C

Senior Software Engineer - Security Platform (Python)

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to…

cloudflare На сервисе с: 09.10.26 10:16

Зарплата не указанаСШАКанадаУдалёнка

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations

  • Atlanta, US
  • Austin, US
  • Denver, US
  • New York, US
  • San Francisco, US
  • Seattle, US
  • Washington DC, US
  • Canada

About the Role

The Security Platform team is an infrastructure/developer tools group tasked with building and operating powerful, resilient, and secure infrastructure and systems that enable other engineering teams to deliver products to our customers efficiently and securely. We are responsible for secrets management, internal certificate authorities/PKI, machine and workload identity, and more. We are not a policy, audit, or compliance team, but rather an infrastructure engineering/software development one.

Responsibilities

You’ll build and operate secure and resilient distributed systems for secrets and key management, running across our network that spans more than 310 cities in over 120 countries. Our focus is strengthening/re-architecting internal PKI and machine/workload identity. You’ll run and support the systems we build, both in an operational sense and by helping other internal developers use them. You will participate in the On Call rotation for emergency incident response. You’ll consult on the design and architecture of new systems and products to ensure they are built securely and use our services correctly.

Required skills

  • Software development and distributed systems design expertise.

  • Linux/UNIX system administration proficiency.

  • Strong security background with a focus on implementation, not policy/compliance.

Bonus/nice-to-have skills

  • Track record of contributing to open source security or distributed systems projects.

  • Cryptography background and ability to work with cryptosystems at the primitives level.

  • Experience with HSMs, TPMs, or other platform TEEs (e.g. AMD SEV, Intel SGX, Apple Secure Enclave).

  • Familiarity with HashiCorp Vault or OpenBao, or similar.

  • Familiarity with Go and/or Python + Salt specifically.

Compensation

Compensation may be adjusted depending on work location.

  • For California based hires: Estimated annual salary of $194,000 - $266,000
  • For Colorado based hires: Estimated annual salary of $168,000 - $231,000
  • For New York based hires: Estimated annual salary of $185,000 - $254,000
  • For Washington based hires: Estimated annual salary of $185,000 - $254,000
  • For Washington DC based hires: Estimated annual salary of $185,000 - $254,000
  • For Canada based hires: Estimated annual salary of $150,000 - $206,000

Applications will be accepted until December 25, 2026.

Equity

This role is eligible to participate in Cloudflare's equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun! The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Похожие вакансии Кибербезопасность

hh.ru
Зарплата не указанаРоссияМоскваОфис

Мы ищем инженера по безопасной разработке. Если Вы умеете выстраивать процессы безопасного кодирования, работать с требованиями по защите приложений и налаживать эффективное взаимодействие между командами разработки и ИБ — присоединяйтесь к нам!

Когда ты с нами:

  • Работаешь в крупной компании, лидере своего сегмента
  • Оформляешься с 1 дня по ТК РФ
  • Получаешь стабильный доход
  • График работы 5/2 с 10:00 до 19:00 (суббота и воскресенье — фиксированные выходные)
  • Экономишь благодаря скидкам и спецпредложениям от компаний‑партнёров
  • Получаешь подписку М. Комбо — пакет привилегий: ежемесячные бонусные рубли, бесплатную доставку, скидки на установку и ремонт, приоритетную поддержку
  • Офис в 3х минутах от D1 Сколково

С нами ты будешь:

  • Анализировать и приоритизировать уязвимости
  • Обеспечивать развитие средств информационной безопасности микросервисной архитектуры, автоматизировать безопасное развертывание сервисов
  • Организовывать внедрение, администрирование и развитие ИБ-ландшафта на всех этапах разработки и эксплуатации
  • Анализировать системы, предлагать улучшения процессов и сервисов безопасности
  • Разрабатывать техническую документацию по ИБ, готовить обучающие материалы для DevOps-инженеров по безопасности
  • Взаимодействовать с Департаментом ИБ, согласовывать компенсирующие меры, участвовать во внутренних аудитах

Для нас ценно:

  • Знание микросервисной архитектуры, технологий контейнеризации и управления ими (Docker, Kubernetes), понимание CI/CD и DevOps
  • Экспертные знания серверных ОС семейства Linux и Windows
  • Понимание риск-ориентированного подхода для выбора защитных мер
  • Глубокое знание OWASP Top 10, CWE Top 25, классификаций уязвимостей
  • Опыт использования платформ класса DefectDojo и аналогичных
  • Понимание работы облачных сервисов для бизнеса, знание сетевых технологий
  • Базовое понимание скриптов программирования (PowerShell, Python и др.)
  • Технический английский (чтение документации)
При отправлении отклика в сопроводительном письме укажите, пожалуйста, уровень дохода, на который вы ориентируетесь. Спасибо!
hh.ru
Зарплата не указанаРоссияМоскваГибрид

Лаборатория Касперского» уже 27 лет защищает мир от киберугроз. Более 400 миллионов пользователей выбирают наши технологии для защиты своих данных, а мы каждый день работаем над их совершенствованием. Все мы — обычные люди, со своими особенностями и увлечениями, но вместе мы 24 часа в сутки спасаем мир. Работа у нас — это возможность стать настоящим героем, оставаясь самим собой.

Сейчас у нас открыта позиция стажера в отдел развития ИБ (Information Security Development). Если вы хотите работать в динамично развивающейся международной компании c Enterprise-инфраструктурой по всему миру и держать ее на пике ИБ-прогресса, то мы ждем вас!

Обязанности:

  • Принимать участие в пилотировании и внедрении новых сервисов ИБ
  • Формировать требования ИБ и разрабатывать процессы контроля их реализации
  • Участвовать в развитии существующих сервисов ИБ
  • Помогать с автоматизацией и выполнением требований ИБ в корпоративных сервисах Компании

Требования:

  • Интерес к области информационной безопасности, и желание в ней разбираться
  • Понимание принципов и концепций информационной безопасности (zero trust, least privilege, need to know, defense in depth)
  • Базовые знания криптографических протоколов и алгоритмов : SSL/TLS, AES, RSA.
  • Знание принципов аутентификации и авторизации, понимание современных протоколов аутентификации (OAuth, Kerberos, NTLM, Raduis, LDAP)
  • Уметь ставить цели и разрабатывать план по их достижению в рамках своей зоны ответственности
  • Способность анализировать угрозы информационной безопасности, выявлять закономерности и аномалии для обнаружения угроз информационной безопасности разрабатывать решения для их предотвращения.
  • Обладать способностью быстро изучать новое и внедрять это в свою работу
  • Коммуникабельность и открытость в общении

Будет плюсом:

  • Владение powershell, bash, на уровне уверенного пользователя. Опыт автоматизации рутинных, административных задач.
  • Опыт редактирования данных в формате JSON и YAML
  • Умение реализовать несложные программы для автоматизации
  • Опыт участия в разработке регламентирующих документов
hh.ru
Зарплата не указанаРоссияМоскваОфис

Мы ищем аналитика по безопасности продуктов. Если Вы умеете выстраивать процессы анализа защищенности продуктов, работать с требованиями по безопасности и налаживать эффективное взаимодействие между командами разработки, продукта и ИБ — присоединяйтесь к нам!

Когда ты с нами:

  • Работаешь в крупной компании, лидере своего сегмента
  • Оформляешься с 1 дня по ТК РФ
  • Получаешь стабильный доход
  • График работы 5/2 с 10:00 до 19:00 (суббота и воскресенье — фиксированные выходные)
  • Экономишь благодаря скидкам и спецпредложениям от компаний‑партнёров
  • Получаешь подписку М. Комбо — пакет привилегий: ежемесячные бонусные рубли, бесплатную доставку, скидки на установку и ремонт, приоритетную поддержку
  • Офис в 3х минутах от D1 Сколково

С нами ты будешь:

  • Анализировать и приоритизировать уязвимости: изучать найденные угрозы в конкретном продукте, определять реальные риски, отсекать ложные срабатывания, ранжировать по критичности и консультировать разработчиков по устранению выявленных недостатков
  • Проводить security code review: вручную и с помощью инструментов проверять наиболее критичный функционал – аутентификацию, авторизацию, работу с персональными данными и т.д
  • Анализировать сторонние библиотеки и компоненты на наличие известных уязвимостей (CVE)
  • Готовить отчёты и аналитические материалы, заводить и сопровождать задачи в Jira

Для нас ценно:

  • Понимание принципов безопасной разработки (Secure SDLC) и CI/CD-процессов
  • Глубокое знание OWASP Top 10, CWE Top 25, классификаций уязвимостей
  • Понимание методологий тестирования безопасности (SAST, DAST, IAST, пентест)
  • Умение читать код на современных языках программирования
  • Опыт работы с инструментами: Burp Suite, OWASP ZAP, Nessus, SonarQube и др.
  • Понимание принципов работы веб-приложений, RESTful API, микросервисных архитектур
При отправлении отклика в сопроводительном письме укажите, пожалуйста, уровень дохода, на который вы ориентируетесь. Спасибо!

HireSeeker собирает вакансии со всех площадок и присылает только релевантные. Бесплатно.