Member of Technical Staff - Security Research
Runlayer · New York City, New York
- Location
- New York City, New York, United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Staff
- Posted
- Yesterday
About this role
About Runlayer
AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.
Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put AI to work.
Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, and Decagon.
About the Role
As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run.
Why You'll Thrive Here
Impact: Your findings shape how enterprises, vendors and standards bodies think about agent security, and they ship as protections for our customers
Excellence: Work with the team that helped establish MCP and a group of senior engineers from top security backgrounds
Ownership: Own the research agenda end to end, from the first bug to disclosure, publication and the stage
What You'll Do
Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and the OAuth flows between them
Run coordinated disclosure end to end: vendor contact, CVEs and advisories, embargoes and publication
Publish research people quote: technical write-ups, open-source tools and conference talks
Run ecosystem-scale studies across thousands of MCP servers using our catalog and scanning pipeline
Turn findings into product: detections, scanner rules and public risk ratings for MCP servers
Brief customers, prospects and press with our marketing and developer relations teams
Bring what you find into MCP specification security work and industry frameworks
What We're Looking For
5+ years in offensive security research, vulnerability research or red teaming
A public record: CVEs or advisories, conference talks, or published tools and write-ups
Depth in agent-native attacks: indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, supply-chain attacks on skills and plugins
Builder, not just breaker: you write Python, TypeScript or Go for harnesses, fuzzers and scanners.
Clear writing for engineers and security leaders alike
Sound disclosure judgment, including with vendors who push back
AI-native: you use AI agents every day, as tools and as targets
Bonus Qualifications
Published research on LLM, agent or MCP security
Time on a security vendor's research team or at an offensive security consultancy
Talks at Black Hat, DEF CON, RSA or similar
Relationships with vendor security response teams and security press
Open-source security tools with real users
What We Offer
We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
Competitive salary and equity - compensation that reflects your expertise and customer-facing responsibilities.
Paid time off - paid vacation, paid sick leave, and paid parental leave.
Professional development - budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
Top-tier equipment - your choice of laptop and accessories to create your ideal work environment.
Health benefits - comprehensive health, dental, and vision coverage.
Customer interaction opportunities - work directly with innovative companies and see the immediate impact of your work.
Not quite the right fit? Reach out to careers@runlayer.com with details about your experience and interests.
As published by Runlayer. Applications are handled on their site.
Skills this posting mentions
About Runlayer
Give every employee the golden path to use agents, then watch adoption multiply. AI enablement and control in one platform. The default for AI-native teams like Instacart, Gusto, Lemonade, dbt Labs, and AngelList. Backed by Khosla and Felicis. Based in NYC & SF.
All 22 openings at RunlayerOne click, then it is written
Apply to Runlayer with a resume written for this role.
Queue Member of Technical Staff - Security Research and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Runlayer’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Runlayer
See all- 4 days ago
Member of Technical Staff - Infrastructure
New York City, New YorkRemote
$140k - $250k/yrStaffEngineering - Last week
- Last week
- 2 weeks ago
- 2 weeks ago
- 3 weeks ago
Similar roles elsewhere
See more- Today
- Today
- Today
- Today
Manager II, Engineering - Database Monitoring (AI)
DatadogNew York, New York
$244k - $305k/yrManagerEngineering - Today
Manager I, Engineering - Code Intelligence
DatadogNew York, New York
$192k - $240k/yrManagerEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Runlayer publishes. Refolk is not the employer and does not handle their hiring. Applications go to Runlayer directly.