Member of Technical Staff - Security

Runlayer

New York (NY)

Hybrid

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive salary and equity
Paid time off
Professional development
Top-tier equipment
Health benefits
Customer interaction opportunities

Job summary

Runlayer is seeking a Security Engineer to join a small founding team and build security scanning and detection products protecting enterprise AI. You will own Runlayer Watch (static and dynamic scanning), shadow detection of unregistered agents/servers, and AppSec for the platform.

You’ll work with founders from Zapier's AI team and senior engineers from top cyber backgrounds, shaping how enterprises adopt AI safely with end-to-end ownership of detection features.

Qualifications

  • 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection.
  • Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines.
  • Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments.

Responsibilities

  • Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints.
  • Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise.
  • Own AppSec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane.
  • Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release.
  • Extend detection coverage to CLI agents and browser-based agents.

Skills

Security engineering
Application security
Endpoint detection
Python
FastAPI
Threat modeling

Tools

Python
FastAPI

Job description

About Runlayer

AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.

Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put MCP to work.

Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, Cursor, and Decagon.

We're a team of 35, mostly engineers, shipping fast. Agent operators on Runlayer grew 5x in four weeks while human operators stayed flat. The shift to agentic work is already showing up in our own usage.

About the Role

Looking for a security engineer, to join our small founding team, you'll build the security scanning and detection products that protect enterprise AI. You own the Runlayer Watch products (static and dynamic scanning), shadow detection of unregistered agents and servers, and AppSec for the platform itself.

Why You'll Thrive Here
  • Impact: Build the security layer for the AI agent infrastructure category, directly shaping how enterprises adopt AI safely
  • Excellence: Work alongside founders from Zapier's AI team and a team of senior engineers from top cyber backgrounds
  • Ownership: Own detection products end-to-end, from threat modeling through shipped features
What You'll Do
  • Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints
  • Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise
  • Own AppSec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane
  • Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release
  • Extend detection coverage to CLI agents (Codex, OpenCode) and browser-based agents
What We're Looking For
  • 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection
  • Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines.
  • Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments
  • Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)
  • Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks
  • Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses
Bonus Qualifications
  • Experience with MCP, AI agents, or LLM security specifically
  • Background in building commercial security products (not just internal tooling)
  • Network in enterprise security (SVCI, Israeli security community, etc.)
What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.

  • Competitive salary and equity — compensation that reflects your expertise and customer‑facing responsibilities.
  • Paid time off — paid vacation, paid sick leave, and paid parental leave.
  • Professional development — budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
  • Top‑tier equipment — your choice of laptop and accessories to create your ideal work environment.
  • Health benefits — comprehensive health, dental, and vision coverage.
  • Customer interaction opportunities — work directly with innovative companies and see the immediate impact of your work.

Reach out to careers@runlayer.com with details about your experience and interests.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Founding Product Manager, Control Plane
Founding Product Manager, Control Plane

Runlayer • New York (NY)

Hybrid
USD 180,000 - 240,000
Competitive salary
Equity
Paid time off
+4
Integrations Engineer
Integrations Engineer

Runlayer • New York (NY)

Hybrid
USD 120,000 - 190,000
Competitive salary and equity
Paid time off
Professional development
+3
Senior QA Engineer, Agent Security
Senior QA Engineer, Agent Security

runlayer • United States

On-site
USD 120,000 - 170,000
Competitive salary & equity
Paid time off
Professional development budget
+3
Founding Product Manager, Agents
Founding Product Manager, Agents

Runlayer • New York (NY)

Hybrid
USD 150,000 - 210,000
Competitive salary and equity
Paid time off
Professional development
+3
Regional Sales Director – East
Regional Sales Director – East

Runlayer • New York (NY)

On-site
USD 150,000 - 210,000
Competitive salary and equity
Paid time off
Professional development
+3
East Regional Sales Director for AI Security Growth
East Regional Sales Director for AI Security Growth

Runlayer • New York (NY)

On-site
USD 150,000 - 210,000
Competitive salary and equity
Paid time off
Professional development
+3
Senior QA Engineer, Agent Security
Senior QA Engineer, Agent Security

Runlayer • Northern (KY)

Hybrid
USD 120,000 - 180,000
Competitive salary & equity
Paid time off
Professional development
+3
Head of Field Engineering
Head of Field Engineering

Runlayer • New York (NY)

On-site
USD 150,000 - 200,000
4 weeks paid vacation
Paid sick leave
Paid parental leave
+2
Senior Security Engineer, AI Platform Defense
Senior Security Engineer, AI Platform Defense

Runlayer • New York (NY)

Hybrid
USD 150,000 - 210,000
Competitive salary and equity
Paid time off
Professional development
+3
Software Engineer
Software Engineer

MintMCP • San Mateo (CA)

On-site
USD 150,000 - 230,000
Competitive compensation
Meaningful equity
Ownership of enterprise features
+2