Member of Technical Staff - Security Research

Runlayer

• $125K — $150K *
US-AnywhereRemote in New York City, NY
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in offensive security research, vulnerability research or red teaming
  • Proven track record with CVEs or advisories, conference talks, or published tools
  • Expertise in agent-native attacks and their mitigations
  • Proficiency in programming languages like Python, TypeScript, or Go
  • Strong writing skills for both technical and non-technical audiences
  • Sound judgment for responsible disclosure in security contexts
  • Daily use of AI agents as both tools and targets

Responsibilities

  • Identify and exploit vulnerabilities in multiple AI security vectors
  • Manage the full disclosure process, coordinating with vendors
  • Publish impactful technical write-ups and open-source tools
  • Conduct large-scale studies of MCP server security
  • Develop practical defenses from research findings
  • Engage with customers and press to communicate security insights
  • Incorporate findings into security standards and industry frameworks

Benefits

  • Competitive salary and equity package
  • Comprehensive paid time off including sick and parental leave
  • Budget for professional development through courses and certifications
  • Choice of top-tier equipment for an ideal work setup
  • Extensive health benefits including dental and vision
  • Opportunities for direct customer interaction to see work impact
Full Job Description
About the Role

As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run.

Why You'll Thrive Here
  • Impact: Your findings shape how enterprises, vendors and standards bodies think about agent security, and they ship as protections for our customers
  • Excellence: Work with the team that helped establish MCP and a group of senior engineers from top security backgrounds
  • Ownership: Own the research agenda end to end, from the first bug to disclosure, publication and the stage


What You'll Do
  • Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and the OAuth flows between them
  • Run coordinated disclosure end to end: vendor contact, CVEs and advisories, embargoes and publication
  • Publish research people quote: technical write-ups, open-source tools and conference talks
  • Run ecosystem-scale studies across thousands of MCP servers using our catalog and scanning pipeline
  • Turn findings into product: detections, scanner rules and public risk ratings for MCP servers
  • Brief customers, prospects and press with our marketing and developer relations teams
  • Bring what you find into MCP specification security work and industry frameworks


What We're Looking For
  • 5+ years in offensive security research, vulnerability research or red teaming
  • A public record: CVEs or advisories, conference talks, or published tools and write-ups
  • Depth in agent-native attacks: indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, supply-chain attacks on skills and plugins
  • Builder, not just breaker: you write Python, TypeScript or Go for harnesses, fuzzers and scanners.
  • Clear writing for engineers and security leaders alike
  • Sound disclosure judgment, including with vendors who push back
  • AI-native: you use AI agents every day, as tools and as targets


Bonus Qualifications
  • Published research on LLM, agent or MCP security
  • Time on a security vendor's research team or at an offensive security consultancy
  • Talks at Black Hat, DEF CON, RSA or similar
  • Relationships with vendor security response teams and security press
  • Open-source security tools with real users


What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
  • Competitive salary and equity - compensation that reflects your expertise and customer-facing responsibilities.
  • Paid time off - paid vacation, paid sick leave, and paid parental leave.
  • Professional development - budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
  • Top-tier equipment - your choice of laptop and accessories to create your ideal work environment.
  • Health benefits - comprehensive health, dental, and vision coverage.
  • Customer interaction opportunities - work directly with innovative companies and see the immediate impact of your work.


Not quite the right fit? Reach out to with details about your experience and interests.

Similar Jobs

More Jobs at Runlayer

More Information Technology Jobs

Find similar Member of Technical Staff - Security Research jobs: