跳到主要内容
OOfficialJobs
菜单
官方来源官方来源职位

AI安全研究与红队工程师

机器翻译
查看雇主原标题AI Security Research & Red Team Engineer

Cloudflare · Hybrid · $166k – $208k

职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。

为什么值得关注?

发现指数 75/100,仅依据与该职位一起存储的证据计算。

75/100 发现指数
  • 新的雇主官方职位
  • 已披露薪资
  • 远程职位
  • 稀有职位匹配

分数构成

  • 时效性 (随职位发布时间变化)+18
  • 雇主官方来源+15
  • 已披露薪资+15
  • 远程职位+8
  • 稀有职位+11
  • 公司来源健康度+8

该职位未包含:提及签证担保、提及搬迁、未出现在监控的职位板上。

这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。

职位描述

机器翻译

关于我们

在 Cloudflare,我们的使命是帮助构建更好的互联网。如今,公司运营着全球最大的网络之一,为从个人博主到中小企业再到《财富》500 强企业的客户提供支持,驱动着数百万个网站和其他互联网资产。Cloudflare 无需添加硬件、安装软件或更改一行代码,即可保护和加速任何在线互联网应用。由 Cloudflare 驱动的互联网资产,其网络流量都会通过其智能全球网络进行路由,而该网络会随着每一次请求变得更加智能。因此,它们的性能显著提升,垃圾邮件和其他攻击也减少了。Cloudflare 曾入选《Entrepreneur》杂志的顶级公司文化榜单,并被《Fast Company》评为全球最具创新力公司之一。

在 Cloudflare,我们寻找的不是等待一份完美路线图的人;我们寻找的是那些看到互联网裂缝、而其他人都只是学会与之共处的建设者。我们看重那些有直觉发现“被正常化”的问题,并具备 AI 原生好奇心、能够使用最新工具创造解决方案的候选人。我们的文化建立在迭代之上,利用 AI 在今天更快交付,以便明天做得更好,同时确保每一项改进,无论多么微小,都会在团队中共享,让每个人都得到提升。如果你是那种重视好奇心而非官僚作风,并且认为 AI 是解决棘手问题、推动互联网继续前进的伙伴的人,你会非常适合这里。

职位:

我们正在寻找一位高技能 AI 安全研究与红队工程师,加入我们安全威胁检测、响应与模拟组织内的红队。这是一个关键角色,将站在保护我们公司和客户免受恶意威胁的最前沿。你将负责推动安全研究、演练和活动,模拟现实世界的攻击者和攻击,以推动 Cloudflare 安全态势的改进,重点关注 AI、Agents、harnesses 和 LLM。

主要职责:

• AI 安全与漏洞研究:紧跟新兴威胁,并进行深入研究,以识别 AI 特有的漏洞和风险,以及 Cloudflare 产品和服务中的一般漏洞。

• Agentic 测试与采用:作为核心职能,通过对 agentic 实现和 LLM 使用进行严格测试来识别与 AI 相关的攻击面,这将有助于主动定义需求和实施指南。

• 对手模拟:执行针对 Cloudflare 全球基础设施、企业网络和产品生态系统的全链路红队行动。

• 有效性测试:建立严格的“安全有效性”测试框架——精确衡量我们的 WAF、EDR 和 SIEM 检测针对已知 TTP(战术、技术和程序)的表现如何。

• 紫队协作:与蓝队(检测与响应)建立高度协作的关系,确保发现的问题转化为即时的防御改进。

• 指导与成长:成为技术领导者,提供技术专长,同时培养好奇心、道德黑客文化,并合作改进 Cloudflare 的安全态势。

• 高管汇报:将复杂的技术漏洞利用转化为基于风险的高管叙事,帮助确定工程资源应优先投入的最重要领域。

合作伙伴关系

• 安全事件响应团队(SIRT):你将作为 SIRT 的“陪练伙伴”。通过开展

岗位职责

我们正在寻找一位高技能 AI 安全研究与红队工程师,加入我们安全威胁检测、响应与模拟组织内的红队。这是一个关键角色,将站在保护我们公司和客户免受恶意威胁的最前沿。你将负责推动安全研究、演练和活动,模拟现实世界的攻击者和攻击,以推动 Cloudflare 安全态势的改进,重点关注 AI、Agents、harnesses 和 LLM。

• AI 安全与漏洞研究:紧跟新兴威胁,并进行深入研究,以识别 AI 特有的漏洞和风险,以及 Cloudflare 产品和服务中的一般漏洞。

• Agentic 测试与采用:作为核心职能,通过对 agentic 实现和 LLM 使用进行严格测试来识别与 AI 相关的攻击面,这将有助于主动定义需求和实施指南。

• 对手模拟:执行针对 Cloudflare 全球基础设施、企业网络和产品生态系统的全链路红队行动。

• 有效性测试:建立严格的“安全有效性”测试框架——精确衡量我们的 WAF、EDR 和 SIEM 检测针对已知 TTP(战术、技术和程序)的表现如何。

• 紫队协作:与蓝队(检测与响应)建立高度协作的关系,确保发现的问题转化为即时的防御改进。

• 指导与成长:成为技术领导者,提供技术专长,同时培养好奇心、道德黑客文化,并合作改进 Cloudflare 的安全态势。

• 高管汇报:将复杂的技术漏洞利用转化为基于风险的高管叙事,帮助确定工程资源应优先投入的最重要领域。

合作伙伴关系

• 安全事件响应团队(SIRT):你将作为 SIRT 的“陪练伙伴”。通过开展未事先通知的演练,你帮助他们完善 playbook、测试他们的 on-call 轮值,并确保他们的取证工具在压力下有效。

• 威胁检测与威胁工程:你将与这些团队紧密合作,弥合对手模拟与防御覆盖之间的差距。你将主动识别检测缺口,主导新检测逻辑的开发,并建立严格的验证框架,以针对新兴 TTP 测试和调优检测。

• 产品工程/SRE:我们作为自己产品的“Customer Zero”运作,你的红队发现将推动流程和实现的韧性,最终使 Cloudflare 及其客户更加安全。

• 治理、风险与合规(GRC):你将弥合“纸面安全”与“技术现实”之间的差距。通过提供控制有效性的实证证据,你帮助 GRC 从人工审计转向持续、自动化的合规验证。

必备资格:

任职要求

• 深厚知识:AI、编码 agents、LLM、提示工程、AI 相关攻击向量(例如提示注入、越狱)以及 Agentic 概念,既用于红队,也用于测试 Cloudflare 的使用。

• 技术根基:在手动渗透测试、漏洞利用开发或云安全(AWS/GCP/裸金属)方面有深厚背景。

• 运营思维:具有使用 MITRE ATT&CK 框架来映射覆盖范围并识别防御遥测中“盲点”的经验。

• 沟通能力:能够向非技术利益相关者解释复杂的“0-day”漏洞利用,同时保持深入工程团队的尊重。

• 工具熟悉度:了解自动化入侵与攻击模拟(BAS)工具,以及用于 payload 投递和 C2 基础设施的自定义框架。

福利待遇

薪酬可能会根据工作地点进行调整。

• 对于纽约的录用者:预计年薪为 $166,000 - $208,000。

股权

该职位有资格参与 Cloudflare 的股权计划。 Cloudflare 有何特别之处?

我们不仅仅是一家雄心勃勃的大型科技公司。我们是一家雄心勃勃、规模庞大且拥有灵魂的科技公司。我们帮助构建更好互联网的使命,其根本在于保护自由开放的互联网。

Project Galileo:自 2014 年以来,我们已为 111 个国家的 2,400 多个新闻和公民社会组织提供了强大的工具,使他们能够抵御原本会审查其工作的攻击,这些技术已被 Cloudflare 的企业客户使用——而且是免费的。

Athenian Project:2017 年,我们创建了 Athenian Project,以确保州和地方政府免费获得最高级别的保护和可靠性,使其选民能够获取选举信息和选民登记。自该项目以来,我们已为 33 个州的 425 多个地方政府选举网站提供服务。

1.1.1.1:我们发布了 1.1.1.1,通过构建更快、更安全且以隐私为中心的公共 DNS 解析器,帮助修复互联网的基础。这可供所有人公开使用——这是 Cloudflare 发布的首个面向消费者的服务。事情是这样的——我们永远不会存储客户端 IP 地址。我们将继续遵守我们的隐私承诺,并确保不会将任何用户数据出售给广告商或用于定向消费者。

听起来像是你想参与的事情?我们很乐意听到你的消息!

请注意,进入面试流程录用阶段的申请人可能会被要求参加 Cloudflare 办公室或 Cloudflare Hub 之一的现场面试。有关此事的更多细节将在面试流程的该阶段提供。

该职位可能需要访问受美国出口管制法律(包括美国出口管理条例)保护的信息。请注意,任何录用通知都可能以你获得接收受这些美国出口法律管制的软件或技术的授权为前提,且无需申请出口许可证担保。

Cloudflare 自豪地成为平等机会雇主。我们致力于为所有人提供平等就业机会,并高度重视多样性和包容性。所有合格申请人都会获得就业考虑,不因其或任何其他人被感知或实际的种族、肤色、宗教、性别、性别认同、性别表达、性取向、国籍、血统、公民身份、年龄、身体或精神残疾、医疗状况、家庭照护状况或任何其他受法律保护的基础而受到歧视。我们是 AA/Veterans/Disabled 雇主。

Cloudflare 为符合条件的残障人士提供合理便利。如果你在申请工作时需要合理便利,请告诉我们。合理便利的例子包括但不限于:更改申请流程、以替代格式提供文件、使用手语翻译或使用专业设备。如果你在申请工作时需要合理便利,请通过电子邮件 hr@cloudflare.com 联系我们,或通过邮寄地址 101 Townsend St. San Francisco, CA 94107 联系我们。

以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。

查看雇主原文

职位描述

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

The Role:

We are seeking a highly skilled AI Security Research & Red team engineer to join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvements in Cloudflare’s security posture focusing on AI, Agents, harnesses and LLM’s.

Key Responsibilities:

• AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflare’s products and services.

• Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively.

• Adversary Simulation: Execution of full-chain red team operations targeting Cloudflare’s global infrastructure, corporate networks, and product ecosystems.

• Efficacy Testing: Establish a rigorous framework for testing "Security Efficacy"—measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures).

• Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements.

• Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflare’s security posture.

• Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most.

Partnerships

• Security Incident Response Team (SIRT): You will act as the "sparring partner" for SIRT. By conducting

岗位职责

We are seeking a highly skilled AI Security Research & Red team engineer to join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvements in Cloudflare’s security posture focusing on AI, Agents, harnesses and LLM’s.

• AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflare’s products and services.

• Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively.

• Adversary Simulation: Execution of full-chain red team operations targeting Cloudflare’s global infrastructure, corporate networks, and product ecosystems.

• Efficacy Testing: Establish a rigorous framework for testing "Security Efficacy"—measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures).

• Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements.

• Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflare’s security posture.

• Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most.

Partnerships

• Security Incident Response Team (SIRT): You will act as the "sparring partner" for SIRT. By conducting unannounced exercises, you help them refine their playbooks, test their on-call rotations, and ensure their forensic tooling is effective under pressure.

• Threat Detection & Threat Engineering: You will partner closely with these teams to bridge the gap between adversary simulation and defensive coverage. You will proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks to test and tune detections against emerging TTPs.

• Product Engineering/SRE: We operate as "Customer Zero" of our own products, your red teaming findings will drive resilience in processes and implementations, ultimately making Cloudflare and its customers more secure.

• Governance, Risk, and Compliance (GRC): You will bridge the gap between "paper security" and "technical reality." By providing empirical evidence of control effectiveness, you help GRC move away from manual audits and toward continuous, automated compliance validation.

Required Qualifications:

任职要求

• Deep knowledge: AI, Coding agents, LLMs, prompt engineering, AI-related attack vectors (e.g., prompt injection, jailbreaking), and Agentic concepts all for use in the red team but also testing Cloudflare uses.

• Technical Roots: A strong background in manual penetration testing, exploit development, or cloud security (AWS/GCP/Bare Metal).

• Operational Mindset: Experience using the MITRE ATT&CK framework to map coverage and identify "blind spots" in defensive telemetry.

• Communication Skills: The ability to explain a complex "0-day" exploit to a non-technical stakeholder while maintaining the respect of a deep-dive engineering team.

• Tooling Familiarity: Knowledge of automated breach and attack simulation (BAS) tools, as well as custom-built frameworks for payload delivery and C2 infrastructure.

福利待遇

Compensation may be adjusted depending on work location.

• For New York based hires: Estimated annual salary of $166,000 - $208,000.

Equity

This role is eligible to participate in Cloudflare’s equity plan. What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

Athenian Project : In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.

1.1.1.1 : We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Cloudflare 的更多职位

公司主页

Systems Engineer原文

Cloudflare · Engineering

官方来源最新
混合办公混合办公全职未披露薪资
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于8小时前
已核实8小时前
官方来源最新
混合办公混合办公全职未披露薪资
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于8小时前
已核实8小时前

Principal Customer Engineer, Majors原文

Cloudflare · Solution Engineering

官方来源最新
Distributed全职€148k – €204k
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于8小时前
已核实8小时前
官方来源最新
Distributed全职€148k – €204k
英文原文

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet propertie…

官方来源职位
首次发现于8小时前
已核实8小时前