JobBobsReal-time global job discoveryLive

Senior Incident Response Analyst - REACT

Cloudflare · Hybrid · 2026-07-28

executive
Apply on the employer's site

About this role

<div class="content-intro"><div><strong>About Us</strong></div> <div> <p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. </p> <p>At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.</p> </div></div><p><strong>Available Locations: Lisbon, Portugal </strong></p> <h3><strong>About the Role</strong></h3> <p>Cloudflare is a system spanning the globe, on a mission to make the Internet safer and more powerful every day. To help fulfill this mission, we are seeking an incident response Analyst / Consultant to join our Cloudforce One REACT organization.</p> <p>In this role, you will respond to active customer attacks across two primary tracks:<br>1) L7 mitigations — bot abuse, web scraping, credential stuffing, and WAF/API abuse.<br>2) L3/L4 mitigations — volumetric and protocol DDoS attacks.</p> <p>You will execute hands-on edge mitigations, verify effectiveness with measurable KPIs, and communicate clearly with customers under pressure. This position requires an innovative, self-starting, detail-oriented problem solver with a passion for scoping, deploying, and validating mitigations in real time. You will engage with customers at all levels — including Executive, VP, Director, and engineering, serving an integral role alongside forensic analysts, threat researchers, detection engineers, and malware analysts.</p> <p><strong>What You’ll Do</strong></p> <p><br><strong>1. Active Edge Mitigation</strong><br>   • Deploy and tune custom WAF rules (block, challenge, JS challenge, managed challenge) to stop abusive L7 traffic.<br>   • Implement bot mitigations using request/behavior signals and, where applicable, fingerprinting signals; apply rate limiting and challenge policies.<br>   • Execute L3/L4 DDoS mitigations (e.g., attack mode tuning, shunning, flow-based controls) to protect customer availability before traffic reaches the origin.<br>   • Scope every mitigation tightly by path, endpoint, tenant, or audience to minimize collateral impact.</p> <p><strong>2. Customer Containment & Threat Isolation</strong><br>   • Identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration when needed.<br>   • Track unauthorized lateral movement, correlate threat actor activity, and execute containment that preserves evidence while neutralizing the adversary.<br>   • Adapt mitigations as attacker tactics change without over-scoping or breaking legitimate traffic.</p> <p><strong>3. Verification, KPIs & Rollback</strong><br>   • Define “mitigated” using success criteria: service health recovery, reduced abusive match rate, and acceptable collateral limits.<br>   • Verify effectiveness after each mitigation update using time-bucketed telemetry; rollback or re-scope immediately if collateral damage appears.<br>   • Maintain a versioning mindset for mitigations so updates are reversible and auditable.</p> <p><strong>4. IR Lifecycle, Evidence & Reporting</strong><br>   • Support the full incident response lifecycle: investigation, containment, remediation, and recovery.<br>   • Preserve forensic evidence (logs, volatile memory, disk images) according to standards to support legal, regulatory, or insurance requirements.<br>   • Prepare high-fidelity incident reports and customer communications that are clear, accurate, and actionable for both executives and engineers.</p> <p><strong>Minimum Qualifications (Must-Haves)</strong><br>   • 3+ years of hands-on experience in SOC, incident response, or detection engineering.<br>   • Proven experience deploying mitigations that affect live customer traffic — not only monitoring or investigation.<br>   • Hands-on with at least one of the following: WAF rules/actions, DDoS protection controls, bot mitigations, rate limiting/challenge policies.<br>   • Strong…

Skills asked for

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.