Senior Security Researcher & Analyst - WAF Application Security Experts in London
Senior Security Researcher & Analyst - WAF Application Security Experts

Senior Security Researcher & Analyst - WAF Application Security Experts in London

London Full-Time No home office possible
C

Senior Security Researcher & Analyst – WAF Application Security Experts

Join to apply for the Senior Security Researcher & Analyst – WAF Application Security Experts role at Cloudflare

About The Department

Cloudflare’s Application Security organization builds and operates the systems that detect, classify, and mitigate malicious or abusive HTTP traffic across one of the largest networks on the Internet. Our products – including the Web Application Firewall (WAF), Bot Management, and Fraud Detection – protect millions of Internet properties from attacks and abuse in real time. We combine large‑scale data analytics, cutting‑edge AI and ML models, and expert threat research to continuously evolve Cloudflare’s detection and protection capabilities.

What You’ll Do

  • Analyze web exploits and vulnerability patterns (RCE, SQLi, XSS, SSRF, deserialization, etc.) and build corresponding WAF mitigations.
  • Collaborate with product engineering and data teams to tune detection efficacy – reducing false positives/negatives across large‑scale, high‑volume traffic.
  • Develop, test, and deploy WAF managed rules and exploit signatures based on public CVEs, threat intelligence, and internal telemetry.
  • Perform targeted penetration testing and red‑team style assessments to uncover gaps in Cloudflare’s WAF coverage and propose mitigations.
  • Leverage strong coding skills to automate rule validation, testing pipelines, and data analysis workflows.
  • Conduct research on attacker behaviors, evolving exploit chains, and web attack automation trends.
  • Produce internal and external research reports summarizing Internet‑wide attack trends and WAF efficacy insights.
  • Collaborate closely with Bot Management, Fraud, and ML teams to design cross‑signal detection frameworks that unify WAF and behavioral defenses.
  • Communicate complex technical findings clearly to both engineering and non‑technical audiences.

What You Bring

  • Bachelor’s or Master’s degree in Computer Science, Information Security, or equivalent practical experience.
  • 2+ years of experience in Web Application Security, WAF rule development, incident detection, or threat research.
  • Deep understanding of web protocols (HTTP/HTTPS), common web vulnerabilities, and exploitation techniques (OWASP Top 10).
  • Proven experience writing and optimizing WAF rules or custom detection logic.
  • Hands‑on experience with vulnerability analysis, exploit reproduction, or reverse engineering.
  • Strong analytical mindset and comfort working with large data sets (SQL, ClickHouse, BigQuery, etc.).
  • Proficiency in at least one programming language such as Python, Go, or Rust for building automation tools or analysis scripts.
  • Familiarity with Grafana or equivalent visualization tools to track rule performance and attack trends.
  • Strong written and verbal communication skills – able to document, present, and collaborate effectively.
  • Experience working in fast‑paced environments with production‑scale systems.

Bonus Points

  • Experience with columnar databases like ClickHouse and advanced SQL query optimization.
  • Familiarity with machine learning for security analytics (feature extraction, anomaly detection, model evaluation).
  • Solid understanding of Linux/UNIX systems, TCP/IP networking, and proxy architectures.
  • Prior publications or conference presentations (e.g., Black Hat, DEF CON, BSides).
  • Contributions to open‑source WAF projects or web security tools.
  • Knowledge of WAF and bypassing WAF products with novel techniques.
  • Experience on bug bounty/CTF is plus.

Equal Employment Opportunity

Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person\’s, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e‑mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations.

#J-18808-Ljbffr

C

Contact Detail:

CloudFlare Recruiting Team

Senior Security Researcher & Analyst - WAF Application Security Experts in London
CloudFlare
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

C
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>