Responsibilities
- Provide premium-level support for Cloudflare's security products and features.
- Analyze threats using customer-facing dashboards and internal tools, make detailed and informed suggestions for mitigation, and may implement mitigation strategies directly on behalf of the customer with appropriate approval.
- Provide 24x7x365 proactive monitoring via internal alerting systems, near real-time analysis of security events, and attack reporting beyond Cloudflare's self-service reports.
- Monitor and investigate proactive alerts to identify attacks.
- Work with Engineering and Operations teams to mitigate attacks, suggest steps to mitigate, and apply the appropriate mitigation when applicable.
- Work with Engineering and Product teams to improve products and tools.
- Communicate with customers via chat, email, and phone.
- Review alerts to determine relevancy and urgency; create tracking tickets for incidents requiring review or escalation.
- Adhere to SOC SLAs for alert response and customer communication.
- Configure and manage security monitoring rules; contribute to tool and threshold improvements.
- DDoS mitigation for OSI Layers 3, 4, & 7: filter malicious traffic using Cloudflare tools including Magic Transit, Magic Firewall, Advanced TCP Protection, WAF, Custom Rules, IP Access Rules, and Rate Limiting.
- Maintain customer-specific SOC runbooks and escalation matrices.
- Support SOC customer onboarding and deliver monthly security reviews.
Requirements
- Strong understanding of internet protocols (TCP, UDP, ICMP, GRE, BGP).
- Networking fundamentals are crucial for success.
- Analysis of traffic for attack anomaly detection and creation of mitigation rules.
- Experience handling attack mitigation with knowledge of L3/4 and L7 attacks.
- Command line / Bash shell proficiency.
- Customer Facing or Technical support experience is mandatory.
- Strong communication skills, including with VIP customers during active attacks.
- Ability to remain calm under pressure.
- Ability to work 24x7 rotating shifts.
Nice to Have
- Sysadmin skills - Linux, Mac, or Windows (Preferred).
- Knowledge of Cloudflare Security Products & Features (Preferred).
- Scripting skills, Python preferred (Preferred).
- Prometheus/Grafana monitoring experience (Preferred).
- Packet capture tools such as tcpdump or Wireshark (Preferred).
- API/GraphQL experience (Nice to have).
- Security certifications: GCIA, GCIH, GCFA, GCFE, CISSP equivalent (Strongly preferred).
- Network certifications: CCNA, CCNP (Nice to have).
Work Arrangement
Hybrid
Additional Information
- Ability to work 24x7 rotating shifts.