Security Engineer - Cloud and Network Security
Gusto- Base salary
- $210k–$270k Published base salary range
- Location
- Hybrid - San Francisco, CA, 2-3 days/week Remote eligibility
- Employment
- Full-time Mid-level
About the job
About the Role
Gusto is looking for a Security Engineer to lead its edge and network security strategy, owning the design and operation of Cloudflare WAF, DDoS protection, Zero Trust, and broader perimeter controls. The ideal candidate brings deep, hands-on Cloudflare expertise and a proven track record of hardening edge and network architectures at scale, including tuning WAF rulesets, defending through live DDoS events, and shipping Zero Trust rollouts engineers actually adopt. The engineer will serve as a force multiplier across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions.
About the Team
The Enterprise Security Engineering team is a small, high-leverage group responsible for cloud security posture, edge and network defense, container security, secrets management, and endpoint protection across the company. The team runs a modern stack including Cloudflare, Wiz, CrowdStrike, Panther, and Tines, scaling impact through automation, IaC, and AI-augmented tooling.
Responsibilities
- Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic.
- Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane.
- Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
- Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
- Contribute broadly across cloud security, container security, IAM, vulnerability management, and on-call.
- Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows; prototype and ship agents, custom MCP servers, and LLM-assisted automations.
Qualifications
- 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
- Production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
- Strong network architecture skills across edge and cloud: TLS/mTLS, segmentation, egress controls, DDoS resilience, and AWS networking including VPC, Network Firewall, Shield, CloudFront, and NACLs.
- Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
- Generalist foundation across cloud security, IAM, container security, and detection engineering, with hands-on incident response experience in a modern SIEM.
- AI-native working style with daily use of Claude Code or equivalent agentic tooling, and a track record of building AI-assisted workflows including custom MCP servers, agents, and LLM automations.
- Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent.
Compensation
Cash compensation is targeted at $210,000/yr to $230,000/yr in Denver & most remote locations, and $230,000/yr to $270,000/yr for San Francisco, New York & Seattle. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise.
Benefits
All full-time employees receive competitive base pay, benefits, and equity (RSUs).
Work Location
Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees based in those locations are expected to work from the office on designated days approximately 2-3 days per week. The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.
Application
Apply via the Gusto Greenhouse job posting. Gusto is an equal opportunity employer and considers qualified applicants with criminal histories consistent with applicable law. Reasonable accommodations are available; see the application for the accommodation form.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.