System Engineer, Behavioral Analysis
- Location
- Hybrid
- Salary
- $150K–$206K / yr
- Posted
- September 30, 2026
- Source
- Greenhouse
Job description
About Us
Available Locations: Austin Texas or New York
About the Role
Cloudflare One brings together secure access, network connectivity, and data protection. Our products generate massive amounts of signals about how people and agents access applications, use the network, and handle data—but a security practitioner needs more than isolated events. They need to understand what happened, whether it is unusual, why it matters, and what to investigate next.
The UEBA (User and Entity Behavior Analytics) team builds the systems behind those answers. We ingest and evaluate Cloudflare One signals, produce high fidelity user-risk events, maintain risk scores, and make that information available to customer-facing experiences and other Cloudflare services. Today, we are focused on expanding our behavioral detections and improving the clarity of the resulting investigations and integrations.
As a Systems Engineer, you will build and operate production services in this pipeline. You might implement a detection for an unusual pattern of DNS activity or data movement, improve how events contribute to a user’s risk score, or make risk-event history easier for customers to investigate. You will own well-defined projects through design, implementation, testing, rollout, and operational follow-through, working with other engineers, Product, and partner teams across Cloudflare.
Responsibilities
- Build behavioral detections . Turn product requirements and available telemetry into production-ready detections across signals such as Access, Gateway, DNS, device posture, and data protection. Define the data dependencies, evaluation approach, and how you will assess signal quality before release.
- Make risk understandable . Help connect detection output to event history, logs, and customer-facing investigations so practitioners can see what triggered a finding and how a user’s risk changed.
- Design & Scale Infrastructure : Architect, deploy, and maintain robust distributed systems, focusing on high availability, low latency, and horizontal scalability.
- Collaborate across teams . Collaborate with Product and engineers in Access, Gateway, Analytics and Reporting, Logs, and other data-producing or data-consuming teams to agree on event contracts and deliver end-to-end functionality.
- Ensure Reliability . Participate in architecture reviews, capacity planning, and proactive system health monitoring to guarantee maximum uptime and resilience.
Desirable Skills, Knowledge, and Experience
- 3+ years of professional experience building, testing, and operating backend or distributed systems in production.
- Strong proficiency in at least one systems programming language (e.g., Go, Rust, C/C++) with a track record of writing clean, maintainable code.
- 3+ years of practical experience with databases and data-intensive services—for example, PostgreSQL, ClickHouse, or comparable relational or analytical stores.
- Experience reasoning about event-driven systems: message delivery, duplicate or late events, state, failure recovery, and safe changes to live consumers or APIs.
- Clear written and verbal communication, and an ability to work through technical decisions with product and engineering partners.
- Experience using metrics, logs, traces, profiling, and experiments to understand production behavior and validate improvements
- Bring strong opinions, clear judgment, and a willingness to revise your view when data, users, or production reality prove otherwise.
Bonus Points
- Experience with security analytics, fraud or abuse detection, identity, Zero Trust, SASE, or network telemetry.
- Familiarity with Kafka or other streaming systems; Kubernetes; and high-volume event processing.
- Experience with statistical baselines, anomaly detection, time-windowed aggregation, or evaluating false positives and detection coverage.
- Familiarity with DNS, HTTP, authentication events, data-loss-prevention signals, or endpoint-security integrations.
- Experience with distributed state, caches, object storage, or safe migration of a legacy production service.
Compensation
Compensation may be adjusted depending on work location and level.
New York Estimated Base salary $150,000 - $206,000.
Austin Texas Estimated Base salary $136,000 - $187,000.