Available Locations: Austin, TX (US), London (UK)
Cloudforce One is Cloudflare’s threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world’s largest global networks can provide. The team is able to analyze these unique data points, at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers.
Cloudflare’s Trust & Safety team is the frontline defense against platform abuse — phishing, malware distribution, fraud, and content that undermines the safety of the internet. Together, these teams form a unified capability: from tracking an adversary’s infrastructure to dismantling it at network scale.
Cloudflare is a system spanning the globe, on a mission to make the internet better, safer, and more powerful every day. We are looking for a Principal Engineer who is equal parts architect, threat analyst, and disruptor — someone who doesn’t just build systems but fundamentally rethinks how we detect, analyze, and neutralize threats across one of the world’s largest networks.
This is not a role that lives in a single team or a single codebase. You will operate across the full breadth of Cloudflare Products, diving into whatever problem is most critical — whether that’s redesigning a detection pipeline in Kubernetes, deploying a new mitigation capability at the edge via Workers, building agentic AI workflows that automate analyst tradecraft, or architecting a data system that processes trillions of signals per day. You will be the person teams turn to when the problem is ambiguous, the architecture is complex, and the adversary is sophisticated.
Our ideal candidate has deep technical expertise in distributed systems architecture and an equally deep understanding of how threat actors operate — their tactics, techniques, procedures, and infrastructure. You think like an attacker and build like an engineer who has been burned by production incidents at 3 AM. You are energized by hard problems, impatient with the status quo, and have a track record of shipping solutions that others said couldn’t be done.
This role may require flexibility to be on-call outside of standard working hours to address technical issues as needed.