Fall 2026
Posted on 6/23/2026
CDN, cybersecurity, and serverless computing platform
No salary listed
Company Historically Provides H1B Sponsorship
Austin, TX, USA
In Person
Work from the Austin office 3-5 days per week during the fall.
Preparing a concise company summary based on the provided Cloudflare description.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
People at Cloudflare who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salaries
Take-what-you-need paid vacation policy
Comprehensive health plans and benefits
Paid maternity and paternity leave
Commuter and ride share options
Returnships
Cybersecurity weekly update: 8-15 June 2026. * 4 days ago 1. Microsoft's record-breaking patch tuesday drops 206 fixes. In what has officially become the largest security update release in the history of the program, Microsoft patched 206 security flaws this past week. The massive release includes 32 critical vulnerabilities and three publicly disclosed zero-days. While none of the three zero-days are currently reported to be actively exploited in the wild, their public disclosure means threat actors are actively developing proof-of-concept exploits. * CVE-2026-50507 (CVSS 6.8): A protection mechanism failure in Windows BitLocker that could allow an attacker with physical access to bypass drive encryption and steal sensitive data. * CVE-2026-45586 (CVSS 7.8): An elevation of privilege (EoP) flaw in the Windows Collaborative Translation Framework (CTFMON) that can grant an attacker full SYSTEM privileges. Why it matters: Organizations storing highly regulated data on endpoint devices - such as medical records or financial transactions - are at increased risk if laptops are lost or stolen, due to the BitLocker bypass vulnerability. Laptops traveling across European and South African borders are highly exposed. Action: Deploy the June 2026 Windows cumulative updates across all endpoints immediately. For high-risk personnel in finance or healthcare who travel with corporate devices, enforce strict Pre-Boot Authentication (PBA) via your endpoint management tools (MDM/GPO) to act as a vital hardware barrier against physical BitLocker bypasses. 2. The "HTTP/2 Bomb" Threatens enterprise web infrastructure. Security researchers have disclosed a severe vulnerability in the default configurations of major web servers - including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora. Tracked as CVE-2026-49975, the flaw combines a compression bomb with a Slowloris-style flow-control window hold. A single attacker operating from a basic home internet connection can leverage this flaw to consume up to 32GB of server memory in less than 20 seconds, crashing web applications instantly. Why it matters: Online banking platforms, public health portals, and university student portals running default web server configurations are highly vulnerable to prolonged denial-of-service (DoS) attacks, rendering vital services inaccessible to citizens and clients. Action: Prioritize the immediate update of your exposed web servers (NGINX, Apache, IIS, Envoy) to their latest secure versions. If immediate patching is impossible due to operational downtime constraints, configure your edge firewalls or Web Application Firewall (WAF) to enforce strict maximum limits on header size and stream counts, or temporarily disable HTTP/2 support on public-facing banking and student portals. 3. Active exploitation: Cisco Catalyst SD-WAN Manager zero-day. Cisco issued an urgent warning regarding a high-severity, unpatched zero-day flaw (CVE-2026-20245) affecting its Catalyst SD-WAN Manager. Local, authenticated attackers with netadmin access are actively exploiting this vulnerability via the command-line interface to achieve root privilege escalation and push rogue configuration changes to network edge devices. Why it matters: This represents a continuing, severe campaign against SD-WAN infrastructure this year. For defense organizations, financial backbones, and healthcare networks managing highly distributed networks across South Africa and Europe, an unauthorized configuration push could compromise the integrity of isolated communication channels or silently redirect secure traffic. Action: Because a permanent vendor patch is still pending under intense crunch conditions, completely isolate your Cisco Catalyst SD-WAN management interfaces from the public internet. Restrict all administrative console access strictly to isolated internal networks or dedicated out-of-band management segments using tight Access Control Lists (ACLs), and immediately audit configuration logs for any unauthorized root-level modifications. (Source: https://nvd.nist.gov/vuln/detail/CVE-2026-20245) 4. UK NCSC: testing frontier AI models in National Cyber defense. The UK's National Cyber Security Centre (NCSC) published a landmark case study detailing their framework for bringing frontier Artificial Intelligence out of the laboratory and into government cyber defense infrastructure. Concurrently, global threat intelligence reports note that ransomware syndicates are aggressively adopting automated AI tools to scale their operations - specifically using machine learning to automate system reconnaissance and optimize social engineering tactics. Why it matters: As defensive frameworks adopt AI to accelerate patch management, threat actors are using the exact same technology to spot vulnerabilities faster. Organizations across all target spaces must evaluate their third-party software supply chains to ensure vendors are securing their own AI implementations. Action: Conduct an enterprise-wide audit of internal development pipelines and shadow AI tool usage. Ensure your development teams are not pulling insecure or unvetted open-source AI building blocks into production environments, and demand a comprehensive Software Bill of Materials (SBOM) from your third-party software vendors to verify how they secure their own integrated AI systems. (Source: https://www.gov.uk/government/case-studies/when-ai-leaves-the-lab-testing-frontier-models-in-government-cyber-defence) Key recommendations: * Immediately update your core web server software (NGINX, Apache, IIS, Envoy) to its latest safe version, or have your web provider block unusually heavy incoming traffic to prevent your servers from crashing under the HTTP/2 Bomb exploit. * Force a mandatory update to the June 2026 security patch on all work and personal systems, and configure endpoint policies to enforce strict Pre-Boot Authentication (PBA) to block unpatched or physically compromised devices from exposing local corporate data. * Disconnect the Cisco management screen from the public internet entirely and restrict login access strictly to trusted IT administrator computers using strict Access Control Lists (ACLs). * Heavily restrict what company data your AI tools are allowed to see, and install a specialized safety filter to scan all question text and third-party software dependencies before they reach your core models.
Cloudflare Radar data shows automated bot traffic now accounts for 57.5% of HTML webpage requests, surpassing human traffic for the first time in internet history, driven by surging agentic AI.
Acquire announces partnership with Cloudflare. Acquire is excited to announce its new partnership with Cloudflare, further strengthening its ability to deliver advanced cybersecurity, networking and cloud solutions to businesses across New Zealand and Australia. As organisations continue to embrace hybrid work, cloud-first strategies and digital transformation initiatives, the need for secure, high-performing and scalable infrastructure has never been greater. Through this partnership, Acquire can now provide customers with access to Cloudflare's globally recognised cloud connectivity and security platform, helping businesses improve protection, performance and reliability across their environments. Cloudflare powers and protects millions of websites, applications and networks worldwide, delivering enterprise-grade security and performance through one of the largest global cloud networks. By partnering with Cloudflare, Acquire can help organisations modernise traditional network architectures, strengthen cybersecurity postures and create more secure experiences for employees and customers alike. Through the partnership, Acquire can offer a wide range of Cloudflare solutions and services, including: Zero Trust Security Help secure users, devices and applications regardless of location by replacing traditional perimeter-based security models with modern Zero Trust architecture. Secure Access Service Edge (SASE) Combine networking and security into a unified cloud-delivered platform designed to support hybrid and remote workforces while improving visibility and control. DDoS & Threat Protection Protect websites, applications and critical infrastructure from cyber threats, malicious traffic and distributed denial-of-service attacks with always-on security protection. Web Application & API Security Safeguard business-critical applications and APIs from vulnerabilities, bots and sophisticated attacks while maintaining performance and uptime. Secure Remote Access Enable employees and third-party users to securely access corporate applications and systems without the complexity of traditional VPN infrastructure. Network & Application Performance Improve website speed, application responsiveness and network reliability through intelligent traffic routing, content delivery and optimisation services. Cloud Email Security Enhance email protection against phishing, malware, ransomware and business email compromise attacks through advanced cloud-native security controls. WAN & Infrastructure Modernisation Simplify network management and reduce complexity by transitioning from traditional hardware-based networking to flexible cloud-native architectures. Acquire's experienced team works closely with customers to understand their unique environments, challenges and business objectives. Together with Cloudflare, Acquire can deliver tailored solutions that improve security, simplify operations and support future growth. This partnership also complements Acquire's broader cloud, networking and cybersecurity capabilities, enabling customers to access end-to-end technology solutions backed by trusted vendors and expert local support. Whether organisations are looking to strengthen cybersecurity resilience, modernise network infrastructure, support hybrid workforces or improve application performance, Acquire and Cloudflare provide the technology and expertise to help businesses move forward with confidence. Acquire is excited about the opportunities this partnership brings and look forward to helping its customers unlock the full potential of secure, connected and cloud-driven business environments. To learn more about Cloudflare solutions through Acquire or to arrange a consultation with its team, get in touch today. Contact Acquire to discuss your journey to the Cloud today!
Cloudflare layoffs 2026: 1,100 employees cut as AI agents replace jobs - Despite 34% revenue growth. Cloudflare is laying off 1,100 employees (20% of its workforce) despite Q1 2026 revenue rising 34% to $639.8M. CEO Matthew Prince says AI agent usage surged 600% in 3 months, making traditional roles obsolete. 9 May 2026 by Mediosick Discover more Racing Video Games Video Games Quick facts: Cloudflare announced on May 7, 2026 that it is laying off approximately 1,100 employees - about 20% of its 5,156-person global workforce. The cuts were announced alongside strong Q1 2026 earnings (revenue up 34% year-over-year to $639.8M). CEO Matthew Prince and COO Michelle Zatlyn cited a 600% surge in internal AI agent usage in just three months as the driving force. The restructuring is expected to cost $140-$150 million. Cloudflare's stock (NET) dropped approximately 24% following the announcement. Inside the Cloudflare mass layoff: In the spring of 2026, Cloudflare (one of the most recognized names in global internet infrastructure and cybersecurity) made a major decision. Despite being in its strongest financial position in years, the company announced it would eliminate more than 1,100 roles, reducing its headcount from approximately 5,156 to around 4,000 employees worldwide. "The way we work at Cloudflare has fundamentally changed." - Matthew Prince, CEO & Michelle Zatlyn, COO / Co-Founder, Cloudflare (Staff Memo, May 7, 2026) The announcement arrived in a staff memo, published openly on the Cloudflare blog and titled "Building for the Agentic AI Era." In it, Prince and Zatlyn explained that Cloudflare's internal use of AI agents had surged more than 600% over the prior three months alone. Teams across engineering, finance, human resources, and marketing were described as now running "thousands of AI agent sessions each day" - a transformation that rendered many traditional roles redundant not because of poor performance, but because the nature of the work itself had changed. The co-founders were explicit: "Today's actions are not a cost-cutting exercise or an assessment of individuals' performance; they are about Cloudflare defining how a world-class, high-growth company operates and creates value in the agentic AI era." Speaking during the Q1 earnings call, Prince described artificial intelligence as "the biggest tailwind we've ever seen in Cloudflare's history," arguing that the re-platforming of the internet around AI agents represents the company's single largest growth opportunity. He also acknowledged the human cost directly: "Today is a hard day." Yet despite beating expectations on revenue, adjusted earnings per share ($0.25 vs. $0.23 estimate), and free cash flow ($84.1 million, or 13% of revenue), markets were unmoved by the strong numbers. C loudflare's stock (NYSE: NET) plunged approximately 24% in the trading session following the announcement. The company's decision to execute one large restructuring rather than a series of rolling smaller cuts was itself a deliberate strategy. The memo noted: the company wanted to avoid "prolonged emotional uncertainty for employees" and the operational stagnation that multiple rounds of smaller layoffs create. Industry observers noted the severance package is unusually generous by the standards of 2026 tech layoffs. The total restructuring bill is projected at $140 million to $150 million: of that, $105-$110 million represents cash outflows for severance, notice periods, and employee benefits, while a further $35-$40 million is a non-cash expense tied to accelerated equity vesting. Agentic AI: Unlike simple AI chat tools or code auto-completers, agentic AI systems are capable of autonomously completing multi-step tasks - planning, executing, and iterating across complex workflows without human oversight at each step. In early 2026, Cloudflare's employees began leveraging such systems at an extraordinary rate, enabling a level of per-person productivity that made certain roles structurally redundant. "There are roles at the company that just aren't the roles that we need for the future." - Matthew Prince, CEO, Cloudflare - Q1 2026 Earnings Call The reasons behind layoffs: Employees across all departments began running thousands of AI agent sessions daily, dramatically compressing workloads that previously required dedicated headcount. Cloudflare explicitly stated the move is not a response to financial pressure. Q1 2026 was one of its strongest quarters on record. The leadership team chose a single large restructuring to prevent the organizational drag and emotional toll of repeated smaller layoffs over multiple quarters. The company is restructuring roles and teams to operate natively with AI automation, rather than layering AI tools on top of traditional org structures. Cost savings from the restructuring are projected to be reinvested into AI infrastructure and new AI-native hiring - roles that don't exist yet at scale. Despite the strong Q1, Cloudflare issued conservative forward guidance of $664-$665M for Q2 and $2.805-$2.813B for full-year 2026, signaling near-term reinvestment over margin expansion. Questions for you: * What is your opinion on the decision made by the CEO of Cloudflare? * Would you trust an AI agent to handle your company's HR or financial decisions? * Do you think AI "agents" can truly replace the nuance of a human employee, or is this just a corporate trend? Mediosick 9 May 2026 Its posts.
Cloudflare launches Code Mode MCP server to optimize token usage for AI agents. Write for infoq. Feed your curiosity. Help 550k+ global senior developers each month stay ahead. Get in touch Cloudflare has introduced a major evolution in how AI agents access complex APIs by launching a new Model Context Protocol (MCP) server powered by Code Mode, dramatically reducing the cost of interacting with its full API platform. The new approach highlights a new way for agent-to-tool integrations in the MCP ecosystem. At its core, MCP is an emerging standard that lets large language models (LLMs) interface with external tools and APIs by exposing structured tools the model can call during execution. Traditionally, each API endpoint exposed to an agent represented a separate tool definition. While straightforward, this model incurs a significant context window cost every time a tool specification consumes tokens in the model's limited input budget, leaving less room for reasoning about the user's task. Luuk Hofman, Solutions Engineer at Cloudflare, noted: So InfoQ tried: convert MCP tools into a TypeScript API and just ask the LLM to write code against it. Cloudflare's Code Mode instead exposes only two tools, search and execute, backed by a type-aware SDK that allows the model to generate and execute JavaScript inside a secure V8 isolate. This compiles an agent's plan into a small code snippet orchestrating multiple operations against the OpenAPI spec, avoiding the need to load all endpoint definitions into context. Traditional MCP vs Cloudflare Code Mode (Source: Cloudflare Blog Post) The practical impact is significant: Cloudflare reports that Code Mode reduces the token footprint of interacting with over 2,500 API endpoints from more than 1.17 million tokens to roughly 1,000 tokens, a reduction of around 99.9%. This fixed footprint holds regardless of API surface size, enabling agents to work across large, feature-rich platforms without exhausting the model context. Cloudflare emphasized in a Reddit post: The team utilized a specialized encoding strategy to fit expansive API schemas into minimal context windows without losing functional precision. Agents first use search to query the OpenAPI spec by product area, path, or metadata; the spec itself never enters the model's context. Then, execute runs code handling pagination, conditional logic, and chained API calls in a single cycle, cutting round-trip overhead. Cloudflare emphasized the security and sandboxing model during execution. The server runs user-generated code in a Dynamic Worker isolate with no file system, no environment variables exposed, and outbound requests controlled via explicit handlers. This design mitigates risks associated with executing untrusted code while preserving agent autonomy. This new MCP server for the entire Cloudflare API spans DNS, Zero Trust, Workers, and R2 services already and is immediately available for developers to integrate. Cloudflare also open-sourced a Code Mode SDK within its broader Agents SDK to enable similar patterns in third-party MCP implementations. Analysts and practitioners see Code Mode as a key step in scaling agentic workflows beyond simple, single-service interactions toward broad, multi-API automation. The pattern may influence both standard MCP server designs and agent frameworks in the coming year, as industry players grapple with context costs and orchestration complexity in production-grade AI agents. Leela kumili. Leela is a Lead Software Engineer at Starbucks with deep expertise in building scalable, cloud-native systems and distributed platforms. She drives architecture, delivery, and operational excellence across the Rewards Platform, leading efforts to modernize systems, improve scalability, and enhance reliability. In addition to her technical leadership, Leela serves as an AI Champion for the organization, identifying opportunities to improve developer productivity and workflows using LLM-based tools and establishing best practices for AI adoption. She is passionate about building production-ready systems, enhancing developer experience, and mentoring engineers to grow in both technical and strategic impact. Her interests include platform engineering, distributed systems, developer productivity, and bridging technical solutions with business and product goals. This content is in the Model Context Protocol (MCP) topic.