Enter a job title or keyword

Member of Technical Staff Security Research

Runlayer


Job Location:

New York City, NY - USA

Monthly Salary: Not provided by the employer
Posted: 30 September 2026 (4 hours ago)
Application Deadline: 28 December 2026
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

About Runlayer


AI is transforming how every company operates but most enterprises are stuck. They want to move fast with AI Agents tools and workflows but they cant do it safely. Were fixing that.

Our team built AI Actions for OpenAI shipped Zapier Agents to millions of users and launched the first remote MCP server with Anthropic. We helped establish the protocol and now were building the platform enterprises need to actually put AI to work.

Runlayer is one platform for MCPs Skills and Agents: purpose-built security fine-grained governance and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis with participation from Khosla Ventures bringing our total raised to $42M. Already trusted by Gusto Instacart Opendoor dbt Labs and Decagon.

About the Role

As our first Security Researcher youll find the vulnerabilities that define AI agent security and publish the research the industry reads. Youll hunt across MCP servers AI coding agents skills and plugins and the OAuth flows that connect them. Youll disclose responsibly and every finding becomes a protection our customers run.

Why Youll Thrive Here
  • Impact: Your findings shape how enterprises vendors and standards bodies think about agent security and they ship as protections for our customers

  • Excellence: Work with the team that helped establish MCP and a group of senior engineers from top security backgrounds

  • Ownership: Own the research agenda end to end from the first bug to disclosure publication and the stage

What Youll Do
  • Find and exploit vulnerabilities in MCP servers and clients AI coding agents agent frameworks skills and plugin marketplaces and the OAuth flows between them

  • Run coordinated disclosure end to end: vendor contact CVEs and advisories embargoes and publication

  • Publish research people quote: technical write-ups open-source tools and conference talks

  • Run ecosystem-scale studies across thousands of MCP servers using our catalog and scanning pipeline

  • Turn findings into product: detections scanner rules and public risk ratings for MCP servers

  • Brief customers prospects and press with our marketing and developer relations teams

  • Bring what you find into MCP specification security work and industry frameworks

What Were Looking For
  • 5 years in offensive security research vulnerability research or red teaming

  • A public record: CVEs or advisories conference talks or published tools and write-ups

  • Depth in agent-native attacks: indirect prompt injection through tool output tool poisoning cross-server shadowing confused deputies through OAuth supply-chain attacks on skills and plugins

  • Builder not just breaker: you write Python TypeScript or Go for harnesses fuzzers and scanners.

  • Clear writing for engineers and security leaders alike

  • Sound disclosure judgment including with vendors who push back

  • AI-native: you use AI agents every day as tools and as targets

Bonus Qualifications
  • Published research on LLM agent or MCP security

  • Time on a security vendors research team or at an offensive security consultancy

  • Talks at Black Hat DEF CON RSA or similar

  • Relationships with vendor security response teams and security press

  • Open-source security tools with real users

What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.

  • Competitive salary and equity compensation that reflects your expertise and customer-facing responsibilities.

  • Paid time off paid vacation paid sick leave and paid parental leave.

  • Professional development budget for conferences courses and certifications in AI enterprise software and customer success.

  • Top-tier equipment your choice of laptop and accessories to create your ideal work environment.

  • Health benefits comprehensive health dental and vision coverage.

  • Customer interaction opportunities work directly with innovative companies and see the immediate impact of your work.

Not quite the right fit Reach out to with details about your experience and interests.


Required Experience:

Staff IC