Senior Product Security Engineer

Cloudflare, Inc

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Austin, TX
Posted
51 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $182k
$133k most similar roles pay here $225k

This listing doesn't post a salary. Most similar roles pay $151,493–$212,625.

Based on 240 similar postings.

Employer

About Cloudflare, Inc

Cloudflare is a prominent cloud services and security company that provides content delivery network (CDN), DDoS mitigation, and Zero Trust security services to millions of internet properties.

Cloudflare, Inc currently has 190 open roles on FindRole.

Listed pay typically runs $215,000–$278,000 across 59 roles with salary data.

Most-posted roles

View all roles at Cloudflare, Inc

At a glance

TL;DR · Senior Product Security Engineer

Senior Product Security Engineer As a Senior Product Security Engineer, you will join the team to lead security assessments and vulnerability operations for core software products. You will perform deep-dive security reviews on new features, conduct complex threat modeling using methodologies like STRIDE, and manage the full lifecycle of product security findings. Your daily work involves triaging bug bounty submissions, coordinating with engineering teams to mitigate vulnerabilities from SAST, fuzzing, and penetration tests, and ensuring all fixes meet established SLAs. To scale these operations, you will write code and integrate AI/LLM solutions to automate triage and data enrichment. The role requires expertise in distributed cloud environments, systems security research, and automation engineering. You will serve as a technical liaison for penetration testing while building internal tools to streamline manual processes within the product security and vulnerability management domains.

What you'll do

  • Lead security assessments and threat modeling sessions for core software products and distributed systems.
  • Manage the full lifecycle of product security findings to ensure they are triaged and remediated within SLAs.
  • Oversee the technical triage and validation of submissions from the external Bug Bounty program.
  • Develop and deploy AI/LLM-driven tools to automate code analysis, data enrichment, and security workflows.
  • Act as a technical liaison for penetration testing engagements to ensure findings are understood and fixed by developers.
  • Build automated systems to replace manual processes and scale product security operations.
  • Mentor junior engineers and establish "paved-road" developer guardrails to improve overall security posture.

What we're looking for

  • Extensive experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Proven ability to build production-grade automation scripts and tools using AI/LLMs to solve technical challenges.
  • Mastery of threat modeling methodologies, such as STRIDE, to translate complex risks into actionable business context.
  • Experience managing the full vulnerability lifecycle, including triage, routing, and remediation within established SLAs.
  • Strong cross-functional leadership skills to influence senior engineering leaders and advocate for security initiatives.
  • Preferred experience in academic or vulnerability research with a focus on systems security.
  • Familiarity with offensive security tooling, modern exploitation techniques, and hardware security integration is a plus.
  • Must be authorized to receive software or technology controlled under U.S. export control laws.

More like this

Similar roles

Product Security Engineer

Cloudflare, Inc

Austin, TX 38 days ago
Application Security LLM SAST Fuzzing Penetration Testing Threat Modeling STRIDE Bug Bounty Triage JIRA Agile Vulnerability Management SaaS
5+ yrs exp Hybrid

Senior Product Security Engineer

Adobe

San Jose, CA 7 days ago $180,600$261,450
OWASP Top 10 CVSS v3.1 Burp Suite Python PowerBI JIRA REST API OAuth2 AWS Lambda API Gateway SQL Injection XSS SSRF IDOR SOAR Webhooks curl DevTools
5+ yrs exp

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Senior Security Engineer I, Product Security

Oscar Health

Tempe, AZ 8 days ago
SAST DAST SDLC Vulnerability Management Code Review AI Integration Model Context Protocol (MCP) Software Development Risk Assessment Source Code Review
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Los Angeles, CA 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Source Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Senior Product Security Engineer I

Oscar Health

New York, NY 58 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Hybrid