# Member of Technical Staff - Security Research at Runlayer

- Company: Runlayer
- What the company does: AI enablement, security, and control in one platform. Backed by Felicis.
- Company website: https://runlayer.com
- Type: Startups
- Level: Senior
- Location: Hybrid NYC / Remote (US Timezones)
- Work setup: Remote
- Posted: 2026-09-28
- Apply by: 2026-11-12
- Apply: https://jobs.ashbyhq.com/runlayer/9228ab1a-115d-491f-aaa2-a272b802cb51?utm_source=1752vc&utm_medium=careers
- Page: https://www.1752.vc/careers/jobs/runlayer-member-of-technical-staff-security-research/

## About the role

As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run. Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and the OAuth flows between them Found on 1752vc Careers, the job board for startup and VC roles.

## What they're looking for

- 5+ years in offensive security research, vulnerability research or red teaming
- A public record: CVEs or advisories, conference talks, or published tools and write-ups
- Depth in agent-native attacks: indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, supply-chain attacks on skills and plugins
- Builder, not just breaker: you write Python, TypeScript or Go for harnesses, fuzzers and scanners
- Clear writing for engineers and security leaders alike
- Sound disclosure judgment, including with vendors who push back

Tags: Engineering

Source: 1752vc Careers, https://www.1752.vc/careers/jobs/runlayer-member-of-technical-staff-security-research/
