We are seeking a hands-on Senior Cloudflare Solutions Engineer to design build and deploy a production-ready Cloudflare Workers transparent proxy and edge-security perimeter for an enterprise search platform. The engagement will address client-side API-key exposure restore accurate client-IP analytics and implement Cloudflare WAF Advanced Rate Limiting and bot protection to defend the platform against AI scraping automated traffic and quota abuse.
Design and develop a secure transparent proxy using Cloudflare Workers. Route browser-based search requests securely through the Cloudflare edge. Prevent direct exposure or misuse of third-party search API credentials. Implement secure API-key handling and server-side request validation. Preserve accurate client-IP information for analytics security monitoring and rate limiting. Prevent spoofing or manipulation of forwarded client-IP headers. Configure Cloudflare WAF custom rules and managed rulesets. Implement Cloudflare Advanced Rate Limiting across IP session endpoint and behavioural attributes. Design bot and abuse controls to mitigate AI scraping and automated traffic. Implement request filtering header manipulation origin protection and secure routing. Restrict permitted API methods indexes endpoints and request parameters. Configure logging monitoring alerting and security-event visibility. Support development testing UAT and production deployment. Establish CI/CD configuration management and rollback procedures. Conduct performance security and failure testing. Troubleshoot Cloudflare DNS TLS caching routing and origin-connectivity issues. Prepare architecture diagrams configuration documentation operating procedures and handover materials. Collaborate with product security cloud and application teams. Provide knowledge transfer to internal technical teams. Mandatory Experience Strong hands-on experience developing and deploying Cloudflare Workers using JavaScript or TypeScript. Demonstrated experience building reverse proxies transparent proxies or API gateways at the edge. Strong experience with Cloudflare WAF and custom firewall rules. Hands-on experience with Cloudflare Advanced Rate Limiting. Experience implementing Cloudflare Bot Management or equivalent bot-mitigation controls. Strong understanding of HTTP/S DNS TLS REST APIs headers cookies and caching. Experience with secure API-key token and credential-management patterns. Experience preserving trusted client-IP information through proxies and CDN layers. Strong application and API-security knowledge including OWASP Top 10 and OWASP API Security. Experience protecting public APIs from scraping credential abuse automated traffic and denial-of-wallet attacks. Production deployment and troubleshooting experience in enterprise environments. Ability to produce clear technical designs operational documentation and knowledge-transfer materials. Highly Desirable Experience integrating Cloudflare Workers with Algolia or a similar hosted search platform. Understanding of Algolia search keys secured API keys indexes analytics and usage quotas. Experience using Cloudflare API Shield Turnstile Zero Trust KV D1 Durable Objects or Queues. Infrastructure-as-Code experience using Terraform. CI/CD experience using GitHub Actions Azure DevOps or similar platforms. Experience with Cloudflare Logpush SIEM integration and security analytics. Experience protecting services from generative-AI crawlers and sophisticated scraping tools. Cloudflare certifications or formal Cloudflare partner training. Experience delivering solutions within regulated or security-sensitive organisations. Expected Deliverables Current-state review and confirmed technical requirements. Solution architecture and detailed implementation design. Production-ready Cloudflare Workers transparent proxy. Secure API-key and request-validation controls. Trusted client-IP preservation and analytics solution. Cloudflare WAF and custom security rules. Advanced Rate Limiting policies. Bot AI-scraping and automated-abuse protection. Logging monitoring and alerting configuration. Test plan and evidence covering functionality security and performance. Deployment rollback and operational runbooks. Knowledge-transfer sessions and final handover documentation. Engagement
The successful consultant must be available for up to 20 hours per week over six weeks and be capable of working independently while collaborating with the customer’s product and technology teams. Candidates must provide examples of Cloudflare Workers solutions they have personally designed and coded. Shortlisted applicants may be asked to complete a practical technical assessment covering proxy development header handling rate limiting and bot mitigation. Pay ₹487677.24 - ₹1671576.33 per year
Remote
Unlock: Sign Up for free / Sign In and use the searches from your home page or the links in the footer.