Cloudflare logo
Cloudflare

Cloudflare, Inc. protects online applications without installing software, adding hardware, or changing lines of code. The company’s internet properties help

Network Security Engineer

Location

Singapore

Posted

2 days ago

Salary

0

Seniority

Mid Level

English

Job Description

Network Security Engineer

Cloudflare

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the World's Most Innovative Companies by Fast Company. At Cloudflare, we're not looking for people who wait for a polished roadmap; we're looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you're the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you'll fit right in. Available Location: Singapore About the Team The Cloudflare Customer Support Team solves complicated problems and answers technical questions via phone, email, chat and social media. Whether it is a Wordpress blogger using our services for free or a global Enterprise business with petabytes of web traffic, we are always eager to assist. We are the eyes and ears of Cloudflare, acting as the real-time voice of the customer to help communicate their needs and real-world use cases back to the rest of the company - for better service and future product development. What You'll Do Do you love solving complex technical issues and interacting with people? Are you passionate about providing premium-level support to customers and are a standout colleague? Cloudflare is seeking an experienced Network Security Engineer to join our team and support our largest and most technically sophisticated customers in resolving technical problems, threats or attacks on their infrastructure at OSI Layers 3, 4, and 7. This will span the range of Cloudflare products from Magic Transit Infrastructure Protection, Argo Smart Routing, DDoS mitigation and Network Firewall, to using the Web Application firewall (WAF), Spectrum and Rate Limiting to help customers. - Serve as a trusted technical advisor for our enterprise customers, responding to and resolving inquiries and incidents related to network security and performance, while delivering timely, high-quality and personalized assistance. - Work directly with customers to diagnose, troubleshoot and resolve complex technical issues involving DDoS mitigation, firewall rules, SSL/TLS, network confirmation, and other security configurations. - Create and maintain knowledge base articles, technical guides, and troubleshooting documentation for internal and customer use. - Compare traffic signatures and attributes including IP addresses, cookie variations, HTTP headers, and JavaScript footprints to determine what is good traffic and what is malicious - DDoS mitigation for OSI layers 3,4, & 7: advise customers on how to filter malicious traffic using Cloudflare tools like Magic Transit, Network Firewall, WAF, IP reputation lists, packet inspection, blocklisting, allowlisting, and rate limiting - Work with Engineering and Product teams to improve products and tools - Utilize generative AI and automation tools to streamline log analysis, accelerate root-cause analysis during security incidents, and optimize customer response times. What We're Looking For - You have a minimum of 4 years experience working as a Network Security Engineer / Technical Support Engineer / Sr. Support Engineer supporting networking or web security products. - Exceptional troubleshooting and problem-solving skills, with the ability to simplify complex concepts for customers. - Strong customer service orientation and communication skills - Ability to work independently and collaboratively in a fast-paced, dynamic environment. - Strong understanding of network protocols, including TCP/IP, DNS, HTTP/S, and BGP, with a particular focus on anycast routing concepts and implementation, as well as tools such as iptables and looking glass. - Proven experience troubleshooting network connectivity issues, BGP routing, and GRE tunnels, and performing packet capture analysis - Confident with command line and tools, including curl, dig, traceroute, openssl, git - Experience in a web development and / or hosting environment such as installing and configuring web servers like Apache, Nginx, Caddy and IIS. - You are competent at writing scripts in Bash, Python, JavaScript or other scripting languages. - You have worked with PostgreSQL, MySQL, MS SQL, and other database servers. - Bachelor's degree in Computer Science, Cybersecurity, or a related field (or equivalent experience). - Relevant certifications such as CISSP, GCIA GCIH, GCFA, GCFE or equivalent. What Makes Cloudflare Special? We're not just a highly ambitious, large-scale technology company. We're a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet. Project Galileo: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare's enterprise customers--at no cost. Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states. 1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here's the deal - we don't store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers. Sound like something you'd like to be a part of? We'd love to hear from you! Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process. This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license. Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer. Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Related Categories

Related Job Pages

More Security Engineer Jobs

Highmark Health logo

Associate Information Security Engineer

Highmark Health

Creating remarkable health experiences, freeing people to be their best.

Full TimeRemoteTeam 10,001+Since 1852H1B Sponsor

• Assists teams in clearly defining requirements, deliverables and timeframes • Escalate issues and make recommendations to resolve them • Assists in conducting root cause analysis to identify and resolve complex problems • Assists in developing and/or delivering technical training in less complex areas • Assists in completing project tasks to enable on time, within budget delivery of ISRM Infrastructure projects • Assists to implement, monitor, configure, and maintain security systems.

Louisiana + 4 moreAll locations: Louisiana | North Carolina | Maryland | Pennsylvania | Washington
$68.4K - $105.9K / year
Vultr logo

Senior Security Engineering Architect

Vultr

Vultr is on a mission to make high-performance cloud computing easy to use, affordable, and locally accessible.

Full TimeRemoteTeam 201-500Since 2014H1B No Sponsor

• Own and maintain the organization's baseline security standards for Linux hardening, VM image governance, container and Kubernetes security, and CI/CD pipeline security controls, ensuring standards are practical, well-documented, and easy for engineering teams to adopt • Act as the primary bridge between Security, Compliance, and Engineering, translating regulatory and policy requirements into concrete, implementable guidance without blocking delivery velocity • Engage engineering squads in a consultant capacity, embedding into team workflows to assess current security posture, identify gaps, and deliver actionable remediation plans across bare metal, virtual, and container environments • Partner closely with the DevSecOps Engineer to identify security controls that can be codified, ensuring hardening standards, compliance checks, and policy enforcement are built into images, configuration management pipelines, and CI/CD workflows rather than left as manual processes • Champion secure-by-default practices by making security requirements visible early in the design and architecture phase, before engineering teams build • Own the security review process for infrastructure architecture changes, partnering with SecOps on tooling and third-party integration reviews to ensure engineering context and requirements are represented • Develop and maintain accessible runbooks, playbooks, and onboarding materials that enable engineering teams to self-serve security best practices across bare metal, virtual, and container environments • Build and maintain cross-functional relationships to surface emerging risks early, synthesizing findings from engineering teams into prioritized remediation work that can be automated and scaled • Represent engineering's security needs in compliance and risk discussions, ensuring security strategy stays grounded in operational realities • Measure program effectiveness through adoption metrics, policy compliance rates, and mean-time-to-remediate trends, using data to continuously improve both the standards themselves and how they are communicated

Alabama + 32 moreAll locations: Alabama | Arizona | Colorado | Connecticut | Florida | Idaho | Illinois | Iowa | Kentucky | Louisiana | Montana | Nebraska | Nevada | New Jersey | New Mexico | New York | North Carolina | Ohio | Oklahoma | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Pennsylvania | Rhode Island | South Carolina | Tennessee | Texas | Utah | Vermont | Virginia | Wisconsin
$130K - $145K / year
Semgrep logo

Senior/Staff Security Researcher

Semgrep

Semgrep is a code scanning platform for finding first and third-party security vulnerabilities in your code base.

Full TimeRemoteTeam 51-200Since 2017H1B No Sponsor

• Build detection at scale. Design and ship security workflows that combine deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk, and beyond) across many languages and frameworks. • Make LLMs viable for security-critical work. Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy: atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and which models see sensitive code. • Push on hard problems in automated triage and validation. Help close the gap between 'a finding exists' and 'this finding is real and worth a developer’s time,' so we can run workflows broadly and validate results at scale rather than by weeks of manual review. • Build and defend quality with evals. Design benchmarks and evaluation loops grounded in real customer codebases, not just synthetic datasets, so we actually know when a workflow is good. • Encode security judgment into tooling. Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems. • Learn new territory fast. Dive into unfamiliar languages, frameworks, and technologies, figure out how vulnerabilities manifest there, and turn that understanding into detection. • Prototype new products. Partner with Engineering and Product to conceive, prototype, and validate new capabilities, writing real (if not always production-grade) code, with a strong sense for the customer and the user. • Share your work. Publish blog posts, give talks, produce cheat sheets and workshops, and represent Semgrep’s research to the wider community. • Lead and plan research with impact. Set the direction for research based on industry trends, emerging threats, and where the field is heading, and turn that into work that moves our products and the broader security community forward.

Arizona + 20 moreAll locations: Arizona | California | Colorado | Connecticut | District Of Columbia | Florida | Illinois | Nebraska | New Jersey | New York | North Carolina | Oregon | Maryland | Massachusetts | Michigan | Missouri | Tennessee | Texas | Virginia | Washington | Wisconsin
$190K - $319K / year

IAM Specialist

NATIONMIND LLC

NationMind LLC is a technology consulting firm focused on Technical Engineering, software development, technicians, QA testing and services. We help clients build reliable, scalable applications with a strong emphasis on automation, performance, and quality. Our team works across industries, delivering solutions that drive innovation and operational efficiency.

Role Description We are seeking an experienced Identity and Access Management (IAM) Specialist to support user access administration in an ITAR-regulated environment. The ideal candidate will have strong experience with Microsoft Entra ID (Azure AD), Identity Governance & Administration (IGA), RBAC, Active Directory, and access governance while ensuring compliance with regulatory requirements. Qualifications - 3–5 years of experience in Identity and Access Management (IAM) / User Access Management - Experience managing user access in regulated ITAR environments - Strong understanding of Role-Based Access Control (RBAC) - Strong understanding of Identity Governance - Strong understanding of Access Certification processes - Hands-on experience with Active Directory - Hands-on experience with LDAP - Hands-on experience with UNIX - Hands-on experience with Mainframe - Hands-on experience with Microsoft Exchange Administration - Experience with Microsoft Entra ID - Experience with Identity Governance & Administration (IGA) - Experience with Single Sign-On (SSO) - Experience with Multi-Factor Authentication (MFA) - Experience with Conditional Access - Experience with user provisioning, deprovisioning, and access review processes - Strong analytical, audit, and documentation skills Requirements - Experience supporting ITAR-regulated environments - Strong understanding of access governance and compliance controls - Experience conducting User Access Reviews - Experience conducting Entitlement Reviews - Experience conducting Access Certification - Experience implementing and managing Role-Based Access Control (RBAC) - Ability to manage access requests and approvals - Hands-on experience with Microsoft Entra ID - Hands-on experience with IGA - Hands-on experience with SSO - Hands-on experience with MFA - Hands-on experience with Conditional Access - Excellent stakeholder communication skills Good-to-Have Skills - Knowledge of SOX and other regulatory compliance frameworks - Experience with ServiceNow workflows - Automation and scripting experience - Experience supporting Aerospace, Defense, or Manufacturing organizations Key Responsibilities - Manage user access requests across ITAR and non-ITAR systems. - Perform provisioning and deprovisioning activities in compliance with regulatory requirements. - Conduct user access reviews, certifications, and audit support activities. - Enforce Role-Based Access Control (RBAC) and least-privilege access principles. - Investigate and resolve user access-related issues. - Maintain IAM documentation, SOPs, and compliance evidence. - Coordinate with Security, Audit, and Business teams to ensure ITAR compliance.

United States
$40 - $45 / hour