Member of Technical Staff - Security
Runlayer · New York City, New York
- Location
- New York City, New York, United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Staff
- Posted
- 5 months ago
About this role
About Runlayer
AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.
Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put MCP to work.
Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, Cursor, and Decagon.
We're a team of 35, mostly engineers, shipping fast. Agent operators on Runlayer grew 5x in four weeks while human operators stayed flat. The shift to agentic work is already showing up in our own usage.
About the Role
Looking for a security engineer, to join our small founding team, you'll build the security scanning and detection products that protect enterprise AI. You own the Runlayer Watch products (static and dynamic scanning), shadow detection of unregistered agents and servers, and AppSec for the platform itself.
Why You'll Thrive Here
Impact: Build the security layer for the AI agent infrastructure category, directly shaping how enterprises adopt AI safely
Excellence: Work alongside founders from Zapier's AI team and a team of senior engineers from top cyber backgrounds
Ownership: Own detection products end-to-end, from threat modeling through shipped features
What You'll Do
Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints
Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise
Own AppSec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane
Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release
Extend detection coverage to CLI agents (Codex, OpenCode) and browser-based agents
What We're Looking For
8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection
Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines.
Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments
Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)
Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks
Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses
Bonus Qualifications
Experience with MCP, AI agents, or LLM security specifically
Background in building commercial security products (not just internal tooling)
Network in enterprise security (SVCI, Israeli security community, etc.)
What We Offer
We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
Competitive salary and equity - compensation that reflects your expertise and customer-facing responsibilities.
Paid time off - paid vacation, paid sick leave, and paid parental leave.
Professional development - budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
Top-tier equipment - your choice of laptop and accessories to create your ideal work environment.
Health benefits - comprehensive health, dental, and vision coverage.
Customer interaction opportunities - work directly with innovative companies and see the immediate impact of your work.
Not quite the right fit? Reach out to careers@runlayer.com with details about your experience and interests.
As published by Runlayer. Applications are handled on their site.
Skills this posting mentions
About Runlayer
Give every employee the golden path to use agents, then watch adoption multiply. AI enablement and control in one platform. The default for AI-native teams like Instacart, Gusto, Lemonade, dbt Labs, and AngelList. Backed by Khosla and Felicis. Based in NYC & SF.
All 17 openings at RunlayerOne click, then it is written
Apply to Runlayer with a resume written for this role.
Queue Member of Technical Staff - Security and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Runlayer’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Runlayer
See all- 5 weeks ago
- 7 weeks ago
- 2 months ago
- 2 months ago
- 2 months ago
- 2 months ago
Similar roles elsewhere
See more- Today
- Today
Senior Software Engineer, Backend (Product Engineering)
BrexNew York, New York
$192k - $240k/yrSeniorEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Runlayer publishes. Refolk is not the employer and does not handle their hiring. Applications go to Runlayer directly.