Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Incident Response Analyst - REACT

Cloudflare
CompanyCloudflare
CategorySecurity
LocationHybrid
RemoteHybrid
EmploymentNot stated
LevelMid
SalaryNot stated by the employer
Posted16 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.  At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in. Available Locations: Lisbon, Portugal  About the Role Cloudflare is a system spanning the globe, on a mission to make the Internet safer and more powerful every day. To help fulfill this mission, we are seeking an incident response Analyst / Consultant to join our Cloudforce One REACT organization. In this role, you will respond to active customer attacks across two primary tracks: 1) L7 mitigations — bot abuse, web scraping, credential stuffing, and WAF/API abuse. 2) L3/L4 mitigations — volumetric and protocol DDoS attacks. You will execute hands-on edge mitigations, verify effectiveness with measurable KPIs, and communicate clearly with customers under pressure. This position requires an innovative, self-starting, detail-oriented problem solver with a passion for scoping, deploying, and validating mitigations in real time. You will engage with customers at all levels — including Executive, VP, Director, and engineering, serving an integral role alongside forensic analysts, threat researchers, detection engineers, and malware analysts. What You’ll Do 1. Active Edge Mitigation    • Deploy and tune custom WAF rules (block, challenge, JS challenge, managed challenge) to stop abusive L7 traffic.    • Implement bot mitigations using request/behavior signals and, where applicable, fingerprinting signals; apply rate limiting and challenge policies.    • Execute L3/L4 DDoS mitigations (e.g., attack mode tuning, shunning, flow-based controls) to protect customer availability before traffic reaches the origin.    • Scope every mitigation tightly by path, endpoint, tenant, or audience to minimize collateral impact. 2. Customer Containment & Threat Isolation    • Identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration when needed.    • Track unauthorized lateral movement, correlate threat actor activity, and execute containment that preserves evidence while neutralizing the adversary.    • Adapt mitigations as attacker tactics change without over-scoping or breaking legitimate traffic. 3. Verification, KPIs & Rollback    • Define “mitigated” using success criteria: service health recovery, reduced abusive match rate, and acceptable collateral limits.    • Verify effectiveness after each m
HOUSE AD982,094 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →