B

Beazley Security

Vulnerability Detection Engineer

Full-TimePosted on 9/30/2026
No salary listed
Mid
Remote in USA
Remote

About the job

Requirements
  • Proficiency writing analytical SQL, including joins, aggregations, and regular expression matching, with the ability to reason about query correctness and performance against large datasets.
  • Working proficiency in Python for data manipulation, parsing, tooling, and automation.
  • Proficiency designing and applying agentic AI workflows and AI harnesses to detection research and engineering, including building reusable skills, automating research and validation, and operationalizing detection deployments at scale.
  • Experience with Git, code review, and testing practices in a detection engineering environment.
  • Strong grasp of networking fundamentals, HTTP, TLS, and web application architecture, sufficient to interpret raw service responses and understand how to fingerprint software.
  • Practical understanding of common vulnerabilities and how they are exploited, including authentication bypass, remote code execution, injection flaws, deserialization attacks, and path traversal.
  • Ability to read a vendor advisory or public proof of concept code and independently determine what evidence would confirm a vulnerable instance.
  • Demonstrated ability to work carefully with ambiguous or incomplete data.
Responsibilities
  • Conduct vulnerability research on internet-exposed services and software, working with the Beazley Security Labs research team to determine what a vulnerable instance looks like in collected scan data.
  • Monitor vendor advisories and vulnerability disclosures, and help determine which vulnerabilities warrant detection coverage based on exploitability and exposure across the client base.
  • Analyze proof-of-concept exploits in lab environments to identify the version strings, response behaviors, service fingerprints, and configuration artifacts that distinguish vulnerable systems and services.
  • Author, test, and maintain vulnerability detection logic against Exposure Management scan data, and own detection lifecycles.
  • Develop and maintain scan configurations that collect data detections depend on, including service fingerprinting, targeted protocol probes, and response parsing.
  • Validate new and existing software detections across client asset data, and be accountable for the false positive and false negative rates of the coverage owned.
  • Build and improve internal tooling and automation for vulnerability monitoring, detection authoring, and regression testing.
  • Collaborate on technical write-ups, advisories, and remediation guidance that accompany detections, and contribute to Beazley Security Labs intelligence reporting and published research.
  • Partner with other internal departments to convert frontline intrusion findings into proactive detection coverage within Exposure Management.
  • Apply agentic AI to improve existing processes for analyzing new vulnerabilities reported by the industry.
  • Research how agentic AI can improve existing processes for discovering affected software in the client base, validating vulnerable status, and producing advisory content.
Desired Qualifications
  • Experience writing detection, alerting, or analytic logic against large-scale telemetry or scan data in a data warehouse environment.
  • Experience with data quality work identifying gaps, inconsistencies, or drift in upstream collection.
  • Familiarity with detection and scanning frameworks such as Nuclei or Nmap NSE, and an understanding of how their scanning logic works.
  • Experience collaborating in a code repository and using AI-assisted coding tools.
  • Exposure to vulnerability prioritization frameworks including CISA KEV, EPSS, CVSS, and CWE.
  • Experience building isolated lab environments with Docker or virtual machines to reproduce vulnerable software.
  • Experience with patch diffing, binary analysis, or reverse engineering.
  • Published CVEs, bug bounty findings, or open-source security tooling contributions.

About the company

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Lewisville, Texas

Founded

2016

Get referred to Beazley Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Beazley Security reported 36% more disclosed vulnerabilities in Q2 2026, expanding its threat authority.
  • Demand is rising for pre-breach tools; 2026 launches target supply-chain and credential exposure.
  • Black Hat 2026 visibility and Zurich distribution should widen enterprise and insurer-led sales.

What critics are saying

  • Zurich completed Beazley's £8.1 billion acquisition on October 1, 2026.
  • Integration into Zurich can flatten Beazley Security's brand and slow product velocity.
  • Compromised credentials drove 67% of ransomware intrusions in Q2 2026, exposing clients immediately.

What makes Beazley Security unique

  • Beazley Security pairs cyber insurance, claims handling, and response from one operating model.
  • Its 2026 Exposure Management suite adds agentless third-party and dark-web monitoring.
  • Halcyon retainer unifies incident management, response, and ransomware recovery before crises.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Flexible Work Hours

Remote Work Options

Parental Leave

Performance Bonus

Professional Development Budget

Conference Attendance Budget

Training Programs

401(k) Retirement Plan

401(k) Company Match

Company News

PR Newswire
Jul 28th, 2026
Beazley Security and Halcyon launch cyber resilience retainer combining incident management and ransomware protection

Beazley Security and Halcyon have launched the Cyber Resilience Retainer, combining incident management, incident response, and ransomware resilience in a single offering. The retainer provides comprehensive support before, during, and after cyber incidents, moving beyond traditional incident response contracts that focus primarily on post-attack investigation. The service gives organisations access to cyber breach coaches, digital forensics experts, recovery specialists, and ransomware defence professionals through a single point of contact. Halcyon's contribution includes ransomware identification, containment, prevention of further encryption, and recovery support backed by its Ransomware Operations Centre. The retainer aims to eliminate procurement delays during crises by establishing relationships and response processes beforehand, enabling faster coordination and improved recovery outcomes.

PR Newswire
Jul 14th, 2026
Beazley Security launches third-party risk and dark web monitoring modules for exposure management

Beazley Security has launched two new modules for its Exposure Management platform: Third-Party Risk Monitoring and Dark Web Monitoring. The modules provide continuous visibility into supply chain risks and monitor for compromised credentials. Third-Party Risk Monitoring assesses vendor cybersecurity using an outside-in approach rather than static questionnaires. Each vendor receives a risk score from 0 to 100 based on their security posture and relationship with the client. Dark Web Monitoring scans dark web forums, ransomware leak sites, and underground marketplaces to identify exposed credentials linked to an organisation's domains. The service aims to detect stolen credentials before attackers can exploit them. Both modules integrate with Beazley Security's existing platform and require no agents or direct system access. The company will demonstrate the new capabilities at Black Hat USA in Las Vegas from 4 to 6 August.

PR Newswire
Nov 13th, 2024
Beazley Security Taps Experienced Leader For Professional Services

Mandeep Gosal promoted to Vice President, Global Professional Services. WEST HARTFORD, Conn., Nov. 13, 2024 /PRNewswire/ -- As part of its continued growth and expansion, Beazley Security today announced that Mandeep Gosal has been promoted to Vice President, Global Professional Services to lead the strategy and delivery for all professional services engagements. Mr. Gosal joined Beazley Security in August to the lead services expansion in Europe. He was promoted to drive innovation and growth, while also building effective management systems to scale a growing global organization

Lodestone Security LLC
Feb 22nd, 2024
Beazley expands focus on cyber security services with creation of Beazley Security | Lodestone Security

Combining its in-house Cyber Services team with Lodestone, its wholly owned cyber security firm, Beazley will focus on improving cyber resilience for clients. Beazley, the leading specialty insurer, has today announced the merger of its in house Cyber Services team with its wholly owned cyber security company Lodestone, creating an…