AI LLM Threat Modeling STRIDE Vulnerability Management SAST Fuzzing Penetration Testing Bug Bounty JIRA Agile SaaS Distributed Systems
Hybrid

Senior Product Security Engineer

Adobe

San Jose, CA 7 days ago $180,600$261,450
OWASP Top 10 CVSS v3.1 Burp Suite Python PowerBI JIRA REST API OAuth2 AWS Lambda API Gateway SQL Injection XSS SSRF IDOR SOAR Webhooks curl DevTools
5+ yrs exp

Senior Security Engineer I, Product Security

Oscar Health

Tempe, AZ 8 days ago
SAST DAST SDLC Vulnerability Management Code Review AI Integration Model Context Protocol (MCP) Software Development Risk Assessment Source Code Review
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Senior Security Engineer I, Product Security

Oscar Health

Los Angeles, CA 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Source Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Staff Product Security Engineer

Reddit

Remote 135 days ago $217,000$303,900
Go Python CI/CD LLM Authentication Authorization Cloud-Native Platforms Product Security Application Security Software Engineering
8+ yrs exp Remote