Skip to main content
Back to jobs

Response Engineer - PhishGuard

External
Cloudflare logoCloudflare · Unknown
Full-timeOn-site1d ago
Application SecurityCloudflareHelmMachine Learning
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the World's Most Innovative Companies by Fast Company. At Cloudflare, we're not looking for people who wait for a polished roadmap; we're looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you're the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you'll fit right in. Response Engineer - PhishGuard Location: Bengaluru About the Department Cloudforce One is Cloudflare's threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cyber criminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world's largest global networks can provide. The team analyzes these unique data points at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers. About INTERDICT I.N.T.E.R.D.I.C.T. (Identify, Neutralize, Triage, Engage, Respond, Disrupt, Integrate, Contain, Threat Hunting) is Cloudforce One's unified operational security organization responsible for identifying, analyzing, and responding to threats targeting Cloudflare and its customers. INTERDICT encompasses three main sub-functions: PhishGuard: Managed email threat detection and response service Cloudflare Managed Defense (CMD): Network and application security monitoring for 'Under Attack' mitigation support. Detection Engineering: ML model development and detection optimization Together, INTERDICT provides comprehensive 24×7×365 protection across email, application, and network threat surfaces. Role Summary As a Response Engineer for PhishGuard, you will serve as the essential human intelligence layer responsible for identifying, tracking, and defeating sophisticated email-borne cyber threats like Business Email Compromise (BEC) and vendor fraud. You will operate within the INTERDICT organization, collaborating closely with internal teams like Detection Engineering, PREDICT (Threat Intelligence), and SIRT to hunt down adversaries and refine global security models. Our ideal candidate possesses deep forensic thoroughness, exceptional nuance detection, and a growth-minded curiosity to protect global organizations using one of the world's largest networks.

Responsibilities

  • Conduct continuous, real-time monitoring of email threat queues to review and analyze sophisticated attacks flagged by Cloudflare Email Security automated systems.
  • Investigate customer-reported submissions, execute proactive threat hunts targeting emerging patterns, and perform manual retraction or quarantine of verified malicious emails.
  • Provide critical feedback to Detection Engineering to update machine learning models and contribute novel campaign data to global intelligence repositories.
  • Identify nuanced threat patterns by correlating technical telemetry with behavioral indicators, generating detailed threat dossiers for impending organizational risks.
  • Deliver direct crisis intervention and proactive phone notifications to customers regarding high-dollar BEC threats and active insider risks.
  • Lead technical onboarding sessions for new customers, configuring internal system instances with bespoke detection rules, thresholds, and custom allow/block lists.
  • Guide customers through their multi-year DMARC implementation journey toward strict "Reject" policy enforcement by conducting SPF and DKIM alignmen

Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at Cloudflare? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect