10+
ProdSecOps Manager
1/21/2026
As a ProdSecOps Manager, you will lead a team of engineers to manage the lifecycle of vulnerabilities and ensure systematic remediation. You will also oversee the integration of security practices into product development and operational strategies.
Working Hours
40 hours/week
Company Size
1,001-5,000 employees
Language
English
Visa Sponsorship
No
About The Company
Cloudflare, Inc. (NYSE: NET) is the leading connectivity cloud company. It empowers organizations to make their employees, applications and networks faster and more secure everywhere, while reducing complexity and cost. Cloudflare’s connectivity cloud delivers the most full-featured, unified platform of cloud-native products and developer tools, so any organization can gain the control they need to work, develop, and accelerate their business.
Powered by one of the world’s largest and most interconnected networks, Cloudflare blocks billions of threats online for its customers every day. It is trusted by millions of organizations – from the largest brands to entrepreneurs and small businesses to nonprofits, humanitarian groups, and governments across the globe.
About the Role
<div class="content-intro"><div><strong>About Us</strong></div>
<div>
<p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. </p>
<p><span style="font-weight: 400;">We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us! </span></p>
</div></div><p><strong>Location(s) Available:</strong> Bangalore, India<br><br><strong>About the Team</strong></p>
<p>The <strong>Product Security Operations</strong> team is the central nervous system of Cloudflare’s security posture. We manage the end-to-end lifecycle of vulnerabilities across our entire global product suite. This team bridges the gap between external security researchers, automated scanning telemetry, and our core engineering squads. As the Manager of this team, you will lead a high-performing group of engineers to ensure that security findings are not just identified, but systematically eradicated.</p>
<h3><strong>About the Role / What You’ll Do</strong></h3>
<p>As an Engineering Manager, you will transition from individual execution to <strong>Strategic Alignment and People Leadership</strong>. You will be responsible for the "Remediation Engine" of the company, ensuring your team has the resources, clear priorities, and technical guidance to secure Cloudflare’s CI/CD pipeline.</p>
<h4><strong>1. People Leadership & Mentorship</strong></h4>
<ul>
<li><strong>Growth Coaching:</strong> Directly manage and mentor a team of security engineers, focusing on their career progression from manual triage to security automation and architectural thinking.</li>
<li><strong>Technical Stewardship:</strong> Support senior engineers in designing high-level security "Guardrails" and "Secure-by-Default" libraries, ensuring technical visions align with operational workloads.</li>
<li><strong>Performance Management:</strong> Set clear KPIs for the team, focusing on signal-to-noise ratios, mean-time-to-remediate (MTTR), and researcher satisfaction.</li>
</ul>
<h4><strong>2. Operational Strategy</strong></h4>
<ul>
<li><strong>Vulnerability Pipeline Management:</strong> Oversee the global intake of findings from Bug Bounty platforms, SAST, DAST, and SCA. Ensure the team identifies patterns requiring systemic fixes rather than just "clearing tickets."</li>
<li><strong>Incident Escalation:</strong> Act as the primary escalation point for critical product vulnerabilities. Partner with VPs of Engineering and the CTO to decide when to accept risk for speed versus when to mandate architectural halts.</li>
<li><strong>Tooling Roadmap:</strong> Define the long-term roadmap for security automation—moving the team from manual "chasing" to automated remediation workflows and Slack/Jira integrations.</li>
</ul>
<h4><strong>3. Cross-Functional Influence</strong></h4>
<ul>
<li><strong>Stakeholder Management:</strong> Partner with Product Managers and Engineering Directors to integrate security remediation into their quarterly planning and OKRs.</li>
<li><strong>Policy Design:</strong> Define and enforce "Zero Tolerance" vulnerability classes and auto-remediation rules that block insecure deployments at the Pull Request level.</li>
</ul>
<h3><strong>Requirements</strong></h3>
<ul>
<li><strong>Experience:</strong> 10+ years experience in Product Security, Application Security, or SecOps, including a background in formal people management or technical team leadership.</li>
<li><strong>Technical Depth:</strong> Previous hands-on experience with the <strong>OWASP Top 10</strong>, modern CI/CD pipelines, and cloud-native security (Go, Rust, or Kubernetes environments).</li>
<li><strong>Operational Excellence:</strong> Deep understanding of managing high-volume vulnerability programs (Bug Bounty, SAST/DAST) and the diplomacy required for successful remediation.</li>
<li><strong>Strategic Thinking:</strong> Ability to translate complex technical risks into business impact for non-technical senior leadership.</li>
<li><strong>Education:</strong> Degree in Computer Science, Cybersecurity, or equivalent leadership experience in a high-growth technology environment.</li>
</ul>
<h3><strong>Preferred Qualifications</strong></h3>
<ul>
<li>Experience managing distributed teams in a global "follow-the-sun" model.</li>
<li>Relevant industry certifications such as CISSP, CISM, or CISA.</li>
<li>Familiarity with Cloudflare’s architecture, including Edge computing and Serverless environments.<br><br></li>
</ul><div class="content-conclusion"><p><strong>What Makes Cloudflare Special?</strong></p>
<p><span style="font-weight: 400;">We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.</span></p>
<p><a href="https://blog.cloudflare.com/protecting-free-expression-online/"><strong>Project Galileo</strong></a><span style="font-weight: 400;">: Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.</span></p>
<p><strong><a href="https://www.cloudflare.com/athenian/">Athenian Project</a></strong><span style="font-weight: 400;">: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we've provided services to more than 425 local government election websites in 33 states.</span></p>
<p><a href="https://1.1.1.1/"><strong>1.1.1.1</strong></a><span style="font-weight: 400;">: We released</span><a href="https://1.1.1.1/"> <span style="font-weight: 400;">1.1.1.1</span></a><span style="font-weight: 400;"> to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our</span><a href="https://developers.cloudflare.com/1.1.1.1/privacy/public-dns-resolver"> privacy commitment</a><span style="font-weight: 400;"> and ensure that no user data is sold to advertisers or used to target consumers.</span></p>
<p><span style="font-weight: 400;">Sound like something you’d like to be a part of? We’d love to hear from you!</span></p>
<p><span style="font-weight: 400;">This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.</span></p>
<p><span style="font-weight: 400;">Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual</span> <span style="font-weight: 400;">race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. </span><span style="font-weight: 400;">We are an AA/Veterans/Disabled Employer.</span></p>
<p><span style="font-weight: 400;">Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at </span><span style="font-weight: 400;">hr@cloudflare.com</span><span style="font-weight: 400;"> or via mail at 101 Townsend St. San Francisco, CA 94107.</span></p></div>
Key Skills
Product SecurityApplication SecuritySecOpsPeople ManagementTechnical LeadershipVulnerability ManagementIncident EscalationSecurity AutomationCloud SecurityCI/CD PipelinesOWASP Top 10Bug BountySASTDASTKubernetesStrategic Thinking
Categories
TechnologyManagement & LeadershipSecurity & SafetyEngineering
Apply Now
Please let Cloudflare know you found this job on InterviewPal. This helps us grow!
Prepare for Your Interview
We scan and aggregate real interview questions reported by candidates across thousands of companies. This role already has a tailored question set waiting for you.
Elevate your application
Generate a resume, cover letter, or prepare with our AI mock interviewer tailored to this job's requirements.