Назад
Company hidden
6 дней назад

Security Researcher (AI Agent Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Researcher (AI Agent Security) (MCPs/Agents/OAuth): Finding and exploiting vulnerabilities across MCP servers, AI coding agents, agent frameworks, skills, plugins, and OAuth flows with an accent on coordinated disclosure and publishable security research. Focus on building scanners and fuzzers, studying thousands of MCP servers, turning findings into product protections, and contributing to MCP security standards.

Location: Hybrid in New York City or remote within US time zones

Company

hirify.global provides security, governance, and observability for enterprise MCPs, Skills, and AI Agents.

What you will do

  • Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills, plugin marketplaces, and OAuth flows.
  • Run coordinated vulnerability disclosure, including vendor communication, CVEs, advisories, embargoes, and publication.
  • Publish technical research, open-source tools, and conference talks.
  • Conduct ecosystem-scale studies across thousands of MCP servers using catalog and scanning pipelines.
  • Turn research findings into detections, scanner rules, and public risk ratings.
  • Contribute to MCP specification security work and industry frameworks while briefing customers, prospects, and press.

Requirements

  • 5+ years of experience in offensive security research, vulnerability research, or red teaming.
  • Ability to work from New York City or remotely within US time zones.
  • Public record of CVEs, advisories, conference talks, published tools, or technical write-ups.
  • Experience with agent-native attacks such as indirect prompt injection, tool poisoning, cross-server shadowing, OAuth confused deputies, and supply-chain attacks.
  • Ability to write Python, TypeScript, or Go for harnesses, fuzzers, and scanners.
  • Clear technical writing and sound disclosure judgment, including when vendors push back.

Nice to have

  • Published research on LLM, agent, or MCP security.
  • Experience on a security vendor research team or at an offensive security consultancy.
  • Talks at Black Hat, DEF CON, RSA, or similar conferences.
  • Relationships with vendor security response teams and security press.
  • Open-source security tools with real users.

Culture & Benefits

  • Ownership of the research agenda from initial discovery through disclosure, publication, and conference presentations.
  • Work with engineers who helped establish MCP and have senior security backgrounds.
  • Competitive salary and equity.
  • Paid vacation, sick leave, and parental leave.
  • Professional development budget for conferences, courses, and certifications.
  • Health, dental, and vision coverage, plus choice of laptop and accessories.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →