Beazley Security is building a new managed service through its MDR Operations Team, focused on visibility, control, and response for agent activity across client endpoints and servers. As the first Agentic Security Engineer, you will help design, deploy, and continuously improve the agentic runtime platform and policy enforcement that power Managed AI Detection and Response. This role blends platform engineering, detection and routing automation, and analyst enablement, with direct reporting to the Director of MDR Operations.
Role Overview
Reporting to the Director of MDR Operations, you will develop and operate the core systems that enforce AI security policies under an “allow, ask, and deny” model. You will also support how findings and escalations move to analysts, how enforcement actions are controlled to avoid business disruption, and how service coverage evolves as clients adopt new AI capabilities.
Responsibilities
- Deploy, configure, and maintain the AI security platforms behind the Managed AI Detection and Response solution, including rolling out tooling via MDM or EDR and setting initial enforcement policies.
- Manage platform agent endpoint enforcement actions, including software removal and removal of integrations such as MCP server, shell, and database, using per-client pre-authorization and exclusion lists to prevent removal of business-critical tooling.
- Monitor platform health, coverage, webhook delivery, and enforcement-action lifecycle state to identify gaps in visibility or delivery before they impact detection or reporting.
- Translate client AI acceptable use policies, data handling requirements, and risk appetite into enforceable platform configurations using the “allow, ask, and deny” enforcement model.
- Build and maintain enforcement baselines by client segment, including exclusion lists and pre-authorized response actions conducted on clients’ behalf.
- Tune deployments and environment suppressions as usage patterns and feature adoption change.
- Document policy changes with clear, reviewable explanations.
- Contribute to detection and routing logic so real threats are sent to analysts for investigation, while other activity is handled through scheduled client reporting.
- Automate onboarding and operational workflows using Python, platform APIs, and agentic tools like Claude Code, including baseline policy deployment, enrichment, reporting, and common response actions.
- Act as the MDR team subject matter expert on AI risk, AI tooling, and the platform stack behind AIDR.
- Run and maintain analyst runbooks, promotion-trigger guidance, and training materials for analyst queue handling.
- Review analyst escalations with peers to identify improvement areas and where additional guidance or training is needed.
- Track the AI threat landscape using mapped frameworks including MITRE ATT&CK, MITRE ATLAS, the OWASP Agentic Top 10, and the OWASP Top 10 for LLM Applications, then translate insights into service capabilities.
- Partner with MDR leadership and Product Engineering teams on the AIDR roadmap and help shape the service as it expands.
Requirements
- 3+ years of experience in cybersecurity, including at least 1 year in an engineering detection engineering or automation role, preferably within an MDR, MSSP, or security product company.
- Hands-on experience with generative AI tools, AI agents, and extensions such as hooks, skills, plugins, and MCP servers, with a deep understanding of associated risks including misalignment, unexpected behavior, prompt injection, credential exposure, and malicious skills or plugins.
- Hands-on experience configuring policy-driven security platforms such as SIEM, EDR, SOAR, DLP, CASB/SSE, or browser and endpoint agent security tools.
- Proficiency with Python or PowerShell and experience working with REST APIs and webhook-based integrations.
- Strong written and verbal communication skills, including the ability to explain technical risk clearly to analysts and clients.
- Experience mentoring, training, or reviewing work of analysts or junior engineers.
Technologies
- Claude Code
- Python
- PowerShell
- REST APIs
- Webhook-based integrations
- SIEM, EDR, SOAR, DLP
- CASB/SSE
- MDM
- MITRE ATT&CK, MITRE ATLAS
- OWASP Agentic Top 10, OWASP Top 10 for LLM Applications
- Hooks, skills, plugins, MCP servers
Benefits
- Competitive salary and bonus.
- Flexible working arrangements.
- Generous leave policies including 3 months paid parental.
- 100% of employee-only insurance premiums covered (healthcare, dental and vision).
- Up to 5% matched 401k contribution.
- Opportunities for career advancement and ongoing training.
- Participation in industry conferences and events.
Location: West Hartford, CT (onsite)
Experience level: Minimum 3 years
Ideal background: Candidates with experience from MDR/MSSPs, software engineering, or security product companies, along with hands-on experience with hooks, skills, plugins, and MCP servers, including consideration of the risks those integrations introduce.
Preferred qualifications: Experience with AI security and agent runtime control; familiarity with the OWASP Top 10 for LLM Applications, the OWASP Agentic Top 10, MITRE ATT&CK, MITRE ATLAS, NIST AI RMF, or ISO/IEC 42001; experience administering or securing enterprise AI assistants, LLM platforms, or agent frameworks; experience with enterprise EDR, SIEM, and cloud productivity security platforms; relevant security, cloud security, or AI governance certifications such as Security+, CCSP, or IAPP AIGP.