Cloudflare13 days ago
AI Security Research & Red Team Engineer
RUB 13,833–17,333per month · before tax
MARKET
30,208 ₽median for this role
AI Researcher · 30 jobs with disclosed pay
5,600half of the offers: 16,410–78,975131,300
Below market · above 17% of offers
Hybrid
Responsibilities
- 01AI Security and Vulnerability Research: Stay current with emerging threats and perform deep-dive research to identify AI-specific vulnerabilities and risks in addition to general vulnerabilities across Cloudflare’s products and services
- 02Agentic testing and adoption: As a core function, identifying AI-related attack surfaces through rigorous testing of agentic implementations and LLM usage which will help define requirements and implementation guidance while proactively
- 03Adversary Simulation: Execution of full-chain red team operations targeting Cloudflare’s global infrastructure, corporate networks, and product ecosystems
- 04Efficacy Testing: Establish a rigorous framework for testing "Security Efficacy"—measuring exactly how well our WAF, EDR, and SIEM detections perform against known TTPs (Tactics, Techniques, and Procedures)
- 05Purple Teaming: Foster a highly collaborative relationship with the Blue Team (Detection & Response) to ensure findings are translated into immediate defensive improvements
- 06Mentorship & Growth: Be a technical leader, providing technical expertise while fostering a culture of curiosity, ethical hacking and partnering to improve Cloudflare’s security posture
- 07Executive Reporting: Translate complex technical exploits into risk-based narratives for leadership, helping prioritize engineering resources where they matter most
- 08Act as the "sparring partner" for SIRT by conducting unannounced exercises to help them refine their playbooks, test their on-call rotations, and ensure their forensic tooling is effective under pressure
- 09Partner with Threat Detection & Threat Engineering to bridge the gap between adversary simulation and defensive coverage, proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks
- 10Operate as "Customer Zero" of our own products, driving resilience in processes and implementations through red teaming findings
- 11Bridge the gap between "paper security" and "technical reality" for GRC by providing empirical evidence of control effectiveness
Requirements
- 014+ years in offensive security, application security or other relevant field
- 02Deep knowledge: AI, Coding agents, LLMs, prompt engineering, AI-related attack vectors (e.g., prompt injection, jailbreaking), and Agentic concepts all for use in the red team but also testing Cloudflare uses
- 03Technical Roots: A strong background in manual penetration testing, exploit development, or cloud security (AWS/GCP/Bare Metal)
- 04Operational Mindset: Experience using the MITRE ATT&CK framework to map coverage and identify "blind spots" in defensive telemetry
- 05Communication Skills: The ability to explain a complex "0-day" exploit to a non-technical stakeholder while maintaining the respect of a deep-dive engineering team
- 06Tooling Familiarity: Knowledge of automated breach and attack simulation (BAS) tools, as well as custom-built frameworks for payload delivery and C2 infrastructure
What we offer
- 01Compensation may be adjusted depending on work location
- 02For New York based hires: Estimated annual salary of $166,000 - $208,000
- 03This role is eligible to participate in Cloudflare’s equity plan