Senior Security Engineer
Cybret
| Company | Cybret |
| Category | Engineering |
| Location | Norway |
| Remote | Remote |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 12 Jan 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
SENIOR SECURITY ENGINEER
CYBRET AI
Remote
Norway and Europe preferred
Full-time
Early hire with equity
ABOUT CYBRET AI
CYBRET AI is building Autonomous Security Infrastructure for modern organizations operating in complex, distributed, cloud-native environments.
Our ambition is to move cybersecurity away from reactive, human-dependent workflows and toward continuous, intelligent, autonomous security. We design systems that combine human judgment where it matters with fully autonomous decision-making where speed, scale, and precision are required.
We make a strict distinction between automation and autonomy.
CYBRET AI does not rely on static rules or predefined playbooks. Our systems understand context, reason over attack surfaces and exposure, assess real-world consequences, and take risk-based decisions. Humans are involved only when escalation is necessary.
Our primary focus is Exposure and Vulnerability Management as a decision system, not a reporting layer.
Instead of listing CVEs or producing noisy scan results, our platform understands real attack surfaces, realistic attack paths, business criticality, identity relationships, trust boundaries, and how modern attackers chain exposures in practice.
CYBRET AI answers questions such as:
• What can actually be exploited right now
• What creates real risk for the organization
• What actions reduce risk most effectively
We are building toward Azure, AWS, and Google Cloud Marketplace launches, with cloud-agnostic design as a core principle.
ABOUT THE ROLE
This is a senior security role with deep technical responsibility and real ownership.
You will help define how exposure, risk, and exploitability are modeled, analyzed, and acted upon inside autonomous security systems. Your work directly shapes how CYBRET AI reasons about security decisions.
You will work across cloud security, identity, network security, detection engineering, and security architecture, closely influencing both product logic and technical direction.
RESPONSIBILITIES
EXPOSURE AND ATTACK SURFACE ANALYSIS
Design and improve how CYBRET AI models attack surfaces across cloud, identity, network, and application layers
Identify real-world attack paths and exploit chains rather than theoretical vulnerabilities
VULNERABILITY AND RISK ENGINEERING
Develop risk scoring and prioritization beyond CVSS
Incorporate exploitability, exposure, identity context, and business impact into decision-making
CLOUD AND IDENTITY SECURITY
Design and evaluate security controls across Azure, AWS, and GCP
Work deeply with identity systems, permissions, service principals, and trust boundaries
Define secure patterns for cloud-native and hybrid environments
DETECTION AND SECURITY LOGIC
Contribute to detection logic, correlation, and multi-signal reasoning
Distinguish noise from real risk to support autonomous decision-making
NETWORK AND ZERO TRUST ARCHITECTURE
Design and assess secure network architectures including private networking, segmentation, and zero-trust principles
Evaluate exposure through public services, APIs, and infrastructure
SECURITY RESEARCH AND THREAT MODELING
Track attacker techniques, emerging threats, and exploitation patterns
Perform threat modeling and security analysis to improve product logic and coverage
HOW WE WORK
CYBRET AI operates fully remote.
The team is currently based in Norway, but we hire internationally.
We recruit based on merit, excellence, and intelligence.
We value deep focus, curiosity, and strong ownership.
You are expected to work independently and make sound decisions in both low-effort, high-impact situations and high-effort, high-impact situations.
A strong shipping mindset is essential. Security work at CYBRET AI must lead to real product improvements, not just analysis.
Interest in security research and state-of-the-art techniques is strongly preferred.
Writing technical blogs or research content is optional but highly valued.
This is an e