×
Register Here to Apply for Jobs or Post Jobs. X

Security Researcher & Analyst - WAF Application Security Experts

Job in Central London, Greater London, England, UK
Listing for: CloudFlare
Full Time position
Listed on 2025-11-10
Job specializations:
  • IT/Tech
    Cybersecurity, Data Security, Network Security
Salary/Wage Range or Industry Benchmark: 60000 - 80000 GBP Yearly GBP 60000.00 80000.00 YEAR
Job Description & How to Apply Below

Security Researcher & Analyst - WAF Application Security Experts

In-Office

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code.

Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time e join us!

About the Department

Cloudflare’s Application Security organization builds and operates the systems that detect, classify, and mitigate malicious or abusive HTTP traffic across one of the largest networks on the Internet. Our products — including the Web Application Firewall (WAF), Bot Management, and Fraud Detection — protect millions of Internet properties from attacks and abuse in real time.

We combine large-scale data analytics, cutting-edge AI and ML models, and expert threat research to continuously evolve Cloudflare’s detection and protection capabilities. The team brings together security researchers, analysts, and engineers who collaborate to identify new attack vectors, create innovative mitigations, and deliver protection at Internet scale.

What You’ll Do

As a WAF Application Security Expert, you’ll focus on researching, designing, and improving detection logic and rules that protect customer applications from the latest web threats.

  • Analyze web exploits and vulnerability patterns (RCE, SQLi, XSS, SSRF, deserialization, etc.) and build corresponding WAF mitigations.
  • Collaborate with product engineering and data teams to tune detection efficacy — reducing false positives/negatives across large‑scale, high‑volume traffic.
  • Develop, test, and deploy WAF managed rules and exploit signatures based on public CVEs, threat intelligence, and internal telemetry.
  • Perform targeted penetration testing and red‑team style assessments to uncover gaps in Cloudflare’s WAF coverage and propose mitigations.
  • Leverage strong coding skills to automate rule validation, testing pipelines, and data analysis workflows.
  • Conduct research on attacker behaviors, evolving exploit chains, and web attack automation trends.
  • Produce internal and external research reports summarizing Internet‑wide attack trends and WAF efficacy insights.
  • Collaborate closely with Bot Management, Fraud, and ML teams to design cross‑signal detection frameworks that unify WAF and behavioral defenses.
  • Communicate complex technical findings clearly to both engineering and non‑technical audiences.
What You Bring
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or equivalent practical experience.
  • 2+ years of experience in Web Application Security, WAF rule development, incident detection, or threat research.
  • Deep understanding of web protocols (HTTP/HTTPS), common web vulnerabilities, and exploitation techniques (OWASP Top 10).
  • Proven experience writing and optimizing WAF rules or custom detection logic.
  • Hands‑on experience with vulnerability analysis, exploit reproduction, or reverse engineering.
  • Strong analytical mindset and comfort working with large data sets (SQL, Click House, Big Query, etc.).
  • Proficiency in at least one programming language such as Python, Go, or Rust for building automation tools or analysis scripts.
  • Familiarity with Grafana or equivalent…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary