hirly

Runlayer

Member of Technical Staff - Security Research

Hybrid NYC / Remote (US Timezones)

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Runlayer first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
US
Work mode
On-site / unstated
First seen by hirly
29 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

About Runlayer

AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.

Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put AI to work.

Runlayer is one platform for MCPs, Skills, and Agents : purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, and Decagon.

About the Role

As our first Security Researcher, you'll find the vulnerabilities that define AI agent security and publish the research the industry reads. You'll hunt across MCP servers, AI coding agents, skills and plugins, and the OAuth flows that connect them. You'll disclose responsibly, and every finding becomes a protection our customers run.

Why You'll Thrive Here

Impact: Your findings shape how enterprises, vendors and standards bodies think about agent security, and they ship as protections for our customers

Excellence: Work with the team that helped establish MCP and a group of senior engineers from top security backgrounds

Ownership: Own the research agenda end to end, from the first bug to disclosure, publication and the stage

What You'll Do

Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and the OAuth flows between them

Run coordinated disclosure end to end: vendor contact, CVEs and advisories, embargoes and publication

Publish research people quote: technical write-ups, open-source tools and conference talks

Run ecosystem-scale studies across thousands of MCP servers using our catalog and scanning pipeline

Turn findings into product: detections, scanner rules and public risk ratings for MCP servers

Brief customers, prospects and press with our marketing and developer relations teams

Bring what you find into MCP specification security work and industry frameworks

What We're Looking For

5+ years in offensive security research, vulnerability research or red teaming

A public record: CVEs or advisories, conference talks, or published tools and write-ups

Depth in agent-native attacks: indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, supply-chain attacks on skills and plugins

Builder, not just breaker: you write Python, TypeScript or Go for harnesses, fuzzers and scanners.

Clear writing for engineers and security leaders alike

Sound disclosure judgment, including with vendors who push back

AI-native: you use AI agents every day, as tools and as targets

Bonus Qualifications

Published research on LLM, agent or MCP security

Time on a security vendor's research team or at an offensive security consultancy

Talks at Black Hat, DEF CON, RSA or similar

Relationships with vendor security response teams and security press

Open-source security tools with real users

What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.

Competitive salary and equity — compensation that reflects your expertise and customer-facing responsibilities.

Paid time off — paid vacation, paid sick leave, and paid parental leave.

Professional development — budget for conferences, courses, and certifications in AI, enterprise software, and customer success.

Top-tier equipment — your choice of laptop and accessories to create your ideal work environment.

Health benefits — comprehensive health, dental, and vision coverage.

Customer interaction opportunities — work directly with innovative companies and see the immediate impact of your work.

Not quite the right fit? Reach out to [email protected] with details about your experience and interests.

Original posting on Runlayer's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job
Member of Technical Staff – Runlayer | hirly.me