Live opening · Posted 5 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
About Beazley Security
Beazley Security is a global cybersecurity firm committed to helping clients enable advanced cyber defenses that reduce risk with quantifiable results. We’re comprised of top talent from private industry, government, intelligence, and law enforcement who are specialists in threat detection, incident response, digital forensics, offensive security, risk management, and cyber resilience. As a subsidiary of a specialty insurance giant, Beazley Insurance, we’ve been at the forefront of cyber insurance management and breach response activities for business clients in the US, UK, and Europe since 2017. As Beazley Security, the company will have an expanded scope, leveraging nearly two decades of cyber incident experience, a strong services division, and a business strategy focused on growth, to realize our goals and deliver benefits to clients.
As a company, we are committed to upholding our core values of Belonging, Integrity, Service, Accountability, and Curiosity. We believe these values are essential to creating a strong and inclusive workplace culture, as well as to deliver world-class cybersecurity solutions to our clients worldwide. As Beazley Security, these values will continue to thrive, with an extra emphasis on expansion of our capabilities and capacity in helping solve unique client challenges.
About Beazley Security Labs
Beazley Security Labs (BSL) is responsible for transforming real-world threat activity into actionable intelligence that directly improves client security outcomes and strengthens Beazley Security’s products and services. The team conducts in-depth cybersecurity research, derives insight from incident response engagements and MDR findings, and proactively identifies emerging threats and vulnerabilities to deliver timely security advisories and detection logic for our Exposure Management platform.
Beazley Security Labs also provides operational threat intelligence that supports Managed Detection and Response and Incident Response teams through threat hunts and threat actor profiling, while also producing original research, quarterly threat reports, and industry content that builds Beazley Security’s credibility and brand. With the ultimate goal of making adversaries less effective, Labs serves as a critical bridge between frontline incidents, product innovation, and thought leadership.
About The Role
The window between vulnerability disclosure and mass exploitation keeps getting shorter. As a Vulnerability Detection Engineer on Beazley Security Labs, your job is to close that window for our clients. When a critical vulnerability drops, you figure out how to reliably identify it from the internet, build a detection for it, prove it works, and ship it to our Exposure Management platform so clients know whether they are exposed before an attacker does. This work rewards a certain curiosity about how software breaks, and the patience to keep asking how to identify vulnerable systems from the internet.
You will work as part of the Beazley Security Labs research team to identify and analyze emerging threats and critical vulnerabilities, and to own the delivery of detection logic that surfaces that exposure in client environments. The role combines vulnerability analysis, exploit research, and threat intelligence with the engineering work required to turn research findings into real world detections. You will use agentic workflows as part of that process, building skills and automation that accelerate research, validation, and detection development. The role also contributes to Beazley Security Labs research supporting security operations, incident response, and client advisories.
Key Responsibilities
Conduct vulnerability research on internet exposed services and software, working with the BSL research team to determine what a vulnerable instance looks like in collected scan data
Monitor vendor advisories, vulnerability disclosures, and help determine which vulnerabilities warrant detection coverage based on exploitability and exposure across our client base
Analyze proof of concept exploits in lab environments to identify the version strings, response behaviors, service fingerprints, and configuration artifacts that distinguish vulnerable systems and services
Author, test, and maintain vulnerability detection logic against Exposure Management scan data, and own detection lifecycles
Develop and maintain scan configurations that collect the data detections depend on, including service fingerprinting, targeted protocol probes, and response parsing
Validate new and existing software detections across client asset data, and be accountable for the false positive and false negative rates of the coverage you own
Build and improve internal tooling and automation for vulnerability monitoring, detection authoring, and regression testing
Collaborate on technical write ups, advisories, and remediation guidance that accompany your detections, and contribute to Beazley Security Labs intelligence reporting and published research
Partner with other internal departments to convert frontline intrusion findings into proactive detection coverage within Exposure Management
Apply where Agentic AI can be leveraged to improve our existing processes analyzing new vulnerabilities reported by the industry.
Research where Agentic AI can be leveraged to improve our existing processes of discovering affected software in our client base, validating vulnerable status, and producing advisory content.
Required Qualifications:
Proficiency writing analytical SQL, including joins, aggregations, and regular expression matching, with the ability to reason about query correctness and performance against large datasets
Working proficiency in Python for data manipulation, parsing, tooling, and automation
Proficiency designing and applying agentic AI workflows and AI harnesses to detection research and engineering, including building reusable skills, automating research and validation, and operationalizing detection deployments at scale
Experience with Git, code review, and testing practices in a detection engineering environment
Strong grasp of networking fundamentals, HTTP, TLS, and web application architecture, sufficient to interpret raw service responses and understand how to fingerprint software
Practical understanding of common vulnerabilities and how they are exploited, including authentication bypass, remote code execution, injection flaws, deserialization attacks, and path traversal
Ability to read a vendor advisory or public proof of concept code and independently determine what evidence would confirm a vulnerable instance
Demonstrated ability to work carefully with ambiguous or incomplete data
Preferred Qualifications
Experience writing detection, alerting, or analytic logic against large-scale telemetry or scan data in a data warehouse environment
Experience with data quality work identifying gaps, inconsistencies, or drift in upstream collection
Familiarity with detection and scanning frameworks such as Nuclei or Nmap NSE, and an understanding of how their scanning logic works
Experience collaborating in a code repository and using AI assisted coding tools
Exposure to vulnerability prioritization frameworks including CISA KEV, EPSS, CVSS, and CWE
Experience building isolated lab environments with Docker or virtual machines to reproduce vulnerable software
Experience with patch diffing, binary analysis, or reverse engineering
Published CVEs, bug bounty findings, open-source security tooling contributions
Beazley Security Offers
Competitive salary and bonus.
Flexible working arrangements.
Generous leave policies including 3 months paid parental.
100% of employee-only insurance premiums covered (healthcare, dental and vision).
Up to 5% matched 401k contribution.
Opportunities for career advancement and ongoing training.
Participation in industry conferences and events.
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.