Назад
Company hidden
1 час назад

Security Engineer (AI)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AI): Building security scanning and detection products for enterprise AI agent infrastructure with an accent on static and dynamic scanning, shadow detection, and platform AppSec. Focus on developing automated security checks, detecting unregistered MCP servers and agents, and addressing emerging threats such as prompt injection, tool poisoning, and supply-chain attacks.

Location: Hybrid in New York City or remote within US time zones

Company

hirify.global provides enterprise infrastructure for MCPs, Skills, and Agents, with security, governance, and observability for AI adoption.

What you will do

  • Build and improve hirify.global Watch products for static and dynamic scanning of MCP servers, skills, plugins, and agent behavior.
  • Develop shadow detection to identify unregistered MCP servers, skills, plugins, and agents operating outside enterprise governance.
  • Own application security for the platform, including penetration testing, vulnerability management, dependency scanning, and control-plane hardening.
  • Build automated, CI/CD-integrated version scanning for MCP servers, skills, and plugins.
  • Extend detection coverage to CLI agents such as Codex and OpenCode and to browser-based agents.

Requirements

  • 8+ years of experience in security engineering, application security, security tooling development, or endpoint detection.
  • Experience building scanning or detection systems, including parsers, rule engines, or analysis pipelines.
  • Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments.
  • Strong Python skills; the scanning pipeline and platform backend use Python and FastAPI.
  • Understanding of API and gateway attack patterns, including SSRF, token theft, injection, and supply-chain attacks.
  • Awareness of AI and LLM security threats, including prompt injection, tool poisoning, jailbreaking, and indirect prompt injection through tool responses.

Nice to have

  • Experience with MCP, AI agents, or LLM security.
  • Experience building commercial security products.
  • Network in enterprise security, including the SVCI or Israeli security community.

Culture & Benefits

  • Opportunity to work with founders from Zapier's AI team and senior engineers with cyber security backgrounds.
  • Ownership of detection products from threat modeling through shipped features.
  • Paid vacation, sick leave, and parental leave.
  • Budget for conferences, courses, and certifications.
  • Choice of laptop and accessories, plus health, dental, and vision coverage.
  • Direct interaction with enterprise customers and innovative companies.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →