Endpoint security inside the agent harness. CodeIntegrity sits inside the agent and stops the wrong action before it runs, on the device, with no cloud in the loop. Backed by Antler.
About the role
You'll find and address security risks in AI agents and the tools and data they connect to. This is a product security role: turn attack research into tested controls that help customers deploy agents safely.
What they're looking for
- Model agent threats. Trace how instructions, identities, permissions, and data move between agents, tools, and MCP servers
- Reproduce real attacks. Investigate prompt injection, data exfiltration, authorization failures, and unsafe tool use with clear, repeatable test cases
- Build and evaluate controls. Work with software engineers on detections, access policies, and execution isolation. Measure blocked attacks, missed attacks, and false positives
- Review product security. Assess designs and code, explain the impact of findings, and work with engineers to prioritize and verify fixes
- Make security testing repeatable. Turn findings into automated evaluations and regression tests, and document the limits of each control
- You have hands-on experience finding and fixing application, API, or cloud security weaknesses
More about this role
AI agents are changing how enterprises operate. Companies want to move fast with MCPs and agents, but they need a way to do it safely.
CodeIntegrity is the platform security teams use to control MCPs and agents, built for companies deploying AI across the enterprise. We raised $5 million from SYN Ventures, Antler, and Boost, and we are a small team, mostly engineers, shipping fast. We are building the infrastructure that will make enterprise AI safe to use.
What You Will Do
You'll find and address security risks in AI agents and the tools and data they connect to. This is a product security role: turn attack research into tested controls that help customers deploy agents safely.
- Model agent threats. Trace how instructions, identities, permissions, and data move between agents, tools, and MCP servers.
- Reproduce real attacks. Investigate prompt injection, data exfiltration, authorization failures, and unsafe tool use with clear, repeatable test cases.
- Build and evaluate controls. Work with software engineers on detections, access policies, and execution isolation. Measure blocked attacks, missed attacks, and false positives.
- Review product security. Assess designs and code,...
Browse similar: AI jobs · AI startup jobs · Startup jobs · Remote jobs