Beazley Security

Vulnerability Detection Engineer

About Beazley Security:

Beazley Security is a global cybersecurity firm committed to helping clients enable advanced cyber defenses that reduce risk with quantifiable results. We’re comprised of top talent from private industry, government, intelligence, and law enforcement who are specialists in threat detection, incident response, digital forensics, offensive security, risk management, and cyber resilience. As a subsidiary of a specialty insurance giant, Beazley Insurance, we’ve been at the forefront of cyber insurance management and breach response activities for business clients in the US, UK, and Europe since 2017. As Beazley Security, the company will have an expanded scope, leveraging nearly two decades of cyber incident experience, a strong services division, and a business strategy focused on growth, to realize our goals and deliver benefits to clients. 


As a company, we are committed to upholding our core values of Belonging, Integrity, Service, Accountability, and Curiosity. We believe these values are essential to creating a strong and inclusive workplace culture, as well as to deliver world-class cybersecurity solutions to our clients worldwide. As Beazley Security, these values will continue to thrive, with an extra emphasis on expansion of our capabilities and capacity in helping solve unique client challenges.


About Beazley Security Labs:

Beazley Security Labs (BSL) is responsible for transforming real-world threat activity into actionable intelligence that directly improves client security outcomes and strengthens Beazley Security’s products and services. The team conducts in-depth cybersecurity research, derives insight from incident response engagements and MDR findings, and proactively identifies emerging threats and vulnerabilities to deliver timely security advisories and detection logic for our Exposure Management platform.


Beazley Security Labs also provides operational threat intelligence that supports Managed Detection and Response and Incident Response teams through threat hunts and threat actor profiling, while also producing original research, quarterly threat reports, and industry content that builds Beazley Security’s credibility and brand. With the ultimate goal of making adversaries less effective, Labs serves as a critical bridge between frontline incidents, product innovation, and thought leadership.


About the Role:

The window between vulnerability disclosure and mass exploitation keeps getting shorter. As a Vulnerability Detection Engineer on Beazley Security Labs, your job is to close that window for our clients. When a critical vulnerability drops, you figure out how to reliably identify it from the internet, build a detection for it, prove it works, and ship it to our Exposure Management platform so clients know whether they are exposed before an attacker does. This work rewards a certain curiosity about how software breaks, and the patience to keep asking how to identify vulnerable systems from the internet.

You will work as part of the Beazley Security Labs research team to identify and analyze emerging threats and critical vulnerabilities, and to own the delivery of detection logic that surfaces that exposure in client environments. The role combines vulnerability analysis, exploit research, and threat intelligence with the engineering work required to turn research findings into real world detections. You will use agentic workflows as part of that process, building skills and automation that accelerate research, validation, and detection development. The role also contributes to Beazley Security Labs research supporting security operations, incident response, and client advisories.

Key Responsibilities:

  • Conduct vulnerability research on internet exposed services and software, working with the BSL research team to determine what a vulnerable instance looks like in collected scan data
  • Monitor vendor advisories, vulnerability disclosures, and help determine which vulnerabilities warrant detection coverage based on exploitability and exposure across our client base
  • Analyze proof of concept exploits in lab environments to identify the version strings, response behaviors, service fingerprints, and configuration artifacts that distinguish vulnerable systems and services
  • Author, test, and maintain vulnerability detection logic against Exposure Management scan data, and own detection lifecycles
  • Develop and maintain scan configurations that collect the data detections depend on, including service fingerprinting, targeted protocol probes, and response parsing
  • Validate new and existing software detections across client asset data, and be accountable for the false positive and false negative rates of the coverage you own
  • Build and improve internal tooling and automation for vulnerability monitoring, detection authoring, and regression testing
  • Collaborate on technical write ups, advisories, and remediation guidance that accompany your detections, and contribute to Beazley Security Labs intelligence reporting and published research
  • Partner with other internal departments to convert frontline intrusion findings into proactive detection coverage within Exposure Management
  • Apply where Agentic AI can be leveraged to improve our existing processes analyzing new vulnerabilities reported by the industry.
  • Research where Agentic AI can be leveraged to improve our existing processes of discovering affected software in our client base, validating vulnerable status, and producing advisory content.

Required Qualifications: 

  • Proficiency writing analytical SQL, including joins, aggregations, and regular expression matching, with the ability to reason about query correctness and performance against large datasets
  • Working proficiency in Python for data manipulation, parsing, tooling, and automation
  • Proficiency designing and applying agentic AI workflows and AI harnesses to detection research and engineering, including building reusable skills, automating research and validation, and operationalizing detection deployments at scale
  • Experience with Git, code review, and testing practices in a detection engineering environment
  • Strong grasp of networking fundamentals, HTTP, TLS, and web application architecture, sufficient to interpret raw service responses and understand how to fingerprint software
  • Practical understanding of common vulnerabilities and how they are exploited, including authentication bypass, remote code execution, injection flaws, deserialization attacks, and path traversal
  • Ability to read a vendor advisory or public proof of concept code and independently determine what evidence would confirm a vulnerable instance
  • Demonstrated ability to work carefully with ambiguous or incomplete data

Preferred Qualifications

  • Experience writing detection, alerting, or analytic logic against large-scale telemetry or scan data in a data warehouse environment
  • Experience with data quality work identifying gaps, inconsistencies, or drift in upstream collection
  • Familiarity with detection and scanning frameworks such as Nuclei or Nmap NSE, and an understanding of how their scanning logic works
  • Experience collaborating in a code repository and using AI assisted coding tools
  • Exposure to vulnerability prioritization frameworks including CISA KEV, EPSS, CVSS, and CWE
  • Experience building isolated lab environments with Docker or virtual machines to reproduce vulnerable software
  • Experience with patch diffing, binary analysis, or reverse engineering
  • Published CVEs, bug bounty findings, open-source security tooling contributions

Beazley Security Offers:

  • Competitive salary and bonus. 
  • Flexible working arrangements. 
  • Generous leave policies including 3 months paid parental.
  • 100% of employee-only insurance premiums covered (healthcare, dental and vision).
  • Up to 5% matched 401k contribution.
  • Opportunities for career advancement and ongoing training.
  • Participation in industry conferences and events. 

Research

Remote (United States)

Partilhar em:

Termos de serviço.PrivacidadeCookiesDesenvolvido pela Rippling