Security Engineer - Cloud and Network Security

Gusto
San Jose, CA, United States
19 days ago
Apply on job-boards.greenhouse.io
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$210,000.0 - $230,000.0
Working hours
Regular working hours

Tech stack

Kubernetes Security Microsoft Access Artificial Intelligence Amazon Web Services Amazon Cloudfront Cloud Computing Cloud Computing Security Computer Networks Continuous Integration DDoS Mitigation Identity and Access Management Intrusion Detection and Prevention
+15 more
Key Management Network Security Network Architecture Performance Tuning Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Policy as Code Large Language Models Firewalls (Computer Science) Amazon Virtual Private Cloud (VPC) HR Software Cloudflare Terraform Ddos

Job description

We’re looking for a Security Engineer to lead Gusto’s edge and network security strategy, owning the design and operation of our Cloudflare WAF, DDoS protection, Zero Trust, and broader perimeter controls. The ideal candidate brings deep, hands-on Cloudflare expertise and a proven track record of hardening edge and network architectures at scale, including tuning WAF rulesets, defending through live DDoS events, and shipping Zero Trust rollouts engineers actually adopt. You think in terms of layered defense, measurable risk reduction, and automation over manual toil. In this role, you’ll serve as a force multiplier across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound over time.

About the Team:

The Gusto’s Enterprise Security Engineering team, a small but high-leverage group responsible for cloud security posture, edge and network defense, container security, secrets management, and endpoint protection across the company. The team runs a modern stack including Cloudflare, Wiz, CrowdStrike, Panther, and Tines, scaling impact through automation, IaC, and AI-augmented tooling. The work carries real stakes, protecting the payroll, benefits, and HR systems that hundreds of thousands of small businesses and their employees rely on every day. The team is engineering-first, with most of the roadmap living in code and a strong emphasis on partnering with infrastructure and product teams rather than gatekeeping them.

Here’s what you’ll do day-to-day:

  • Design and operate Gusto’s edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
  • Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
  • Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
  • Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
  • Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
  • Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
  • Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own., Glassdoor Indeed Facebook Built In Colorado News Article Conference or Meetup Company Blog Company Employee Company Website Billboard/Outdoor Ads

Are you legally authorized to work in the country where you are applying?* Select… Will you now or in the future require visa sponsorship for employment?* Select…, In addition to the information required to consider your application, below is a set of demographic questions that help us identify areas for improvement in our process and further support the development and execution of our diversity efforts and programs as well as to create a more inclusive environment for all employees.

Requirements

  • 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
  • Deep, production-grade expertise with Cloudflare’s security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
  • Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs.
  • Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
  • Solid generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience on edge and network telemetry in a modern SIEM.
  • AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations that compound team output.
  • Excellent written and verbal communication; you can take a complex perimeter decision and explain the tradeoffs to a staff engineer, a PM, and a VP without changing the substance.
  • Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent., You are considered to have a disability if you have a physical or mental impairment or medical condition that substantially limits a major life activity, or if you have a history or record of such an impairment or medical condition. Disabilities include, but are not limited to:
  • Blindness
  • Deafness
  • Cancer
  • Diabetes
  • Epilepsy
  • Autism
  • Cerebral palsy
  • HIV/AIDS
  • Schizophrenia
  • Muscular dystrophy
  • Bipolar disorder
  • Major depression
  • Multiple sclerosis (MS)
  • Missing limbs or partially missing limbs
  • Post-traumatic stress disorder (PTSD)
  • Obsessive compulsive disorder
  • Impairments requiring the use of a wheelchair
  • Intellectual disability

Benefits & conditions

At Gusto, we’re on a mission to grow the small business economy. We handle the hard stuff - payroll, health insurance, 401(k)s, and HR - so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs) - because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy.

AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process., If you’ll require this employer to commence, i.e., “sponsor,” an immigration or work permit case in order to employ you, either now or at some point in the future, then you should answer yes. An example of an immigration or work permit case that may require sponsorship now or in the future would be an H-1B or other employment-based work permit sponsorship. How many years of hands-on network security experience do you have?* How do you manage Cloudflare configuration as code at scale?*

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on job-boards.greenhouse.io
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:51 min

Rising DDoS attacks and evaluating CDN mitigation strategies

Chris Heilmann +2 · LIVE

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

4:56 min

Configuring server-side rendering and Cloudflare deployment

Francesco Napoletano Francesco Napoletano · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:11 min

Surviving sudden scale events and malicious traffic

Justin Kitagawa · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all