Senior Staff Security Engineer - Network Security

Gusto Gusto · Fintech · San Francisco, CA · Security

Senior Staff Security Engineer focused on network security and edge defense, leveraging AI-native tools and workflows to enhance security operations and automation.

What you'd actually do

  1. Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
  2. Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
  3. Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
  4. Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
  5. Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.

Skills

Required

  • 10+ years of hands-on security engineering experience
  • significant time owning edge, network, or perimeter security at scale
  • Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access
  • rule tuning
  • incident response
  • Zero Trust rollouts
  • Strong network architecture skills across edge and cloud
  • TLS/mTLS
  • segmentation
  • egress controls
  • DDoS resilience
  • AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs
  • Fluency with policy-as-code
  • Terraform
  • CI/CD-first delivery of security controls
  • Solid generalist foundation across cloud security, IAM, container security, and detection engineering
  • hands-on incident response experience on edge and network telemetry in a modern SIEM
  • AI-native working style with daily use of Claude Code or equivalent agentic tooling
  • track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations
  • Excellent written and verbal communication

Nice to have

  • Crossplane or similar
  • AWS Certified Advanced Networking Specialty
  • AWS Certified Security Specialty
  • Cloudflare Certified Security Associate/Professional
  • CKS, or equivalent

What the JD emphasized

  • Deep, production-grade expertise with Cloudflare's security stack
  • AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output.