Available locations: Lisbon, Portugal About the department
The Threat Intelligence team is responsible for helping teams build security intelligence into their products and delivering new, innovative products to our customers. The team fuses threat intelligence from a swath of external sources with intelligence mined from Cloudflare's world class data to provide threat intelligence used across a number of Cloudflare products. The team's core disciplines are data engineering, data science, devops, and security. We use data science and machine learning to process large volumes of data and build intelligence into Cloudflare's products.
Intel team consumes approximately 35 different threat data feeds, runs 5 different machine learning models, and has data integrated into six different products in the Cloudflare portfolio.
What you'll do
Initially this is a very tactical role, focused on supporting Intel Team's day-to-day operations.
Key Responsibilities include;
- Review domain miscategorizations
- Maintain Application classifications
- Review email miscategorizations
- Submit IOCs to data pipeline based on external reports
- Define automations and software requirements for support tooling
- Define processes and procedures to create 24x7 coverage of miscategorizations
- Continually evaluate the quality of threat data feeds, work to maximize value from them, evaluate new potential sources of data
- Research observed IoCs and network behavior patterns and label data
- Work with data scientists to identify security threats and create machine learning models
- Be a team SME and resource for data scientists building security models and application developers building security products
- Become a subject matter expert for internal teams consuming Intel team security and categorization data
- Become the owner for Intel Team's strategy for false positive controls
- Learn and understand current processes
- Identify gaps and risk areas
- Work the data scientists to test remediation strategies
- Work the engineering teams to implement remediation strategies
- Define and implement metrics for product efficacy
- Research and plan potential software, data science or machine learning projects to improve false positive and false negative rates
- Continually monitor data quality and bring data quality issues and proposed solutions to team leadership
- Identify topical areas in cybersecurity where Cloudflare's unique network can be leveraged to improve user security
- Write blog posts and communicate both internally and externally about Intel Team's work
- Execute daily operational tasks and define automations to streamline operational tasks
- Work with team to define technical requirements for security products
- Research threats, exploits, and TTPs being defended against in products and work with engineers to create products that defend against them
Required Skills & Abilities
- Scripting in Python and Node/Javascript
- Able to use git to create, edit, and review pull requests
- Basic front-end or full-stack development skills preferred but not required
- Knowledge of and passion for cybersecurity
- Knowledge of cyber security industry terms and concepts
- e.g. MITRE ATT&CK Framework, Lockheed Killchain
- Ability to learn about security threats and map them to the MITRE ATT&CK framework and Lockheed Killchain
- Strong knowledge of networking and "how the Internet works"
- DNS, HTTP, TCP/IP, TLS, public key encryption
- Ability to reliably execute several hours a day of operational support tasks
- Ability to communicate to stakeholders and management when priorities change
Top Skills
Cloudflare Seattle, Washington, USA Office
Seattle, WA, United States
Similar Jobs at Cloudflare
What you need to know about the Seattle Tech Scene
Key Facts About Seattle Tech
- Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Amazon, Microsoft, Meta, Google
- Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Madrona, Fuse, Tola, Maveron
- Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute