Principal Engineer - Cloudforce One

Cloudflare Cloudflare · Enterprise · Austin, TX · Security

Principal Engineer for Cloudflare's threat operations and research team (Cloudforce One). This role involves driving architectural direction, identifying and dismantling technical bottlenecks, designing and building data pipelines, and developing agentic AI workflows to automate analyst tradecraft and accelerate threat hunting. The engineer will work across various Cloudflare products, focusing on detecting, analyzing, and neutralizing cyber threats.

What you'd actually do

  1. Drive architectural direction and technical strategy across Cloudforce One engineering, spanning services that run in Kubernetes, on the edge (Workers, D1), and across Cloudflare's global network.
  2. Identify and dismantle technical bottlenecks, legacy patterns, and architectural debt that slow down threat detection and abuse response — then replace them with systems that are faster, more reliable, and more elegant.
  3. Design and build critical data pipelines and services to collect, enrich, analyze, and expose threat intelligence and abuse signals at massive scale, helping identify Tactics, Techniques, and Procedures (TTPs) and Indicators of Compromise (IOCs).
  4. Serve as a technical force multiplier across multiple concurrent projects — you will context-switch between threat intelligence platforms, abuse detection systems, legal response tooling, and customer-facing security products as priorities demand.
  5. Bring a threat-informed perspective to engineering decisions: understand how adversaries adapt, how detection rules degrade, and how to build systems that stay ahead of evolving attack techniques.

Skills

Required

  • distributed systems architecture
  • threat actor operations
  • Kubernetes
  • edge computing (Workers, D1)
  • data pipelines
  • threat intelligence
  • abuse detection systems
  • security and compliance requirements
  • agentic AI workflows
  • AI-assisted development practices

Nice to have

  • architect
  • threat analyst
  • disruptor

What the JD emphasized

  • build systems but fundamentally rethinks how we detect, analyze, and neutralize threats
  • architectural debt
  • trillions of signals per day
  • think like an attacker and build like an engineer who has been burned by production incidents at 3 AM
  • shipping solutions that others said couldn't be done
  • agentic AI workflows
  • AI-assisted development practices

Other signals

  • AI-native curiosity
  • leveraging AI to ship faster
  • agentic AI workflows
  • AI-assisted development practices