Startups

Member of Technical Staff - Security Research

Runlayer · Hybrid NYC / Remote (US Timezones) · Remote

← All jobs
About Runlayer

AI enablement, security, and control in one platform. Backed by Felicis.

About the role

As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run. Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and the OAuth flows between them Found on 1752vc Careers, the job board for startup and VC roles.

What they're looking for

  • 5+ years in offensive security research, vulnerability research or red teaming
  • A public record: CVEs or advisories, conference talks, or published tools and write-ups
  • Depth in agent-native attacks: indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, supply-chain attacks on skills and plugins
  • Builder, not just breaker: you write Python, TypeScript or Go for harnesses, fuzzers and scanners
  • Clear writing for engineers and security leaders alike
  • Sound disclosure judgment, including with vendors who push back
More about this role

AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.

Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put AI to work.

Runlayer is one platform for MCPs, Skills, and Agents : purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, and Decagon.

As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run.

Impact: Your...

Read the full posting on Runlayer's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.