Sida 1 av 1
Summary of the Role: As Security Research Lead at Maze, your research directly shapes our products and how our AI understands real risk. This is a unique opportunity to join a well-funded Series A startup building at the intersection of generative AI and cybersecurity, leading the research function that makes our products sharper than anything else on the market — and gives Maze a credible technical voice in the security community. You'll set the bar for our vulnerability research: defining the methodologies that separate critical risk from noise, validating and contextualising the threats our AI surfaces, and feeding that expertise straight into product and engineering to improve how we detect, prioritise, and remediate. You'll work hand-in-hand with our AI/ML, product, and engineering teams — close to the roadmap and the code, not off to one side — turning what you find into capabilities that crush the competition. Alongside that, you'll amplify the work externally: surfacing novel vulnerabilities and building research narratives that earn real reach, giving Maze technical credibility with practitioners and customers. This role is perfect for a security researcher with real depth in cloud and application security who is ready to step up: someone who wants their research to ship as product, can lead a small research team, and can tell a story that lands with a technical audience. The ideal candidate has done this inside another security vendor and wants to build both great products and a research brand from a strong foundation. What you'll work on: * Make Our Products Brilliant: Feed research directly into product and engineering — work close to the roadmap and the codebase to sharpen how we detect, prioritise, and remediate, building capabilities that outclass the competition * Shape How Our AI Understands Risk: Translate deep threat research into the labels, signals, and product feedback that train our models to prioritise vulnerabilities like a seasoned researcher * Lead Our Security Research Function: Set the direction, standards, and methodologies for how Maze researches, validates, and prioritises cloud and application security threats, scaling a small team of researchers as we grow * Find Novel Vulnerabilities That Get Reach: Surface original research and build narratives — blog posts, technical talks, podcasts, video, conference presentations — that earn real reach and give Maze technical credibility with the security community * Build Authoritative Technical Intelligence: Produce detailed research on exploitation techniques, attack vectors, and remediation across cloud infrastructure and application security, enriched with CVE, advisory, and threat-intel sources * Set the Standard for Research Quality: Establish the frameworks and review processes that keep our vulnerability assessment consistent, defensible, and ahead of the threat landscape * Grow the Bench: Mentor and develop researchers, raising the technical bar of the team and creating a research culture others want to join What You Need to Be Successful: * Proven Security Research Depth:** 6+ years in hands-on security research, with a strong track record investigating complex vulnerabilities, building proof-of-concepts, and validating real-world threats * Cloud & Application Security Expertise: Deep knowledge of cloud (AWS) and application security vulnerabilities, attack vectors, and how they actually get exploited at scale * Research That Ships as Product: A track record of turning research into product and engineering outcomes — working closely with eng, product, and ML teams to translate findings into shipped capabilities, not reports that sit on a shelf * A Public Track Record: Demonstrated ability to be the voice of security research externally — published research, conference talks, well-received technical content, or a recognised presence in the community * Vendor-Grade Perspective: Direct experience inside a security tooling or research organisation, with a view on what good research operations look like and how to build credibility in market * Technical Investigation Skills: Strong coding and scripting (Python, Go, or similar) for automating research, building validation tooling, and creating PoCs * Communication That Lands: Ability to translate complex security research for technical practitioners, customers, and internal AI/ML and product teams without losing rigour * Leadership Instinct: Experience leading or mentoring researchers, setting standards, and owning a domain end-to-end in a fast-moving environment * Startup Readiness: Comfortable operating with ambiguity and limited structure, prioritising ruthlessly, and building the function as you run it * Nice to haves: * Experience with AI/ML security or working with AI-generated security findings * An established personal brand or following in the security research community * Open-source contributions to security tools or research * Experience setting up or scaling a research/labeling operation * Industry certifications (OSCP, AWS Security, CISSP, etc.) Why Join Us: * Ambitious Challenge: We're using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud and application security. You'll define how AI understands and prioritises vulnerabilities — and how the market talks about it. * Expert Team: We are a team of hands-on leaders with experience in Big Tech and Scale-ups, who have been part of the leadership teams behind multiple acquisitions and an IPO. * Build Products and a Research Brand: A rare chance to build a security research function from a strong foundation where your research ships as product — directly shaping what we build and how Maze is seen in the security community. * Impactful Work: Cybersecurity is a force for good. Your research will directly improve how thousands of organisations understand and respond to threats, scaling expert security knowledge through AI. * Build an AI-native Company: Join early enough to shape everything from the ground up, with significant equity upside and the room to grow into senior security leadership.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. Why we're hiring: The Senior Security Incident Responder is a lead technical authority for incident response execution, responsible for handling the most complex, high-impact, and business-critical security incidents across WPP. The role does not have line management responsibility; people management remains with the Security Incident Management Lead. What you'll be doing: * Advanced Incident Detection, Analysis & Response. * Lead investigations for high-severity and complex security incidents. * Perform deep technical analysis using SIEM, SOAR, EDR/XDR, identity, email, and cloud telemetry. * Execute and oversee containment, eradication, and recovery actions. * Serve as the primary escalation point for complex incidents. * Coordinate with Legal, Privacy, Risk, Technology Operations, and agency teams. * Provide clear technical updates to senior stakeholders. * Lead forensic evidence collection, preservation, and analysis. * Ensure documentation and artefacts are audit-ready. * Support external forensic or law-enforcement engagement when required. * Quality Assurance, Playbook Maturity & Continuous Improvement * Improve incident response playbooks and SOPs. * Lead or support post-incident reviews and ensure actions are tracked. * Mentor Security Incident Responders without line management responsibility. * Partner with Detection Engineering, Threat Intelligence, Automation, and VM teams. * Identify opportunities for automation and response optimisation. What you'll need: * Extensive hands-on experience responding to enterprise-scale security incidents. * Deep technical expertise across SIEM, SOAR, EDR/XDR, identity, email, and cloud platforms. * Strong forensic, investigation, and root cause analysis skills. * Ability to operate calmly under pressure and communicate clearly. * Experience acting as incident commander or senior escalation point. * Familiarity with MITRE ATT&CK and threat-led response. * Relevant certifications (GCIH, GCFA, GCED, CISSP). * Fluent in written and spoken English Who you are: You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Build the Future of Technology with Professional Galaxy AB Join a network of talented engineers, developers, cloud specialists, and AI innovators working on impactful projects across Sweden and Europe. At Professional Galaxy AB, we connect top tech talent with organizations driving digital transformation in areas like cloud computing, software engineering, data, cybersecurity, and artificial intelligence. Explore exciting opportunities and grow your career while working with cutting-edge technologies and forward-thinking teams. We are looking for a Cyber Security Advisor Responsibilities: Act as a trusted advisor to management and key stakeholders, ensuring cybersecurity considerations are integrated into decision-making Ensure cybersecurity best practices align with business objectives and delivery goals without hindering operational efficiency Provide cybersecurity expertise during projects and engagements to mitigate risks and enhance security controls Work with cross-functional teams to enhance the organization’s overall cybersecurity resilience Identify, assess, and provide guidance on mitigating cybersecurity risks across business functions Support compliance with relevant cybersecurity laws, regulations, and industry standards Contribute to the development and implementation of security strategies, policies, and frameworks Promote cybersecurity awareness and best practices among employees and stakeholders Qualifications: Typically 10+ years of experience in cybersecurity, information security, IT governance, risk management, or compliance Bachelor’s degree in Computer Science or related field (or equivalent experience) Proven leadership in security governance frameworks, policies, and strategies Experience aligning security and data privacy with business objectives at a strategic level Hands-on experience with enterprise risk management and compliance frameworks (e.g., GDPR, ISO 27001, NIST, PCI DSS) Strong expertise in third-party/vendor risk management Experience in security incident response and crisis management Ability to influence senior leadership and board-level stakeholders Additional qualifications (optional): Strong communication skills and stakeholder management Business understanding with security impact awareness Ability to analyze and mitigate security risks Certifications such as CISSP, CIPM, CISA, ISO/IEC 27001 Lead Auditor Specializations such as AI Governance, Cloud Security, or CIPP/E Uppdragsinformation: Uppdragslängd: 2026-05-04 – 2026-09-30 Placeringsort: Stockholm Svar önskas snarast, dock senast 2026-05-03. How to Apply: Please apply via the Professional Galaxy AB portal with: Your updated CV Your availability to start A motivation statement describing your suitability Please note: Applications via email will not be accepted. All applications must be submitted through the portal. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
SUMMARY OF THE ROLE: As a Security Research Engineer at Maze, you'll be at the forefront of defining what constitutes real security risk in the age of AI-powered vulnerability detection. This is a unique opportunity to join our growing security research team at a well-funded startup building at the intersection of generative AI and cybersecurity, where your security expertise directly shapes how our AI models understand and prioritize cloud security threats. You'll spend the majority of your time as the expert human-in-the-loop, analyzing cloud vulnerability findings from our AI systems, conducting deep research to validate and contextualize threats, and creating the authoritative labels that train our models to distinguish critical risks from noise. Working alongside other security researchers, you'll help scale our labeling operations while providing critical input into product development decisions based on real-world threat patterns you discover. This role is perfect for a security researcher who wants to pioneer the future of AI-assisted threat detection, loves diving deep into cloud security vulnerabilities, and wants to see their security insights amplified through cutting-edge technology while contributing to a growing team. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Scale Expert Data Labeling Operations: Lead high-volume vulnerability labeling and validation work as the authoritative voice on threat severity, reviewing and categorizing cloud security findings from our AI models to create the high-quality training data that powers our platform * Drive Product Development Through Research Insights: Translate patterns and insights from your labeling and research work into actionable product improvements, working directly with engineering and product teams to enhance detection capabilities and user experience * Collaborate with Security Research Team: Work closely with fellow Security Research Engineers to maintain consistency in labeling standards, share research findings, and collectively improve our vulnerability assessment methodologies * Deep Vulnerability Research: Conduct comprehensive research into cloud vulnerabilities affecting EC2 images, Docker containers, and cloud infrastructure, investigating true/false positives, analyzing business impact, and building proof-of-concepts to validate threat scenarios * Enhance AI Model Accuracy: Provide expert feedback through our labeling tools that improves our AI models' understanding of vulnerability context, helping them learn to prioritize threats like a seasoned security researcher * Technical Investigation and Analysis: Create detailed technical writeups about exploitation techniques, attack vectors, and remediation strategies for cloud vulnerabilities, turning complex security research into actionable intelligence * Leverage External Security Intelligence: Integrate insights from CVE databases, security advisory feeds, and threat intelligence sources to enrich vulnerability findings with broader context and emerging threat patterns * Contribute to Thought Leadership: Support our external presence through technical blog posts, security videos/podcasts, and occasional conference presentations, sharing insights from your research WHAT YOU NEED TO BE SUCCESSFUL: * Security Research Expertise: 5+ years of hands-on security experience with proven vulnerability research background, comfortable investigating complex security issues and building proof-of-concepts to validate findings * Cloud Security Mastery: Deep knowledge of AWS security, cloud infrastructure vulnerabilities, container security, and cloud-native attack vectors, with hands-on experience securing cloud environments at scale * Technical Investigation Skills: Strong coding and scripting abilities (Python, Go, or similar) for automating research tasks, building validation tools, and creating proof-of-concept exploits * Analytical Excellence: Proven ability to analyze complex security data, distinguish between critical threats and false positives, and communicate technical findings to both technical and business audiences * Product Mindset: Experience translating security insights into product requirements, with ability to identify patterns across vulnerabilities that inform strategic product decisions * External Intelligence Integration: Experience working with vulnerability databases, security advisory feeds, and threat intelligence sources to contextualize and prioritize security findings * Collaborative Mindset: Strong communication skills and ability to work effectively with security research peers, AI/ML teams, and product stakeholders, translating security domain knowledge into actionable improvements * High-Volume Execution: Comfort with systematic labeling work while maintaining accuracy and attention to detail, balancing speed with quality in fast-paced environments * Nice to haves: * Experience with AI/ML security or working with AI-generated security findings * Background at security tooling companies or building security products * Expertise in specific vulnerability research methodologies and frameworks * Open source contributions to security tools or research projects * Previous content creation experience in security (blogs, talks, research papers) * Industry certifications (CISSP, OSCP, AWS Security, etc.) WHY JOIN US: * Ambitious Challenge: We're using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud security today. You'll be defining how AI understands and prioritizes vulnerabilities, working at the cutting edge of AI-powered threat detection. * Expert Team: We are a team of hands-on leaders with experience in Big Tech and Scale-ups. Our team has been part of the leadership teams behind multiple acquisitions and an IPO. * Growing Security Research Function: Join a collaborative security research team where you'll work alongside other experts, share insights, and collectively shape how our AI platform understands security threats at scale. * Impactful Work: Your security research and labeling work will directly improve how thousands of organizations understand and respond to cloud security threats, scaling expert security knowledge through AI to protect the entire ecosystem. * Product Influence: Your day-to-day research insights will directly influence product strategy and development, giving you a voice in building the next generation of AI-powered security tools. * Pioneer AI-Native Security: Help establish the gold standard for AI-assisted vulnerability research, defining how human security expertise enhances machine learning models in the cybersecurity domain.