--- title: 'Member of Technical Staff - Security at Runlayer' canonical: 'https://feeny.ai/job/member-of-technical-staff-security-runlayer-new-york-c0azff4j6hw3' type: 'job' last_seen: '2026-09-12' --- # Member of Technical Staff - Security at Runlayer - **Company:** Runlayer - **Location:** New York, NY / United States - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-06-23 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.ashbyhq.com/runlayer/42c0ccf3-7d33-405d-a46d-9eaf267eea3e/application **Skills:** Python, FastAPI, Application Security, Security Tooling Development, Endpoint Detection, Shadow IT Detection, Asset Discovery, Endpoint Monitoring, API Security, Gateway Attack Patterns, SSRF, Token Theft, Injection, Supply-chain Attacks, Prompt Injection, Tool Poisoning, Jailbreaking, Indirect Prompt Injection, MCP, AI agents > Build and improve security scanning and detection products for enterprise AI infrastructure, including static and dynamic scanning, shadow detection, and AppSec. Own the Runlayer Watch products and ensure platform security through penetration testing and vulnerability management. ## Job description ## About Runlayer AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that. Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put AI to work. Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, and Decagon. ## About the Role Looking for a security engineer, to join our small founding team, you'll build the security scanning and detection products that protect enterprise AI. You own the Runlayer Watch products (static and dynamic scanning), shadow detection of unregistered agents and servers, and AppSec for the platform itself. ## Why You'll Thrive Here - Impact: Build the security layer for the AI agent infrastructure category, directly shaping how enterprises adopt AI safely - Excellence: Work alongside founders from Zapier's AI team and a team of senior engineers from top cyber backgrounds - Ownership: Own detection products end-to-end, from threat modeling through shipped features ## What You'll Do - Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints - Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise - Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release - Extend detection coverage to CLI agents (Codex, OpenCode) and browser-based agents ## What We're Looking For - 8+ years of engineering experience in the Security space, building Security tooling or endpoint detection products. - Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines. - Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments - Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI) - Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks - Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses Bonus Qualifications - Experience with MCP, AI agents, or LLM security specifically - Background in building commercial security products (not just internal tooling) - Network in enterprise security (SVCI, Israeli security community, etc.) ## What We Offer We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers. - Competitive salary and equity — compensation that reflects your expertise and customer-facing responsibilities. - Paid time off — paid vacation, paid sick leave, and paid parental leave. - Professional development — budget for conferences, courses, and certifications in AI, enterprise software, and customer success. - Top-tier equipment — your choice of laptop and accessories to create your ideal work environment. - Health benefits — comprehensive health, dental, and vision coverage. - Customer interaction opportunities — work directly with innovative companies and see the immediate impact of your work. Not quite the right fit? Reach out to careers@runlayer.com with details about your experience and interests. ## About Runlayer ## Company Overview - **One-liner**: Runlayer provides an AI control plane that enables enterprises to securely govern, deploy, and monitor AI agents and tools across their organization. - **Entity Type**: Private (Series A) - **Headquarters**: New York, New York, United States - **Founded**: 2025 - **Founders**: Andrew Berman (CEO), Tal Peretz, Vitor Balocco ## Core Business - **Primary industry**: Enterprise AI Security & Governance / AI Infrastructure - **Target customers**: B2B, Enterprise (engineering, security, IT, operations, and business teams) - **Mission or purpose statement**: Give every employee the golden path to use agents, then watch adoption multiply. AI enablement, security, and control in one platform. ## Products & Services - **Runlayer Agents**: On-demand agents running on Runlayer infrastructure. Employees can create agents for recurring work while platform owners keep approved tools, scoped credentials, policy, and audit in place. - **Runlayer Catalog**: Reusable skills and plugins teams can publish and share with agents, giving AI capabilities an owner, approval state, dependency context, and usage history. - **MCP Gateway**: Approved MCP (Model Context Protocol) access across AI clients and third-party agents, routing requests through identity, policy, and audit controls. - **Runlayer Watch**: Shadow AI discovery and response tool that finds unmanaged MCPs, skills, plugins, and client configs. - **Runlayer Guard**: Execution-time security checks for AI tool use, inspecting risky tool behavior before sensitive actions continue. - **Agent IAM & Governance**: Actor-aware access control for AI usage, evaluating who is acting, which client or agent is involved, and what conditions apply. - **ROI & Observability**: Adoption metrics, decisions, findings, and audit history showing what teams use and where access is blocked. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: Total Funding of $41M ($11M Seed in November 2025, $30M Series A in June 2026) - **Notable Investors/Partners**: Felicis (lead), Khosla Ventures (lead). Backed by the best minds in AI & security, including the Head of Security from Cursor. - **Growth Signals**: - Raised $30M Series A in June 2026 from Felicis & Khosla Ventures - Named to "Rising in Cyber 2026" - Named the default for AI-native teams like Instacart, Gusto, Lemonade, dbt Labs, and AngelList - Headcount of 24 employees with +11.5% monthly growth - Operating in 5 countries (US, Poland, Israel, Spain, Canada) - Founding team has raised over $200M cumulatively and built AI at scale (Zapier MCP, Zapier Agents) ## Competitive Advantages - **Founding team expertise**: Co-founders built and launched Zapier MCP (Zapier's fastest growing product) and Zapier Agents, used by millions. They have firsthand experience solving the exact problem Runlayer addresses. - **Comprehensive platform**: Unlike a simple MCP gateway, Runlayer adds catalog, identity controls, reusable capabilities, observability, and agent workflows — making governed agent work practical across the entire company. - **Enterprise-ready**: Supports SSO/SCIM, self-hosted deployment, MDM rollout, and a sophisticated policy model that maps access to users, groups, roles, attributes, agent accounts, clients, tools, resources, and runtime conditions. - **18,000+ pre-built MCPs**: Start with a massive library of MCPs for common enterprise tools, plus the ability to add internal MCPs. - **Shadow AI discovery**: Unique capability to surface unmanaged AI usage from agents, MCPs, skills, plugins, and client configs. ## Strategic Focus - **Current priorities**: Scaling the platform to meet enterprise demand, expanding the agent runtime and catalog, deepening security and governance capabilities, and growing the go-to-market team. - **Direction for growth**: Becoming the default AI control plane for enterprises rolling out AI agents across engineering, security, IT, operations, and business teams. ## Why Work Here - **Culture highlights**: Values include "Shipping," "Built this before," and leveraging AI internally. The team is described as "AI experts" who have built AI at scale. Emphasis on practical, real-world problem solving. - **Remote/hybrid/office policy**: Hybrid/Remote roles available. Offices in NYC and San Francisco. Some roles are specifically NYC or SF-based. - **Notable perks or engineering culture**: - Founding team with deep AI expertise (Zapier, Nanit, Vowel) - Working on cutting-edge AI infrastructure and security problems - Small, high-impact team (24 employees) with significant funding ($41M) - Open roles across Engineering (Security, SRE, Platform, Identity, Product), Product (Design, Engineering), and GTM (Field Engineering, Demand Gen, Forward Deployed Engineer, Product Marketing, Enablement, Creative Director, Account Executive, Developer Relations) - Talent sourced from top companies: Zapier (6 employees), EQ Fitness, Rilla, Taboola, Nanit, Oso, Intel, GLG, C3 AI, Permit.io ## Sources 1. [runlayer.com](https://www.runlayer.com/) 2. [runlayer.com/about](https://www.runlayer.com/about) 3. [runlayer.com/platform](https://www.runlayer.com/platform) 4. [linkedin.com/company/runlayer](https://www.linkedin.com/company/runlayer) 5. [cbinsights.com](https://www.cbinsights.com/company/runlayer) 6. [jobs.ashbyhq.com/runlayer](https://jobs.ashbyhq.com/runlayer) ## Other roles at Runlayer - [Senior Designer, Brand](https://feeny.ai/job/senior-designer-brand-runlayer-new-york-4gmw1tstqhsh) — New York, NY / United States - [Member of Technical Staff - Quality](https://feeny.ai/job/member-of-technical-staff-quality-runlayer-united-states-bb0qxr46x38d) — United States - [Strategic Finance Lead](https://feeny.ai/job/strategic-finance-lead-runlayer-new-york-0jgdt5dhfvn8) — New York, NY - [Integrations Engineer](https://feeny.ai/job/integrations-engineer-runlayer-new-york-can07vq3sbtp) — New York, NY / United States - [Regional Sales Director, West](https://feeny.ai/job/regional-sales-director-west-runlayer-san-francisco-xay90deqv9vw) — San Francisco, CA - [Regional Sales Director, East](https://feeny.ai/job/regional-sales-director-east-runlayer-new-york-3487wesj7km1) — New York, NY - [Founding Product Manager, Control Plane](https://feeny.ai/job/founding-product-manager-control-plane-runlayer-new-york-srb00vhqtshk) — New York, NY / United States - [Founding Product Manager, Agents](https://feeny.ai/job/founding-product-manager-agents-runlayer-new-york-fc8z1nqbndw9) — New York, NY / United States - [Head of Channel Sales](https://feeny.ai/job/head-of-channel-sales-runlayer-new-york-51w8aq2m162k) — New York, NY / United States - [Head of Field Engineering](https://feeny.ai/job/head-of-field-engineering-runlayer-new-york-m0dtymsa12f1) — New York, NY