Security Research Engineer, Attack Surface & Risk Signals
Jobleads-US
About CyberCube:
CyberCube delivers the world's leading analytics to quantify digital risk , helping the largest global carriers, reinsurers and brokers understand, price and manage cyber risk in financial terms.
- AI at our foundation, cyber risk at our core. We don't just use AI, we shape it.
- Built on AI from day one. Artificial intelligence has been part of our strategy since the beginning, blended with deep cybersecurity and insurance expertise and backed by rigorous testing.
- Trusted by more than 100 clients, including 75% of the top 40 European and US cyber insurance carriers and 70% of the top ten reinsurance brokers.
- Backed for global growth. In 2025 Spectrum Equity joined some of CyberCube’s financial partners as a new cornerstone investor, accelerating our global growth and fueling innovation across our end-to-end cyber risk analytics for the insurance industry.
- A truly global team across San Francisco, New York, London, and Tallinn.
- collaboration, openness, intellectual rigor, and ownership for excellence.
- People at the forefront. We encourage CyberCubers to challenge themselves, push boundaries, and do the best work of their careers.
Quantitative Cyber Risk Engineer
About the Role Are you fascinated by the underlying architecture of the internet? Do you look at complex network configurations and immediately see the quantitative risk exposure?
As a Quantitative Cyber Risk Engineer , you will play a critical role at the intersection of network engineering, cybersecurity, and data science. We are looking for an expert who deeply understands how the internet is wired—down to the protocol level—and possesses the quantitative prowess to translate that knowledge into computable risk metrics.
In this role, you will analyze how global businesses configure their internet-facing assets and design mathematical signals that accurately quantify their exposure to cyber attacks. Working alongside Data Scientists, Engineers, and Product teams, your research and models will directly drive the next generation of risk-scoring and analytical engines for the cyber insurance industry.
If you are passionate about turning theoretical network vulnerabilities into actionable, real‑world risk signals that influence a global industry, this is the role for you.
Key Responsibilities
- Design Risk Signals: Develop innovative, quantitative signals that accurately measure a company’s exposure to cyber attacks based on their network architecture, asset configurations, and internet footprint.
- Quantify the Unquantifiable: Translate theoretical cybersecurity concepts and complex network topologies into empirical, actionable risk metrics and assumptions.
- Architectural Deep-Dives: Evaluate and extract meaningful insights from how organizations deploy and configure internet-facing protocols, cloud infrastructure, and enterprise networks.
- Threat Landscape Research: Conduct in-depth research on emerging cyber threats (e.g., critical vulnerabilities, ransomware, trending exploits, data breach techniques) and map them to underlying asset configurations.
- Cross-Functional Collaboration: Serve as the subject matter expert on internet architecture, working closely with product, analytics, and engineering teams to integrate your risk signals into production models.
Must-Have Skills & Qualifications
- Deep Internet & Networking Expertise: Expert-level understanding of how the internet works at a foundational level. You should be intimately familiar with network protocols (TCP/IP, BGP, DNS, TLS), routing, ASN ecosystems, and complex enterprise network configurations.
- Strong Quantitative Acumen: Proven ability to apply mathematical and statistical concepts to real-world problems. You must be able to design quantitative metrics and build logic that scores and sizes risk exposure accurately.
- Analytical Mindset: Exceptional problem-solving skills with a track record of conceptualizing complex, abstract security concepts and breaking them down into measurable data points.
- Educational Background: Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Mathematics, Statistics, or a related highly quantitative/technical field.
- Experience: 3-5+ years of relevant work experience in network engineering, cyber threat research, risk modeling, or a related domain.
Good-to-Have (Preferred) Skills
- Coding for Signal Creation: Proficiency in Python or R to prototype algorithms and turn your theoretical risk concepts into actual programmatic outputs.
- Data Querying: Experience with SQL and relational databases to pull, manipulate, and analyze large datasets of asset and configuration data.
- Big Data Exposure: Familiarity with big data frameworks (Spark / Hadoop), flat files, complex data types (JSON, XML), and working with APIs.
- Industry Context: Experience working in or adjacent to the cyber insurance, risk modeling, or data science industries.
- Certifications: Advanced technical or security certifications (e.g., CISSP, CISM, or advanced Cisco/networking certifications) are a plus, but hands‑on expertise matters most.
Who might thrive here
This role is a fit for people from many backgrounds. You might be a Security Researcher, Threat Researcher, Penetration Tester or Offensive Security Engineer who knows how attackers find and exploit exposed assets. Or you might come from network engineering, detection engineering, or attack surface management and know exactly how internet-facing infrastructure gets set up and misconfigured. If you've done bug bounty or red team work, or built security data and risk models, and you want to turn that experience into signals that shape a global industry, we'd love to hear from you.
AI is reshaping how work gets done across every function. We value people who are curious about AI, eager to learn, and thoughtful about applying AI tools to work more effectively. AI fluency is part of how we assess every role in our hiring process.
Research shows the best candidates rarely match a job description point for point. If you're excited about this role and believe you could make an impact, we'd love to hear from you, even if your experience doesn't line up perfectly with everything listed above.
CyberCube Analytics, Inc. and CyberCube Analytics Europe Limited is an equal opportunity employer. We don’t tolerate discrimination against age, gender, gender identity, gender expression, sexual orientation, race, color, nationality, ethnicity, religion, disability, veteran status, protected genetic information or political affiliation.
#J-18808-Ljbffr Jobleads-US- ...CyberCube Analytics, Inc. in San Francisco is seeking a Quantitative Cyber Risk Engineer to bridge network engineering, cybersecurity, and data science. You will design signals measuring exposure and work with product, analytics, and engineering teams to integrate risk...Risk
- ...CyberCube is seeking a Quantitative Cyber Risk Engineer to translate internet engineering and cyber risk concepts into measurable signals. You will work with data scientists, engineers, and product teams to quantify exposure and inform risk models for the cyber insurance...Risk
$266k - $385k
...of humanity.The Security team protects OpenAI... ...products and research at OpenAI. Our... ...RoleAs a Security Engineer on Detection &... ...emphasis on high-signal detection and reliable... ...failure and attack modes (workloads... ...and datacenter risks, such as firmware/BMC surfaces, network...RiskWork at officeLocal areaFlexible hours$100k - $200k
...About the job Security Engineer Location: San Francisco... ..., detection, and attack-surface management are... ...reviews, vulnerability research, authentication and authorization... ...to prioritize the risks that matter in a fast... ...considered strong signals: Bug bounty work,...RiskFull timeImmediate startVisa sponsorshipRelocation package$231k - $318k
...About this role:Our Engineering organization owns... ...software that is secure, tested, easy to maintain... ...the controls and signals that back it, and... ...systemic causes surface instead of... ...Abuse, where every attack vector has a named... ...view of residual risk, and force the outstanding...RiskPermanent employmentWork experience placementWork at officeLocal areaRemote workMonday to FridayFlexible hoursShift work3 days per week$149k - $235k
...looking for a Senior Cloud Security Engineer II to join our Security... ...forums, translating complex attack paths and risk into clear, actionable guidance... ...assess posture, surface systemic and emerging risk... ...detection strategy: design high-signal detections and SIEM rules...RiskWork at officeLocal areaFlexible hours$227k - $296k
...OPPORTUNITY Apollo Research works with most... ...Our coding agent security product, Watcher,... ...per month across engineering teams at agent-... ...that buyer signal into the AI Security... ...securely and the attack surface Watcher itself introduces... ...significant risks. At Apollo...RiskFull timeWork at officeWork from homeVisa sponsorshipRelocation packageFlexible hours$10k
...Group runs one unified security program across Tinder,... ...owns the corporate attack surface: who gets access to what... ...privileges and secure high-risk administrative actions... ...efforts—device signals from endpoint posture... ...accelerate delivery by engineering automated solutions—using...RiskWork experience placementWorldwide3 days per week$10 per hour
...environment? Come join us.All security disciplines work under... ...that hundreds of engineers around the world rely on... ...takeover, MFA fatigue attacks, and session token theft... ...postureReduce SaaS risk at scale through SSPM tooling... ...integrations to that surface.Automation &...RiskWork at officeImmediate startRelocationRelocation packageFlexible hours$183k - $247.6k
....We are a specialized security team that sits inside... ...that measurably reduce risk.We work shoulder to shoulder... ...early and ambiguous signals into a validated... ...across the organization to surface architectural defects,... ...hunting, detection engineering, or product/application...RiskPermanent employmentLocal areaImmediate startFlexible hoursShift work- ...London, and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team... ...regulatory expectations. GRC Engineering is how we make all of that... ...and risk data into real-time signals for the team and leadership... ...is continuous and gaps surface the moment they appear, not...RiskWork experience placementWork at officeLocal areaShift work
- ...move quickly from signal to action, and enjoys... ...closely with Engineering, IT, Legal, and Business... ...leaders to reduce risk, respond to... ...continuously raise the security bar across the... ...understanding of attacker techniques and defensive... ..., and network surfaces. • Hands-on experience...Risk
$150k - $240k
...diverse, world-class team—engineers, designers, researchers, and product minds—... ...The RoleAs an Offensive Security Engineer within HP IQ’s Product... ...validate, and mitigate security risks across the product... ...and continuously assess attack surfaces to guide and enhance secure...RiskFull timeTemporary workLocal areaFlexible hours$230k - $390k
...teams for Google Workspace.Security EngineerSecurity Engineering builds the foundations... ...our platform to identify risk, strengthen architectures,... ...discovery, or instrumenting high-signal detection and response.... ...systems.You think like an attacker — you naturally ask “what...RiskFull timeFlexible hours- ...San Francisco is seeking an Offensive Security Engineer to partner with engineering teams to identify... ..., validate, and mitigate security risks across the product lifecycle. You will... ...workflows, and continuously assess attack surfaces to guide secure development. This role...Risk
$117.2k - $176.7k
...Salesforce.Job Title: Product Security Engineer, InfrastructureJob Category:... ...vulnerabilities and develop risk mitigation plans throughout the... ..., and by analyzing risk signals and emerging threats to shape... ...reason through abuse cases and attack paths, not just defensive recommendations...RiskFull time$175k - $200k
...building the future of social engineering defense. Our AI-native... ...detect and dismantle attacker infrastructure while... .... By unifying Digital Risk Protection, Human Risk Management and Email Security, Doppel connects threats... ...turns every customer signal into shared intelligence...RiskWork at officeImmediate startRemote work- ...Security Engineer Town holds the keys to a person's entire working life.... ...Security Engineer to own that surface end to end. You'll set the... ...Slack, CRM) against real-world attack. Build the secure... ...instinctively and can explain risk to engineers and founders without...RiskWork at office
- ...next-generation Cloud Security Platform that... ...prioritize critical risks, providing precise insights... ...looking for a Security Engineer to join our MDR team... ...closely with analysts, researchers, and engineers — with... ...risks, exposed attack surfaces, and recommend improvements...RiskNight shiftWeekend work
- ...roleRippling is looking for a Principal Security Engineer to tackle some of the most complex,... ...as well as AuthN/Z to manage product attack surface, 0-day blast radius, and limit lateral... ...business leaders understand and navigate risk tradeoffs to ensure Rippling is making...RiskWork at office3 days per week
- ...responsible for:The Circle Security Team works to protect... ...highest-stakes threat surfaces: our blockchain and... ...exposure to insider risk.What you'll work on:Proactively... ..., and protocol-level attackers targeting USDC and... ...response, or security engineering.3+ years of experience...RiskContract workWork experience placementFlexible hoursShift workNight shift
$165k - $200k
...Senior Security Engineer Our mission is to make the world... ...to accelerate cancer research, improving construction... ...giving both us and attackers increasing leverage.... ...internal and external surfaces. Red Team: Proactively... ...complex security risks into actionable...RiskRemote workWork from homeHome officeRelocation package$218.4k - $365.2k
...a transformative security leader who can evolve... ...of Security Engineering, you will lead a... ...LLMs to correlate signals across Slack's infrastructure... ...AI supply chain risks* Track record... ...extend the attack surface beyond your direct... ..., published researcher, or contributor to...RiskShift work- ...infrastructure where security isn't a layer we add later... ...tooling expands what engineers can build and how fast... ...can build it, the attack surface grows with it. Someone... ...presence in the security research community — running... ...ve translated security risk into product decisions...RiskFull timeFor contractorsInternshipRelocation package
- ...growing group of committed researchers, engineers, policy experts, and... ...intelligence for Security Engineering... ...infrastructure, and attacker tooling to extract indicators... ...TTPs, and attribution signals - Partner with Detection... ...to threat models and risk assessments that...RiskFull time
$139k - $204k
...hunt adversaries before they surface, and build the capabilities that... ...of boom Work alongside security partners who hold a high bar and... ...what's burning and a strategy to attack it before you can see the fire... ...technical situations into risk and decision frameworks that drive...RiskPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$231.9k - $318.25k
...build with more AI tools, the risk of shipping ungoverned... ...execute arbitrary code. The security surface that comes with that is large... ...for an Application Security Engineer who combines deep security fundamentals... ...~ A pragmatic, signal‑oriented relationship with AI...RiskShift work$221k - $299k
...Maven Clinic is looking for a Staff Security Engineer to lead Incident Detection and Response... ...engineering. You will also manage security risk as new AI-driven capabilities expand... ...models for codebases, including attack surface, trust boundaries, and data flow to anticipate...RiskWork at officeImmediate startRemote workFlexible hours3 days per week$220k - $250k
...AI) and trillions of consumer signals to make it easier for... ...re seeking a Lead Application Security Engineer to help advance Zeta Global’s... ...controls, and data-informed risk prioritization to ensure our... ...vulnerability intelligence, and attack-pattern analysis.Identify and...Risk$188.75k - $242.68k
...London, and Amsterdam.The Platform Security team (PlatSec) defends Plaid against attackers. We own laptop security, cloud... .... AI has expanded Plaid's attack surface faster than most security teams can... ...AI technologies to find security risks before they ship, then design and...RiskWork experience placementWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Research Engineer, Attack Surface & Risk Signals. Be the first to apply!
- application security engineer San Francisco, CA
- principal security engineer San Francisco, CA
- senior cloud security engineer San Francisco, CA
- cloud security engineer San Francisco, CA
- aws cloud security engineer San Francisco, CA
- security software engineer San Francisco, CA
- sr information security engineer San Francisco, CA
- physical security engineer San Francisco, CA
- network security engineer San Francisco, CA
- dlp security engineer San Francisco, CA



