Diversity as a Security Strategy

When we joined Cloudflare’s security team in mid-2018, the group was small but the mandate was clear: scale the team to match the company’s growing profile as a provider of cyber protection for millions of Internet-facing properties. Eighteen months later, we have grown the team from under 10 people to nearly 50. Along the way, we have maintained a focus on building a group that reflects a broader range of backgrounds: 40% of our team are women and 25% are from under-represented minority groups.

This wasn’t accidental. Our experience, backed by research, is that diverse teams produce better business outcomes. In honor of International Women’s Day, we are sharing the practices that helped us build this team and, just as importantly, keep it together.

How We Hire

Our approach to building a diverse team begins before we ever see a resume. It starts with the job posting itself. We deliberately choose language that appeals to a wide range of candidates, and we question traditional prerequisites like college degrees or strict experience minimums. We also avoid the militaristic terminology that pervades many security job descriptions, opting instead for language that invites people who are looking to grow.

We cast a wide net across multiple hiring channels:

  • Location flexibility: Cloudflare has 13 offices globally, and we remain open to basing roles in different offices.
  • Multiple sourcing channels: We rely on employee referrals but balance them with company-wide presentations to keep our open roles visible across the 1,200-person company. We also see strong candidates who apply directly through our careers site after reading our technical blog posts.
  • Proactive outreach: We trained our team on using LinkedIn and Eightfold to identify passive candidates. When our hiring managers reach out with personalized messages, our response rate exceeds 10%.
  • Long-term relationship building: Closing a promising passive candidate can take six months to a year. We stay in touch by sharing company updates and the new problems we are tackling.

We also engage with candidates through events like the Grace Hopper conference, AfroTech, and the International Association of Minority Cybersecurity Professionals. Partnerships with organizations such as Path Forward help us connect with talent we might otherwise miss.

Our internship program serves as another pipeline. By exposing interns to the work, we can evaluate their skills directly and challenge assumptions about which educational backgrounds qualify. Several interns who impressed us during short stints have moved into full-time roles.

We are also deliberate about the interview panel. The process is as much about showing the candidate who we are as it is about evaluating them. Candidates need to see someone across the table who makes them comfortable asking the question, “Can someone like me succeed here?”

Finally, we hold ourselves accountable. Our company leadership meets weekly to review metrics on hiring, retention, and diversity across management. We also receive direct support from our co-founders, one of whom always meets the candidate in a final interview. A welcoming message from the top goes a long way.

Building an Inclusive Culture

Hiring a diverse team is not a finish line. On a team where people don’t necessarily share the same background, leadership responsibility increases. Turning a diverse group into a highly productive one requires a culture of openness, where people feel safe sharing their perspectives with colleagues who may see the world differently.

To that end, we have made deliberate choices about how we work:

  • Redefining the security professional: We have moved past the media’s “hacker” image and focus on innovation and empathy as core values. We view our role as closer to a scientist designing a cure or a nurse responding to a patient. Technical skill and an attacker mindset are still essential, but we can’t succeed without standing in the shoes of our customers when we impose painful security requirements.
  • Psychological safety: We regularly discuss the need for every team member to believe their opinions are welcome, valued, and will contribute to the greater good.
  • Innovation over reactivity: Security work can easily become reactive. We counter that by encouraging innovation, which has led to open-source contributions, product development, and conference presentations. We are strategic about what we build in-house versus what we buy from vendors.
  • Symbolism and optimism: Our team chose an orange-to-pink phoenix as our logo. It represents resilience and optimism — the idea that we help Cloudflare bounce back from attacks and emerge stronger. The phoenix imagery fits our brand and gives us something we are proud to wear on our t-shirts.

We also build inclusivity through routine practices. We encourage everyone to work on projects outside their sub-team’s core area, which fosters broader interaction and supports career development. We change seating arrangements regularly to expand relationship circles, and we ask team members across the organization to lead meetings and give presentations. Five team members have already been promoted into first-time manager roles.

We hold open-ended manager round-tables to discuss the challenges of leading a diverse team, and we support team members who take active roles in company Employee Resource Groups. Team-building activities are scheduled during business hours and we limit those involving alcohol.

A recurring theme is the need to celebrate success. In security, recognition often comes only in the aftermath of a failure. Most companies celebrate new products and revenue, not the prevention of harm. Without deliberate effort, a security team can start to feel isolated — or worse, perceived as a blocker. We make it a point to recognize the work that keeps the company safe, even when it goes unnoticed.

Turning Vulnerability into Progress

One of our most meaningful meetings was an informal risk review with our engineers. Around the whiteboard, everyone shared their perspective on our biggest risk areas. No two people saw things the same way, but everyone was open to hearing other viewpoints, and many of us changed our priorities in the moment. We left with the uncomfortable awareness of how much work lay ahead.

Within a week, however, every team member had volunteered to take on one of the hardest challenges. Looking back more than a year later, we have made substantial progress on every risk we identified. The session worked because our team’s makeup and culture made it possible — people felt comfortable speaking up about their concerns, even when it was uncomfortable.

Security is stressful work with no end in sight. But bringing together a diverse team built on a foundation of openness and shared purpose has made the hard work more effective. We know there is room to improve, and we welcome suggestions for how we can keep moving in the right direction.