Incident Response Engineer - CMDC
Cloudflare · Bengaluru · 5+ yrs experience · Posted 2026-07-18
Tech stack: C, GraphQL, Linux, Python
Apply on the company site · Get a referral for this role
Cloudflare salary & ratings · Cloudflare interview process · More live openings
About the role
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Responsibilities:
- Response Engineer within the Cloudflare Managed Defense Center (CMDC) provides front-line technical monitoring and threat mitigation for Cloudflare’s premium enterprise customers.
- In this role, you will proactively monitor internal alerting systems to identify, analyze, and mitigate real-time security events across OSI Layers 3, 4, and 7.
- Working alongside senior engineers and operational teams, you will execute established runbooks to protect complex customer infrastructure from sophisticated DDoS and application-layer attacks.
- We are looking for a collaborative, analytical professional who remains calm under pressure and is eager to develop their security expertise within a fast-paced environment.
- Monitor and investigate proactive security alerts via internal telemetry systems to rapidly identify ongoing infrastructure and application-layer attacks.
- Apply appropriate mitigation steps and filter malicious traffic using Cloudflare’s core security tools, including Magic Transit, Web Application Firewall (WAF), and Rate Limiting.
- Review incoming alerts to determine urgency, scope, and validity, while accurately maintaining incident tracking tickets for necessary escalations.
- Communicate technical updates clearly and professionally with enterprise customers via chat, email, and phone during active security incidents.
- Adhere to strict customer SLAs for alert response times, event analysis, and ongoing operational communications.
- Maintain and update customer-specific runbooks, threshold rules, and escalation matrices to ensure seamless incident execution.
- Collaborate with internal Engineering and Product teams to provide feedback on tools and suggest improvements for alert rules.
Qualifications:
- (Must-Have Skills)
- A minimum of 2–5 years of relevant hands-on experience in a Security Operations Center (SOC), technical support engineering, or network operations environment.
- Strong foundational understanding of networking principles and internet protocols, including TCP/IP, UDP, ICMP, DNS, and BGP.
Qualifications
- (Must-Have Skills)
- A minimum of 2–5 years of relevant hands-on experience in a Security Operations Center (SOC), technical support engineering, or network operations environment.
- Strong foundational understanding of networking principles and internet protocols, including TCP/IP, UDP, ICMP, DNS, and BGP.
Responsibilities
- Response Engineer within the Cloudflare Managed Defense Center (CMDC) provides front-line technical monitoring and threat mitigation for Cloudflare’s premium enterprise customers.
- In this role, you will proactively monitor internal alerting systems to identify
- analyze, and mitigate real-time security events across OSI Layers 3, 4, and Working alongside senior engineers and operational teams, you will execute established runbooks to protect complex customer infrastructure from sophisticated DDoS and application-layer attacks.
- We are looking for a collaborative, analytical professional who remains calm under pressure and is eager to develop their security expertise within a fast-paced environment.
- Monitor and investigate proactive security alerts via internal telemetry systems to rapidly identify ongoing infrastructure and application-layer attacks.
- Apply appropriate mitigation steps and filter malicious traffic using Cloudflare’s core security tools, including Magic Transit, Web Application Firewall (WAF), and Rate Limiting.
- Review incoming alerts to determine urgency, scope, and validity, while accurately maintaining incident tracking tickets for necessary escalations.
- Communicate technical updates clearly and professionally with enterprise customers via chat, email, and phone during active security incidents.
- Adhere to strict customer SLAs for alert response times, event analysis, and ongoing operational communications.
- Maintain and update customer-specific runbooks, threshold rules, and escalation matrices to ensure seamless incident execution.
- Collaborate with internal Engineering and Product teams to provide feedback on tools and suggest improvements for alert rules.