← Back to job listings
GU
Senior Staff Security Engineer (Cloud and Network Security)
Gusto · San Francisco, United States
About The Role
Join Gusto as a Senior Staff Security Engineer, where you'll lead the edge and network security strategy, design and operate the edge security stack, and contribute broadly across the security engineering surface. You'll have the opportunity to make high-impact architectural decisions, develop policy-as-code patterns, and build detections and alerting on edge and network telemetry. This role requires deep expertise in Cloudflare's security stack, strong network architecture skills, and a generalist foundation across cloud security, IAM, container security, and detection engineering.
- Concevoir et exploiter la pile de sécurité de Gusto, y compris le WAF Cloudflare, la protection DDoS, la gestion des bots, WARP, Gateway et Access.
- Posséder le périmètre de sécurité réseau à travers AWS et l'edge, y compris la conception de VPC, le pare-feu réseau, Shield, CloudFront, NACLs et le filtrage de sortie.
- Développer des modèles de politique en tant que code pour les règles WAF, les politiques réseau et la configuration de l'edge, afin que les changements soient expédiés par des demandes de tirage avec révision.
- The ideal candidate brings deep, hands-on Cloudflare expertise and a proven track record of hardening edge and network architectures at scale, including tuning WAF rulesets, defending through live DDoS events, and shipping Zero Trust rollouts engineers actually adopt
- You think in terms of layered defense, measurable risk reduction, and automation over manual toil
- Excellent written and verbal communication; you can take a complex perimeter decision and explain the tradeoffs to a staff engineer, a PM, and a VP without changing the substance
- Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs
- 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale
- Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent
- Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus
- AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output
- Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts
- Solid generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience on edge and network telemetry in a modern SIEM
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring