About this role
About the Role We are seeking a Cloudflare SSL/TLS Specialist to configure and troubleshoot SSL/TLS between Cloudflare edge and origin servers, ensuring secure connections and certificate validity. What You'll Do
- Validate and manage origin certificates: not expired, not revoked, signed by a CA, CN/SAN matches, and the chain is complete.
- Configure Cloudflare SSL/TLS modes (Full and Full (strict)); implement Cloudflare Origin CA certificates or Custom Origin Trust Store.
- Ensure the origin serves a valid certificate on port 443 and verify the certificate chain with the edge.
- Troubleshoot Cloudflare Gateway HTTP 526 scenarios: identify untrusted certificates, unknown issuers, revocation checks, expired chain, CN mismatches, and invalid CN characters.
- Use the SSL Server Test tool to verify origin ciphers and ensure you are not enforcing undesired FIPS-only ciphers; when needed, disable FIPS or create a Do Not Inspect policy for this origin.
- Manage redirects from HTTPS to HTTP when required and configure Worker external fetches to use the Custom Origin Trust Store via the cots_on_external_fetch flag.
- Collaborate with server administrators to verify origin certificate validity and coordinate Cloudflare pause if needed for debugging. What We're Looking For
- Strong understanding of SSL/TLS, certificate lifecycle, and Cloudflare security features including SSL/TLS app, Origin CA, and Custom Origin Trust Store.
- Experience troubleshooting origin certificate issues, CN/SAN validation, and certificate chain completion.
- Familiarity with Cloudflare Gateway, WARP considerations, and certificate validation logic. Nice to Have
- Experience with BoringSSL and Chrome validation quirks when scanning certificates.
- Familiarity with managing origin protections and edge to origin trust relationships.