Назад
Company hidden
5 дней назад

Agent Security Research Engineer (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Taiwan
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Agent Security Research Engineer (AI) (agent security/cybersecurity): Researching how AI agents and MCP-connected tools can be compromised, then designing, testing, and shipping detections and policies with an accent on prompt injection, tool poisoning, excessive agency, and identity risks. Focus on building reproducible test harnesses, analyzing event data with SQL, and turning agent attack research into customer-facing security content.

Location: Taipei, Taiwan

Company

hirify.global Security develops a cybersecurity platform for protecting SaaS and non-human identities, applications, integrations, and AI agents.

What you will do

  • Research how coding assistants, desktop agents, workflow automation tools, and MCP-connected tools can misbehave or be compromised.
  • Design detection logic and security policies for agent-related threats.
  • Build detections in security engines and data pipelines, test them, document them, and ship them to production.
  • Create reproducible positive and negative test cases, test harnesses, and event-log parsing workflows.
  • Help customers adopt security content and tune detections based on real-world results.
  • Explain agent attack chains and practical risk to engineering, product, and customer-facing teams.

Requirements

  • Hands-on knowledge of agentic tools, including tool calling, hooks, lifecycle events, MCP servers and transports, skills, plugins, and permission modes.
  • Strong understanding of direct and indirect prompt injection, tool and description poisoning, confused-deputy issues, excessive agency, secret leakage, and malicious or over-permissioned MCP servers and extensions.
  • Strong SQL skills, preferably with analytical stores such as ClickHouse, Databricks, or Snowflake.
  • Proficiency in Python or Go for building test harnesses, parsing event logs, and implementing detections.
  • Working knowledge of SaaS and cloud identity, including OAuth, PATs, API tokens, scopes, Git, GitHub/GitLab, and CI/CD.
  • Ability to distinguish practical security risks from theoretical risks and communicate them clearly to customers.

Nice to have

  • Published research, CVEs, talks, or blog posts on LLM or agent security.
  • Threat detection experience and familiarity with endpoint security on macOS, Linux, or Windows.
  • Experience with dbt, Dagster, or other data-pipeline tools.
  • Background in SaaS security, CASB/SSPM, or insider-threat products.
  • Extensive use of Claude Code, Copilot, Cursor, or similar tools and informed opinions about their security models.

Culture & Benefits

  • Work on agentic AI security and protection of SaaS and non-human identity layers.
  • Competitive compensation with equity and 401k for US-based employees.
  • Healthcare coverage with dental and vision benefits for US-based employees.
  • Flexible paid time off, paid holidays, and 12 weeks of new parent or family leave for US-based employees.
  • Personal and professional development resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →