Incident Response Analyst - React
Cloudflare · In-Office
About this role
**Incident Response Analyst - React** **About Cloudflare** Cloudflare helps build a better Internet by protecting and accelerating online applications without adding hardware, installing software, or changing code. Its global network routes web traffic through intelligent systems that improve performance and reduce spam and other attacks. **About the Role** Cloudflare is seeking an **Incident Response Analyst** to join the **Cloudforce One REACT** organization. In this role, you’ll help build a proactive, threat-intelligence-driven approach to protecting Cloudflare and its customers from sophisticated, evolving threats. As a **REACT Consultant**, you will respond to customer security incidents across **on-premises, cloud, and hybrid** environments. You’ll analyze, track, and triage malicious activity, and collaborate with forensic analysts, threat researchers, detection engineers, and malware analysts to **detect, isolate, and mitigate** threats. **Location** - **Bengaluru, India** **Responsibilities** - **Active Edge Mitigation:** Execute immediate defensive actions at the Cloudflare edge to protect customer availability (e.g., deploy custom WAF rules, implement L3/L4 DDoS shunning, perform real-time traffic filtering). - **Support Full IR Lifecycle Management:** Handle end-to-end incident response (investigation, containment, remediation, recovery), review technical deliverables, and coordinate with customer stakeholders. - **Incident Remediation:** Develop understanding of targeted attacks and create/execute tactical and strategic remediation plans for compromised organizations. **Desirable Skills, Knowledge, and Experience** - **Education:** Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent training/practical experience. - **Experience:** 5+ years in cybersecurity, including 2+ years in dedicated incident response. - **OS & Cloud Environments:** Strong Windows knowledge; general knowledge of Unix/Linux/Mac. Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies. - **Network & Web Attack Knowledge:** Understanding of L3/L4/L7 attack patterns (e.g., SYN/UDP floods, DNS amplification, HTTP floods, credential stuffing, scraping, API abuse, account enumeration, checkout abuse). - **Threat/Traffic Analysis:** Experience with JA3/JA4 fingerprinting, bot detection, behavioral traffic analysis, or API abuse investigations. - **Live Attack Support:** Experience supporting customers during live DDoS, bot, or application-layer attack events. - **Frameworks:** Solid understanding of **MITRE ATT&CK** and **NIST Cyber Security Frameworks**. - **Communications:** English fluency and strong verbal/written communication; ability to explain complex technical findings to executive and technical clients. **Bonus Points** - Networking/routing/BGP operations knowledge (BGP, Anycast, DNS, TCP/IP, GRE/IPsec, routing policies, prefix announcements, RPKI/IRR, ASN ownership, traffic engineering). - Proficiency in **Python or Golang** for modular code or scripts. - Proficiency with **YARA** and writing detection rules. - Understanding of source code, hex/binary, regex, data correlation, and analysis (network flow, system logs). - Practical malware analysis experience (static/dynamic/automated), including reversing file formats and analyzing complex samples. - Reverse engineering experience with APT malware (infection vectors, infrastruct
Listing freshness
CronJobs last confirmed this listing 15h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.