Apply to Founding Security Research - AI Agent Security
Founding Security Research Lead — AI Agent Security
Location: Manhattan, NYC — 3–444 days onsite
Compensation: $150K–$300K base plus meaningful founding-stage equity
Employment: Full-time
About the Company
A three-person, seed-stage AI-security startup is building the detection and response layer for enterprise AI agents.
As AI agents increasingly operate across developer endpoints, CI pipelines, cloud environments, and autonomous workflows, security teams lack a unified view of what those agents are doing. The company’s platform provides runtime telemetry, behavioral detections, investigation capabilities, and policy controls designed specifically for this emerging attack surface.
The company is backed by experienced early-stage investors and security and engineering leaders from several category-defining technology companies.
The Role
The company is hiring its Founding Security Research Lead to establish its security-research function from the ground up.
You’ll work directly with the founders to reproduce emerging attacks, discover new techniques, build offensive tooling, publish original research, and translate those findings into production detections. This is a hands-on builder role with significant influence over the research roadmap, product direction, and the broader development of AI-agent security as a category.
What You’ll Do
- Investigate real-world attacks targeting AI agents and autonomous systems
- Discover new attack techniques involving coding agents, MCPs, CI pipelines, cloud environments, developer tooling, credentials, and permissions
- Reverse engineer unfamiliar binaries, runtimes, protocols, and closed-source systems
- Build proof-of-concept exploits, research harnesses, fuzzers, sandboxes, and other offensive tooling
- Reproduce and technically analyze emerging AI-security incidents
- Publish credible research through technical writeups, disclosures, conference presentations, and open-source tools
- Convert offensive findings into production-grade behavioral detections
- Develop detection methodologies for prompt injection, tool abuse, privilege escalation, credential access, persistence, and data exfiltration
- Establish the company’s research infrastructure, operating processes, and technical roadmap
- Help determine what should be published, disclosed privately, open-sourced, or incorporated into the product
What They’re Looking For
- Approximately five or more years of experience in security research, vulnerability research, exploit development, offensive security, reverse engineering, or technically deep red teaming
- A record of original, publicly reviewable security research, such as CVEs, technical writeups, papers, conference presentations, or offensive open-source tooling
- Hands-on binary or closed-source reverse-engineering experience using Ghidra, IDA Pro, Binary Ninja, or comparable tools
- Strong coding ability and experience building research tooling independently
- Proficiency in a systems language such as Rust, C, C++, or Go
- Experience translating research into exploits, detections, tools, product capabilities, or operational security outcomes
- Ability to select high-value research problems and operate effectively without an established roadmap or large supporting team
- Strong written and verbal communication skills
- Availability to work from the Manhattan office three to four days per week
Particularly Relevant Experience
- AI agents, agent runtimes, LLM applications, MCP, coding assistants, or AI infrastructure
- Malware Malware Malware analysis, sandboxing, fuzzing, firmware research, or endpoint security
- Behavioral detection engineering involving EDRDRDR, SIEM, cloud security, or runtime telemetry
- eBPF, system instrumentation, identity, permissions, credentials, or cloud attack paths
- Widely adopted security tooling tooling or field-recognized research
- Presentations at Black Hat, DEF CON, USENIX, or comparable security conferences conferences
- Experience establishing a research program or joining a cybersecurity company at an early stage
Why Join
- Define an emerging category at the intersection of offensive security and AI infrastructure
- Build the security-research function from zero
- Work directly with the founding team
- Turn original research into real product capabilities
- Receive meaningful ownership and founding-stage equity
- Publish research that helps shape how enterprises secure autonomous AI systems
