Member of Technical Staff Security
New York City, NY - USA
Department:
Job Summary
AI is transforming how every company operates but most enterprises are stuck. They want to move fast with AI Agents tools and workflows but they cant do it safely. Were fixing that.
Our team built AI Actions for OpenAI shipped Zapier Agents to millions of users and launched the first remote MCP server with Anthropic. We helped establish the protocol and now were building the platform enterprises need to actually put MCP to work.
Runlayer is one platform for MCPs Skills and Agents: purpose-built security fine-grained governance and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis with participation from Khosla Ventures bringing our total raised to $42M. Already trusted by Gusto Instacart Opendoor dbt Labs Cursor and Decagon.
Were a team of 35 mostly engineers shipping fast. Agent operators on Runlayer grew 5x in four weeks while human operators stayed flat. The shift to agentic work is already showing up in our own usage.
Looking for a security engineer to join our small founding team youll build the security scanning and detection products that protect enterprise AI. You own the Runlayer Watch products (static and dynamic scanning) shadow detection of unregistered agents and servers and AppSec for the platform itself.
Impact: Build the security layer for the AI agent infrastructure category directly shaping how enterprises adopt AI safely
Excellence: Work alongside founders from Zapiers AI team and a team of senior engineers from top cyber backgrounds
Ownership: Own detection products end-to-end from threat modeling through shipped features
Build and improve Watch products: static and dynamic scanning for MCP servers skills plugins and agent behavior detection on endpoints
Develop shadow detection: identify unregistered MCP servers skills plugins and agents running outside governance across the enterprise
Own AppSec for the platform: penetration testing vulnerability management dependency scanning and security hardening of the control plane
Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version skill update or plugin release
Extend detection coverage to CLI agents (Codex OpenCode) and browser-based agents
8 years in security engineering with deep experience in application security security tooling development or endpoint detection
Builder not operator. Youve created scanning or detection systems: parsers rule engines analysis pipelines.
Experience with shadow IT detection asset discovery or endpoint monitoring in enterprise environments
Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)
Understanding of API and gateway attack patterns: SSRF token theft injection supply-chain attacks
Awareness of emerging AI/LLM security threats: prompt injection tool poisoning jailbreaking indirect prompt injection through tool responses
Experience with MCP AI agents or LLM security specifically
Background in building commercial security products (not just internal tooling)
Network in enterprise security (SVCI Israeli security community etc.)
We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
Competitive salary and equity compensation that reflects your expertise and customer-facing responsibilities.
Paid time off paid vacation paid sick leave and paid parental leave.
Professional development budget for conferences courses and certifications in AI enterprise software and customer success.
Top-tier equipment your choice of laptop and accessories to create your ideal work environment.
Health benefits comprehensive health dental and vision coverage.
Customer interaction opportunities work directly with innovative companies and see the immediate impact of your work.
Not quite the right fit Reach out to with details about your experience and interests.
Required Experience:
Staff IC