Gusto
Senior Staff Security Engineer - Cloud and Network Security
San Francisco, CA · Staff+ · Full-time
Sponsorship not specifiedDetected 16 days ago
AWSTerraformCI/CDLLMsCybersecurityNetwork SecurityDetection EngineeringIncident ResponseRecruitingFirewallZero TrustCommunication
About the role
- You think in terms of layered defense, measurable risk reduction, and automation over manual toil.
- In this role, you'll serve as a force multiplier across the security org, partnering with infrastructure and product teams to make high-impact architectural decisions that compound over time.
- The Gusto's Enterprise Security Engineering team, a small but high-leverage group responsible for cloud security posture, edge and network defense, container security, secrets management, and endpoint protection across the company.
Responsibilities
- Design and operate Gusto's edge security stack including Cloudflare WAF, DDoS protection, Bot Management, WARP, Gateway, and Access, tuning rules against real traffic and shaping how engineers and operations teams reach internal systems securely.
- Own the network security perimeter across AWS and the edge: VPC design, Network Firewall, Shield, CloudFront, NACLs, and egress filtering, all codified in Terraform and Crossplane, observable, and consistently enforced.
- Develop policy-as-code patterns for WAF rules, network policies, and edge configuration so changes ship through pull requests with review, testing, and clean rollback paths.
- Build detections and alerting on edge and network telemetry including Cloudflare logs, VPC Flow Logs, and CloudTrail flowing into Panther, and lead incident response for perimeter and network events.
- Prototype and ship agents, custom MCP servers, and LLM-assisted automations that compress security work from days to minutes and raise the bar for what one engineer can own.
- With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.
Requirements
- 10+ years of hands-on security engineering experience, with significant time owning edge, network, or perimeter security at scale.
- Deep, production-grade expertise with Cloudflare's security stack including WAF, DDoS, Bot Management, WARP, Gateway, and Access, covering rule tuning, incident response, and Zero Trust rollouts.
Nice to have
- Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls
- Crossplane or similar a plus.
- Relevant certifications a plus including AWS Certified Advanced Networking Specialty, AWS Certified Security Specialty, Cloudflare Certified Security Associate/Professional, CKS, or equivalent.
Skills
- Fluency with policy-as-code, Terraform, and CI/CD-first delivery of security controls; Crossplane or similar a plus.
Compensation
- All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success.
Benefits
- We handle the hard stuff - payroll, health insurance, 401(k)s, and HR - so owners can focus on their craft and their customers.
- All full-time employees receive competitive base pay, benefits, and equity (RSUs) - because everyone who helps build Gusto should share in its success.
- Learn more about our Total Rewards philosophy.
- Stock equity is additional.
Company info
- The team runs a modern stack including Cloudflare, Wiz, CrowdStrike, Panther, and Tines, scaling impact through automation, IaC, and AI-augmented tooling.
- The work carries real stakes, protecting the payroll, benefits, and HR systems that hundreds of thousands of small businesses and their employees rely on every day.
- The team is engineering-first, with most of the roadmap living in code and a strong emphasis on partnering with infrastructure and product teams rather than gatekeeping them.
- Here's what you'll do day-to-day:
- Contribute broadly across the security engineering surface including cloud posture, container security, IAM, vulnerability management, and on-call, bringing a strong generalist instinct to wherever the work is most critical.
- Operate as an AI-native engineer, using Claude Code, MCP-driven tooling, and agentic workflows as a daily force multiplier across investigation, automation, and detection engineering.
- Here's what we're looking for:
This listing is sourced directly from Gusto's careers page and normalized into a canonical job model.