About the role
to join our dynamic and growing Security Threat Detection, Response and Emulation team. This is a critical role that will be at the forefront of protecting our company from malicious and negligent insider activities. You will be responsible for leading the technical aspects of our Insider Threat program, including investigations, threat hunting, and the development of cutting-edge detections and responses.
Responsibilities, requirements, fit, evidence and preparation are organized here. The original posting stays available for final verification.
What they’re looking for
Select a requirement to inspect fit, evidence or application context.
- 5+ years of experience in a technical security role, with at least 2+ years focused on insider threat, digital forensics, or security investigations.
- Proven experience in conducting and leading complex technical investigations, including the use of forensic tools (e.g., EnCase, FTK, X-Ways, or open-source alternatives).
- Deep understanding of security technologies such as SIEM (e.g., Splunk, Elastic), EDR (e.g., CrowdStrike, SentinelOne), and UEBA like data sources.
- Strong scripting and programming skills (e.g., Python, PowerShell) to automate tasks and analyze large datasets.
- Excellent communication skills, both written and verbal, with the ability to explain complex technical concepts to non-technical audiences.
- Experience working with legal and HR teams on sensitive employee-related matters.
Helpful, not always essential
- Certifications such as GCIH, GCFA, GCTI, or similar.
- Experience with cloud-based security and investigations (e.g., AWS, GCP, Azure).
- Prior experience in a tech product or fast-paced startup environment.
- Knowledge of legal and regulatory frameworks related to data privacy and digital evidence (e.g., GDPR, CCPA).
- Legal/Court evidence handling, presentation and implementation of procedures
How they work
- Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.
Eligibility
export laws without sponsorship for an export license.
How to apply
- Please tell us if you require a reasonable accommodation to apply for a job.
- If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St.
About Cloudflare
✓ Verified
We're not looking for people who wait for a polished roadmap. We're looking for builders — people who spot the "normalized" problem everyone else has learned to live with and have the curiosity and drive to fix it. Our culture is built on iteration, leveraging AI to move faster and sharing every improvement across the team. If you value curiosity over bureaucracy and see AI as a partner in solving hard problems, you'll fit right in.
If this one isn’t right.
Related live opportunities you can compare without restarting your search.
Direct employer source
Aptiora keeps the source available for trust and final verification while the working experience stays here.