← Back to jobs
Curated sourceApply on company site
Cloudflare
Curated source

Senior Software Engineer, KPI & Cryptographic Systems

CloudflareHybrid
HybridSoftware engineeringsenior€66,000 - €83,000Verified employer
Source checked 1 hour ago. · Posted 5 hours ago.
Checked today

Role details

About Us

  • At Cloudflare, we are on a mission to help build a better Internet.
  • Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.
  • Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code.
  • Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request.
  • As a result, they see significant improvement in performance and a decrease in spam and other attacks.
  • Cloudflare was named to Entrepreneur Magazine's Top Company Cultures list and ranked among the World's Most Innovative Companies by Fast Company.
  • At Cloudflare, we're not looking for people who wait for a polished roadmap; we're looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with.
  • We value candidates who have the instinct to spot a "normalized" problem and the AI-native curiosity to create a solution using the latest tools.
  • Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up.
  • If you're the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you'll fit right in.
Available LocationsAustin, London, or Lisbon (Hybrid)

About the role

TLS is the connective tissue of the Internet, and Cloudflare terminates a large fraction of it.

Every day our network handles tens of millions of certificate operations across products like Universal SSL, SSL for SaaS, Origin CA, Cloudflare Access, and Cloudflare Tunnel — and the WebPKI ecosystem underneath all of it is undergoing its largest structural change in a generation: shorter certificate lifetimes, a shift toward post-quantum-safe signature algorithms, and new automation and trust-establishment mechanisms on the horizon.

We are investing in the next generation of Cloudflare's PKI and cryptographic infrastructure to keep up with, and stay ahead of, that shift.

As a Senior Software Engineer on this team, you will design and build the systems that manage certificate lifecycles, protect and use private keys at scale, integrate with hardware security modules, automate issuance and renewal, and take Cloudflare's cryptographic stack into the post-quantum era.

  • You will work at the intersection of applied cryptography, distributed systems, and security engineering — on infrastructure that a large fraction of the Internet quietly depends on.
  • This is an early-days role on a growing team. The design decisions you make in the first year will shape how Cloudflare's certificate and key infrastructure operates for years to come.

Responsibilities

  • Design and build core PKI systems — certificate lifecycle management, X.509 issuance and validation logic, key parameter enforcement, and policy engines aligned with industry standards including CA/Browser Forum guidance and browser root program policies.
  • Own the cryptographic core. Integrate with FIPS 140-2 Level 3 (and, where required, Level
  • HSMs via PKCS#11 and vendor-native SDKs; build key ceremony and key-lifecycle tooling; enforce strict key-usage boundaries in code.
  • Automate at scale. Build and evolve ACME-based issuance and renewal pipelines, short-lived certificate rotation, and revocation mechanisms that serve at Cloudflare's global scale.
  • Instrument transparency and audit trails. Integrate with Certificate Transparency, build append-only tamper-evident logging, and design evidence pipelines that hold up to rigorous third-party audit.
  • Maintain accreditation and respond to a changing compliance landscape. PKI operations must maintain compliance under CA/B Forum, WebTrust, and root store program frameworks. You will be aware of, and adapt to, changes in relevant policies, participate in public incident disclosure and discourse, and participate in regular third-party audits.
  • Represent Cloudflare in the WebPKI community. Write public CA incident reports and serve as a primary contact with the WebPKI community; clear technical writing is core to this role.
  • Ship the post-quantum future. Contribute to Cloudflare's ongoing post-quantum migration — including work on post-quantum encryption and authentication — so that Cloudflare's cryptographic infrastructure stays ahead of the transition.
  • Own code end-to-end from design through production incident response. Cryptographic infrastructure cannot silently fail; you will build the observability, runbooks, and on-call posture that keep the service inside SLO.
  • Partner across the org — with the SSL/TLS product teams, the HSM and data-centre infrastructure teams, the Cloudflare Research applied cryptography group, and adjacent product teams that consume PKI as a platform.
  • Raise the bar. Mentor other engineers joining an early-stage team, run design reviews, and establish the engineering standards, threat models, and secure-development practices this team will operate under for years.

Desirable Skills, Knowledge & Experience

  • 5+ years of production systems software experience, with a strong operational track record — you have carried a pager for something people depend on.
  • Deep working knowledge of applied cryptography and PKI. X.509, ASN.1/DER, RFC 5280, CRL distribution, Certificate Transparency, ACME, and the CA/Browser Forum Baseline Requirements. You do not need to be a cryptographer, but you need to reason precisely about certificate profiles, key parameters, and issuance policy.
  • Familiarity with HSMs. PKCS#11 integration, key ceremonies, key-attestation flows, and understanding of what FIPS 140-2/3 validation actually means in production.
  • Strong systems programming background in at least one of Go, Rust, or C/C++.
  • Distributed systems fluency — you have built or operated globally replicated, availability-critical services with strict correctness guarantees.
  • Experience designing and operating database schemas for high-integrity systems (Postgres or equivalent).
  • Security-hardened system design instincts — threat modelling, defence in depth, least privilege, and secure key handling.
  • Comfort with high-consequence work. A mis-issued or mis-revoked certificate is a public, industry-visible event. You need the temperament to move quickly and the discipline to be careful.

Bonus Points

  • Direct experience working on or with a publicly-trusted or private CA, or a large-scale internal PKI (Let's Encrypt / Boulder, Google Trust Services, DigiCert, Sectigo, ISRG, Entrust, Microsoft PKI, HashiCorp Vault PKI, step-ca, CFSSL, or an internal CA at scale).
  • Experience with crypto/x509 , BoringSSL, OpenSSL/AWS-LC, CFSSL, or an equivalent PKI codebase.
  • Experience with WebTrust for CAs / WebTrust BR / WebTrust Network Security audit engagements.
  • Familiarity with post-quantum cryptography — ML-DSA, ML-KEM, hybrid signature schemes, and the current state of PQ signature standardisation.
  • Familiarity with emerging browser trust-establishment proposals (e.g. Merkle Tree Certificates).
  • Prior participation in the CA/Browser Forum, IETF LAMPS / TLS / PLANTS / PQUIP working groups, the transparency.dev community, or a browser root program review.
  • Experience running or automating offline key ceremonies.
  • Experience operating Certificate Transparency log infrastructure or CT monitoring at scale.
  • Familiarity with formal methods, differential fuzzing, or property-based testing for cryptographic protocol code.
  • Kubernetes experience.

Compensation

  • For Portugal based hires: Estimated annual salary is between €66,000 - €83,000.

Equity

  • This role is eligible to participate in Cloudflare's equity plan.

Benefits

  • Cloudflare offers a complete package of benefits and programs to support you and your family.
  • Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!
  • The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We're not just a highly ambitious, large-scale technology company. We're a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo : Since 2014, we've equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare's enterprise customers--at no cost.

Athenian ProjectIn 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration.

Since the project, we've provided services to more than 425 local government election websites in 33 states.

1.1.1.1 <span style