Skip to content

Open nowPosted 13 hours ago

Security Research Engineer, Attack Surface & Risk Signals

CyberCube8 open roles

Pay
$140,000 – $160,000 a year
Where
San Francisco Office
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Research Engineer, Attack Surface & Risk SignalsCyberCube · San Francisco Office
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on CyberCube's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 13 hours ago

The posting

About CyberCube: https://www.cybcube.com/careers

CyberCube delivers the world's leading analytics to quantify digital risk, helping the largest global carriers, reinsurers and brokers understand, price and manage cyber risk in financial terms.

- AI at our foundation, cyber risk at our core. We don't just use AI, we shape it.

- Built on AI from day one. Artificial intelligence has been part of our strategy since the beginning, blended with deep cybersecurity and insurance expertise and backed by rigorous testing.

- Trusted by more than 100 clients, including 75% of the top 40 European and US cyber insurance carriers and 70% of the top ten reinsurance brokers.

- Backed for global growth. In 2025 Spectrum Equity joined some of CyberCube’s financial partners as a new cornerstone investor, accelerating our global growth and fueling innovation across our end-to-end cyber risk analytics for the insurance industry.

- A truly global team across San Francisco, New York, London, and Tallinn.

- A culture of collaboration, openness, intellectual rigor, and ownership for excellence.

- People at the forefront. We encourage CyberCubers to challenge themselves, push boundaries, and do the best work of their careers.

QUANTITATIVE CYBER RISK ENGINEER

About the Role Are you fascinated by the underlying architecture of the internet? Do you look at complex network configurations and immediately see the quantitative risk exposure?

As a Quantitative Cyber Risk Engineer, you will play a critical role at the intersection of network engineering, cybersecurity, and data science. We are looking for an expert who deeply understands how the internet is wired—down to the protocol level—and possesses the quantitative prowess to translate that knowledge into computable risk metrics.

In this role, you will analyze how global businesses configure their internet-facing assets and design mathematical signals that accurately quantify their exposure to cyber attacks. Working alongside Data Scientists, Engineers, and Product teams, your research and models will directly drive the next generation of risk-scoring and analytical engines for the cyber insurance industry.

If you are passionate about turning theoretical network vulnerabilities into actionable, real-world risk signals that influence a global industry, this is the role for you.

KEY RESPONSIBILITIES

- Design Risk Signals: Develop innovative, quantitative signals that accurately measure a company’s exposure to cyber attacks based on their network architecture, asset configurations, and internet footprint.

- Quantify the Unquantifiable: Translate theoretical cybersecurity concepts and complex network topologies into empirical, actionable risk metrics and assumptions.

- Architectural Deep-Dives: Evaluate and extract meaningful insights from how organizations deploy and configure internet-facing protocols, cloud infrastructure, and enterprise networks.

- Threat Landscape Research: Conduct in-depth research on emerging cyber threats (e.g., critical vulnerabilities, ransomware, trending exploits, data breach techniques) and map them to underlying asset configurations.

- Cross-Functional Collaboration: Serve as the subject matter expert on internet architecture, working closely with product, analytics, and engineering teams to integrate your risk signals into production models.

MUST-HAVE SKILLS & QUALIFICATIONS

- Deep Internet & Networking Expertise: Expert-level understanding of how the internet works at a foundational level. You should be intimately familiar with network protocols (TCP/IP, BGP, DNS, HTTP/S, TLS), routing, ASN ecosystems, and complex enterprise network configurations.

- Strong Quantitative Acumen: Proven ability to apply mathematical and statistical concepts to real-world problems. You must be able to design quantitative metrics and build logic that scores and sizes risk exposure accurately.

- Analytical Mindset: Exceptional problem-solving skills with a track record of conceptualizing complex, abstract security concepts and breaking them down into measurable data points.

- Educational Background: Bachelor’s or Master’s degree in Computer Science, Computer Engineering, Mathematics, Statistics, or a related highly quantitative/technical field.

- Experience: 3–5+ years of relevant work experience in network engineering, cyber threat research, risk modeling, or a related domain.

GOOD-TO-HAVE (PREFERRED) SKILLS

- Coding for Signal Creation: Proficiency in Python or R to prototype algorithms and turn your theoretical risk concepts into actual programmatic outputs.

- Data Querying: Experience with SQL and relational databases to pull, manipulate, and analyze large datasets of asset and configuration data.

- Big Data Exposure: Familiarity with big data frameworks (Spark / Hadoop), flat files, complex data types (JSON, XML), and working with APIs.

- Industry Context: Experience working in or adjacent to the cyber insurance, risk modeling, or data science industries.

- Certifications: Advanced technical or security certifications (e.g., CISSP, CISM, or advanced Cisco/networking certifications) are a plus, but hands-on expertise matters most.

Who might thrive here This role is a fit for people from many backgrounds. You might be a Security Researcher, Threat Researcher, Penetration Tester or Offensive Security Engineer who knows how attackers find and exploit exposed assets. Or you might come from network engineering, detection engineering, or attack surface management and know exactly how internet-facing infrastructure gets set up and misconfigured. If you've done bug bounty or red team work, or built security data and risk models, and you want to turn that experience into signals that shape a global industry, we'd love to hear from you.

AI Fluency at CyberCube

AI is reshaping how work gets done across every function. We value people who are curious about AI, eager to learn, and thoughtful about applying AI tools to work more effectively. AI fluency is part of how we assess every role in our hiring process.

Don't tick every box? Apply anyway.

Research shows the best candidates rarely match a job description point for point. If you're excited about this role and believe you could make an impact, we'd love to hear from you, even if your experience doesn't line up perfectly with everything listed above.

CyberCube Analytics, Inc. and CyberCube Analytics Europe Limited is an equal opportunity employer. We don’t tolerate discrimination against age, gender, gender identity, gender expression, sexual orientation, race, color, nationality, ethnicity, religion, disability, veteran status, protected genetic information or political affiliation.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against CyberCube's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on CyberCube's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    CyberCube's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.