Security Engineer & Researcher in London

Security Engineer & Researcher in London

London Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
Maze

At a Glance

  • Tasks: Lead cloud security research and validate AI-generated vulnerability findings.
  • Company: Join a well-funded startup at the forefront of AI and cybersecurity.
  • Benefits: Competitive salary, collaborative environment, and opportunities for professional growth.
  • Other info: Work with an expert team and influence product development directly.
  • Why this job: Shape the future of AI-assisted threat detection and make a real impact.
  • Qualifications: 5+ years in security research with expertise in cloud vulnerabilities.

The predicted salary is between 60000 - 80000 £ per year.

As a Security Research Engineer at Maze, you'll be at the forefront of defining what constitutes real security risk in the age of AI-powered vulnerability detection. This is a unique opportunity to join our growing security research team at a well-funded startup building at the intersection of generative AI and cybersecurity, where your security expertise directly shapes how our AI models understand and prioritize cloud security threats.

You’ll spend the majority of your time as the expert human-in-the-loop, analyzing cloud vulnerability findings from our AI systems, conducting deep research to validate and contextualize threats, and creating the authoritative labels that train our models to distinguish critical risks from noise. Working alongside other security researchers, you’ll help scale our labeling operations while providing critical input into product development decisions based on real-world threat patterns you discover.

This role is perfect for a security researcher who wants to pioneer the future of AI-assisted threat detection, loves diving deep into cloud security vulnerabilities, and wants to see their security insights amplified through cutting‑edge technology while contributing to a growing team.

Your Contributions to Our Journey:

  • Scale Expert Data Labeling Operations: Lead high-volume vulnerability labeling and validation work as the authoritative voice on threat severity, reviewing and categorizing cloud security findings from our AI models to create the high-quality training data that powers our platform.
  • Drive Product Development Through Research Insights: Translate patterns and insights from your labeling and research work into actionable product improvements, working directly with engineering and product teams to enhance detection capabilities and user experience.
  • Collaborate with Security Research Team: Work closely with fellow Security Research Engineers to maintain consistency in labeling standards, share research findings, and collectively improve our vulnerability assessment methodologies.
  • Deep Vulnerability Research: Conduct comprehensive research into cloud vulnerabilities affecting EC2 images, Docker containers, and cloud infrastructure, investigating true/false positives, analyzing business impact, and building proof-of-concepts to validate threat scenarios.
  • Enhance AI Model Accuracy: Provide expert feedback through our labeling tools that improves our AI models' understanding of vulnerability context, helping them learn to prioritize threats like a seasoned security researcher.
  • Technical Investigation and Analysis: Create detailed technical writeups about exploitation techniques, attack vectors, and remediation strategies for cloud vulnerabilities, turning complex security research into actionable intelligence.
  • Leverage External Security Intelligence: Integrate insights from CVE databases, security advisory feeds, and threat intelligence sources to enrich vulnerability findings with broader context and emerging threat patterns.
  • Contribute to Thought Leadership: Support our external presence through technical blog posts, security videos/podcasts, and occasional conference presentations, sharing insights from your research.

What You Need to Be Successful:

  • Security Research Expertise: 5+ years of hands‑on security experience with proven vulnerability research background, comfortable investigating complex security issues and building proof-of-concepts to validate findings.
  • Cloud Security Mastery: Deep knowledge of AWS security, cloud infrastructure vulnerabilities, container security, and cloud-native attack vectors, with hands‑on experience securing cloud environments at scale.
  • Technical Investigation Skills: Strong coding and scripting abilities (Python, Go, or similar) for automating research tasks, building validation tools, and creating proof-of-concept exploits.
  • Analytical Excellence: Proven ability to analyze complex security data, distinguish between critical threats and false positives, and communicate technical findings to both technical and business audiences.
  • Product Mindset: Experience translating security insights into product requirements, with ability to identify patterns across vulnerabilities that inform strategic product decisions.
  • External Intelligence Integration: Experience working with vulnerability databases, security advisory feeds, and threat intelligence sources to contextualize and prioritize security findings.
  • Collaborative Mindset: Strong communication skills and ability to work effectively with security research peers, AI/ML teams, and product stakeholders, translating security domain knowledge into actionable improvements.
  • High-Volume Execution: Comfort with systematic labeling work while maintaining accuracy and attention to detail, balancing speed with quality in fast-paced environments.

Nice to haves:

  • Experience with AI/ML security or working with AI-generated security findings.
  • Background at security tooling companies or building security products.
  • Expertise in specific vulnerability research methodologies and frameworks.
  • Open source contributions to security tools or research projects.
  • Previous content creation experience in security (blogs, talks, research papers).
  • Industry certifications (CISSP, OSCP, AWS Security, etc.).

Why Join Us:

  • Ambitious Challenge: We’re using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud security today. You’ll be defining how AI understands and prioritizes vulnerabilities, working at the cutting edge of AI-powered threat detection.
  • Expert Team: We are a team of hands‑on leaders with experience in Big Tech and Scale-ups. Our team has been part of the leadership teams behind multiple acquisitions and an IPO.
  • Growing Security Research Function: Join a collaborative security research team where you’ll work alongside other experts, share insights, and collectively shape how our AI platform understands security threats at scale.
  • Impactful Work: Your security research and labeling work will directly improve how thousands of organizations understand and respond to cloud security threats, scaling expert security knowledge through AI to protect the entire ecosystem.
  • Product Influence: Your day-to-day research insights will directly influence product strategy and development, giving you a voice in building the next generation of AI-powered security tools.
  • Pioneer AI-Native Security: Help establish the gold standard for AI-assisted vulnerability research, defining how human security expertise enhances machine learning models in the cybersecurity domain.

Security Engineer & Researcher in London employer: Maze

At Maze, we pride ourselves on being an exceptional employer that fosters a collaborative and innovative work culture, where your contributions as a Security Engineer & Researcher will directly shape the future of AI-powered cybersecurity. With a focus on employee growth, we offer opportunities to work alongside industry experts, influence product development, and engage in impactful research that enhances cloud security for thousands of organisations. Join us in a dynamic startup environment that values your expertise and empowers you to pioneer advancements in AI-assisted threat detection.

Maze

Contact Details:

Maze Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer & Researcher in London

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Maze, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Maze

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Maze. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Security Engineer & Researcher in London

Security Research Expertise
Cloud Security Mastery
Technical Investigation Skills
Analytical Excellence
Product Mindset
External Intelligence Integration
Collaborative Mindset

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Maze insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Maze that you’re committed to staying ahead in the game.

How to prepare for a job interview at Maze

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Maze to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Maze.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.