Security Researcher & Analyst - Application Security

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Singapore
Remote
Hybrid
Mid level
Cloud • Information Technology • Security • Software • Cybersecurity
Helping Build a Better Internet
The Role
The Security Researcher & Analyst role focuses on enhancing application security by detecting, mitigating, and analyzing threats and vulnerabilities. The candidate will engage in hands-on security research, conduct penetration testing, and develop security tools. Responsibilities also include communicating security findings and trends, and collaborating with teams to implement effective security measures.
Summary Generated by Built In

Available Location: Singapore About the department
Cloudflare's Application Security department builds and runs the software that detects and mitigates malicious, abusive, and fraudulent HTTP requests going through Cloudflare network before they reach our customer sites. We achieve this by harnessing the vast amount of internet traffic data available to us to create and manage products including WAF, Bot Management, Fraud Detection and more. We use state of art Artificial Intelligence and Machine Learning techniques in security attack detection and mitigation. The team is a multidisciplinary team where system and software engineers, security researchers and analysts, and data scientists work together to identify active adversaries or attackers, and design and implement machine learning models and engineering solutions to protect customers from these security attacks.
What you'll do

  • Hands-on experience working with threat detection and prevention product engineering teams, recognizing vulnerabilities and configuring mitigations or managing risks in existing and new products.
  • Apply a deep understanding of security vulnerabilities in web application and application security.
  • Reverse and research n-day exploits, proactively detect patterns of bot and fraud attacks, review false positive and false negative reports, and recommend security configurations.
  • Excellent at communicating the details about security forensics to technical and non-technical audiences. Including writing public facing research blogs.
  • Authoring periodic report on trends on Internet traffic and security attack insights
  • Experience with modern cloud-based technologies used to deliver rapidly-changing products at scale.
  • Conduct penetration testing to identify security gaps and potential exploits across applications and services.
  • Develop, maintain, and enhance security dashboards to monitor and analyze attack trends, bot activity, and fraud detection metrics.
  • Leverage strong coding skills to build and automate security tools, improve system engineering workflows, and develop new security rules and heuristics.


Examples of desirable skills, knowledge and experience

  • A degree in computer science, IT, systems engineering, or related qualification.
  • 4 years of work experience with incident detection, incident response, forensics, reverse engineering, security research or similar.
  • Ability to work under pressure in a fast-paced environment.
  • Strong attention to detail with an analytical mind and outstanding problem-solving skills. Excellent organizational skills.
  • Great awareness of cybersecurity trends and hacking techniques.
  • Demonstrated results in identifying, tracking and resolving issues to resolution in the areas of cybersecurity.
  • Strong written and verbal communication skills.
  • Experience in OWASP, security standards and best practice
  • Strong SQL experience.
  • Proficiency in penetration testing methodologies, tools, and vulnerability assessment techniques.
  • Experience in building security dashboards using tools like Grafana or similar visualization platforms.
  • Strong programming experience with expertise in Python, Go, Rust, or JavaScript to develop security tools and automation.
  • Prior experience or interest in Web Security, HTTP protocols, Python, Jupyter Notebook, and JavaScript is a huge plus!
  • Knowledge and experience with machine learning, statistical inference, and AI in general is a huge plus


Bonus Points

  • Knowledge and experience with columnar database like Clickhouse
  • Familiarity writing and optimizing advanced SQL queries
  • Good Linux/UNIX systems knowledge
  • Presented in security conferences such as Blackhat, Defcon, Bsides etc.

Top Skills

Go
JavaScript
Python
Rust
The Company
HQ: San Francisco, CA
3,900 Employees
Hybrid Workplace
Year Founded: 2010

What We Do

Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company on a mission to help build a better Internet. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.

Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.

Why Work With Us

Cloudflare employees come from all walks of life. We are mission-driven, and our team is energized by a collaborative, creative environment that celebrates our differences and fosters new ways to grow together.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Cloudflare Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We are committed to developing a global team that is distributed with a flexible working approach. Doing this equitably and inclusively is essential to our success. Visit our careers site for more on 'How & Where We Work.'

Typical time on-site: Flexible
HQSan Francisco, CA
Singapore
Austin, TX
Champaign, IL
Lisbon, PT
London, GB
New York, NY
Seattle, WA
Washington, DC
Learn more

Similar Jobs

Cloudflare Logo Cloudflare

Network Security Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Remote
Hybrid
2 Locations
3900 Employees

Cloudflare Logo Cloudflare

Senior Solutions Engineer, Hong Kong

Cloud • Information Technology • Security • Software • Cybersecurity
Remote
Hybrid
Singapore, SGP
3900 Employees

Cloudflare Logo Cloudflare

Senior Solutions Engineer, Taiwan

Cloud • Information Technology • Security • Software • Cybersecurity
Remote
Hybrid
Singapore, SGP
3900 Employees

Cloudflare Logo Cloudflare

Territory Account Executive, Indonesia

Cloud • Information Technology • Security • Software • Cybersecurity
Remote
Hybrid
Singapore, SGP
3900 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account