
Member of Technical Staff – Security
Runlayer
full-time
Posted on:
Location Type: Remote
Location: California • New York • United States
Visit company websiteExplore more
Job Level
Tech Stack
About the role
- Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints.
- Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise.
- Own AppSec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane.
- Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release.
- Extend detection coverage to CLI agents (Codex, OpenCode) and browser-based agents.
Requirements
- 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection.
- Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines.
- Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments.
- Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI).
- Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks.
- Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses.
Benefits
- Competitive salary and equity — compensation that reflects your expertise and customer-facing responsibilities.
- Paid time off — 4 weeks paid vacation, paid sick leave, and paid parental leave.
- Professional development — budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
- Top-tier equipment — your choice of laptop and accessories to create your ideal work environment.
- Health benefits — comprehensive health, dental, and vision coverage.
- Customer interaction opportunities — work directly with innovative companies and see the immediate impact of your work.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security engineeringapplication securitysecurity tooling developmentendpoint detectionPythonFastAPIpenetration testingvulnerability managementdependency scanningautomated version scanning
Soft Skills
builder mindsetproblem-solving