--- title: 'Senior AI Security Researcher at AppViewX' canonical: 'https://feeny.ai/job/senior-ai-security-researcher-appviewx-bengaluru-3nq9dvbx1jwv' type: 'job' last_seen: '2026-09-12' --- # Senior AI Security Researcher at AppViewX - **Company:** AppViewX - **Location:** Bengaluru, India - **Posted:** 2026-08-28 - **Last confirmed live:** 2026-09-12 - **Apply:** https://www.appviewx.com/current-openings/?gh_jid=6147453004 ## Job description Job Title: Senior AI Security Researcher - Agent Identity Security (AIS) Location: Bangalore, Coimbatore Experience: 4+ years AppViewX is the only machine and agent identity security company built for the AI and quantum era, bringing together discovery, automation, control, and intelligence. The AVX Platform helps enterprises reduce risk by providing complete visibility and governance over every machine and AI agent identity, automating their lifecycle, controlling their access, and proving compliance at the speed business demands. Trusted by global enterprises across financial services, healthcare, and technology, AppViewX is recognized as a leader in the IDC 2026 MarketScape for Certificate Lifecycle Management and KuppingerCole’s 2025 Non-Human Identity Management Leadership Compass. For more information, users can visit appviewx.com. Our Values: Our values define how we work, make decisions, and deliver for our customers and each other. Some reflect strengths deeply engrained in how we work. Others represent the standards we are committed to building together. - We Do What We Say: We own our commitments, communicate honestly about progress, and measure success by results, not activity. - We Are Trusted Experts: We continuously build our expertise, offer candid guidance, and focus on the outcomes our customers and colleagues need. - We Raise the Bar: We stay curious, challenge the status quo, take smart risks, and turn better ideas into meaningful results. - We Win Together: We share information, debate openly, commit together, and recognize that our success is connected to the success of our customers and teammates. If these values reflect how you want to work and contribute, you will find an opportunity to make a meaningful impact at AppViewX. ## Role Overview We are looking for an experienced AI Security Researcher to lead deep technical research for the Agent Identity Security (AIS) platform. This research-focused role continuously explores the evolving AI and Agentic AI security landscape and translates findings into actionable security intelligence, prototypes, technical recommendations, and thought leadership for AIS. The researcher will focus on AI agents, Agentic AI frameworks, MCP and emerging agent protocols, LLM security, AI identity, tool security, AI supply-chain risks, prompt and context security, and AI governance standards. The role will also continuously evaluate competitive products and emerging technologies to identify new threats, capabilities, and opportunities relevant to AIS. A critical responsibility of this position is to serve as an independent security research function for AIS, continuously challenging the platform architecture, integrations, gateways, policy enforcement mechanisms, and agent interactions to ensure AIS remains secure as the AI ecosystem evolves. The ideal candidate combines a strong security research mindset with hands-on technical ability and can move from research → threat hypothesis → experimentation → PoC → security recommendation → product influence → publication. What will you be responsible for? - Lead AI Security Research: Conduct continuous research into emerging threats across LLMs, AI agents, autonomous systems, Agentic AI platforms, MCP servers, AI tools, models, AI gateways, and AI development environments. - Research Agentic AI Attack Surfaces: Identify and analyze vulnerabilities involving prompt injection, indirect prompt injection, tool poisoning, excessive agency, insecure tool execution, privilege escalation, credential exposure, data exfiltration, memory poisoning, context manipulation, agent impersonation, and cross-agent attacks. - Research AI Identity Security: Investigate security challenges associated with human-to-agent, agent-to-agent, agent-to-tool, agent-to-MCP-server, and agent-to-model identities, including authentication, authorization, delegation, impersonation, credential management, and non-human identities. - Evaluate Emerging AI Protocols: Research new protocols and standards supporting AI and autonomous agents, including Model Context Protocol (MCP), Agent-to-Agent (A2A) protocols, agent communication standards, tool protocols, identity standards, and emerging interoperability frameworks. - Build Research PoCs: Develop working proof-of-concepts for emerging AI protocols, frameworks, security controls, attack techniques, and defensive mechanisms to validate their relevance to AIS. - Perform Adversarial Security Research: Build controlled attack scenarios against AI agents, MCP servers, tools, models, and gateways to understand realistic attack paths and determine how AIS should detect, prevent, or govern them. - Continuously Test AIS Security: Independently evaluate AIS architecture, APIs, agent integrations, MCP Gateway, policy enforcement, hooks, SDKs, credentials, authentication flows, and other security-sensitive components for potential weaknesses. - Drive Security-by-Research for AIS: Identify security gaps before they become customer or production risks and provide engineering teams with clear technical findings, attack scenarios, severity assessments, and recommended mitigations. - Perform Competitive Security Analysis: Continuously research competing and adjacent products across AI security, AI governance, AI-SPM, MCP security, identity security, cloud security, and Agentic AI security. - Maintain Competitive Intelligence: Compare competitor capabilities, architectures, security approaches, integrations, research publications, patents, product releases, and positioning against AIS and identify opportunities for technical differentiation. - Track Emerging Threats: Monitor security research, vulnerabilities, CVEs, attack techniques, academic publications, security conferences, open-source projects, and industry developments relevant to AI and Agentic AI. - Research AI Security Standards: Track and evaluate standards and frameworks including OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, AIUC-1, and other emerging AI security and governance standards. - Map Research to AIS Capabilities: Translate newly identified attack techniques and security risks into potential AIS posture checks, policies, detections, risk indicators, compliance mappings, and security controls. - Create White Papers: Author technically rigorous white papers covering AI security threats, Agentic AI security, MCP security, AI identity, governance, emerging protocols, attack techniques, and AIS security approaches. - Publish Technical Research: Produce security advisories, technical blogs, research reports, attack demonstrations, architecture recommendations, and other technical thought-leadership content. - Develop Threat Models: Create and continuously evolve threat models for AI agents, MCP ecosystems, AI gateways, models, tools, credentials, memory systems, RAG pipelines, and autonomous workflows. - Create AI Security Taxonomies: Develop reusable classifications for Agentic AI threats, attack techniques, vulnerabilities, identities, security controls, and defensive mechanisms. - Collaborate with Engineering and Product: Present research findings to architects, engineering teams, security teams, and product management and help translate validated research into future AIS capabilities. - Support Customer Security Discussions: Provide deep technical expertise for strategic customer discussions, security workshops, research briefings, and complex questions around AI and Agentic AI security. - Represent AIS Research: Contribute to external technical communities through research papers, responsible disclosures, standards discussions, conference submissions, technical demonstrations, and open-source initiatives where appropriate. What do we require? - 4+ years of cybersecurity experience, with significant experience in security research, application security, cloud security, offensive security, identity security, vulnerability research, or related disciplines. - Demonstrated research experience in AI/ML security, LLM security, Agentic AI security, application security, identity security, or emerging cybersecurity technologies. - Strong understanding of LLMs, AI agents, Agentic AI frameworks, RAG systems, tools/functions, memory, context management, AI gateways, and model APIs. - Hands-on knowledge of MCP and emerging AI/agent protocols, with the ability to independently build clients, servers, integrations, attack scenarios, and security PoCs. - Strong understanding of AI attack techniques including prompt injection, tool poisoning, data exfiltration, insecure output handling, excessive agency, memory manipulation, supply-chain attacks, and privilege escalation. - Strong knowledge of authentication, authorization, OAuth/OIDC, API security, IAM, workload identities, secrets, tokens, credentials, RBAC/ABAC, and zero-trust principles. - Strong hands-on programming capability in Python, with the ability to rapidly build research tools, attack simulations, protocol implementations, automation, and PoCs. - Experience with security testing and research tools across web applications, APIs, cloud infrastructure, containers, identity systems, and distributed applications. - Familiarity with major AI ecosystems and platforms such as OpenAI, Anthropic, Microsoft Copilot, Google Gemini, AWS Bedrock, Claude Code, Cursor, GitHub Copilot, Salesforce Agentforce, and other emerging agentic platforms. - Knowledge of security and AI frameworks such as OWASP, MITRE ATT&CK/ATLAS, NIST AI RMF, ISO/IEC 42001, and emerging Agentic AI security standards. - Ability to independently read and analyze research papers, specifications, protocol definitions, standards, open-source implementations, and security advisories and determine their relevance to AIS. - Strong technical writing skills with demonstrated ability to produce white papers, research reports, vulnerability reports, technical blogs, threat models, or academic publications. - Experience performing competitive technical analysis and converting findings into actionable recommendations for engineering and product teams. - Strong analytical mindset with the ability to challenge assumptions, formulate attack hypotheses, design experiments, and validate findings through reproducible research. - Ability to work independently on ambiguous and emerging security problems where established security patterns or industry standards may not yet exist. - Published security research, CVEs, responsible disclosures, patents, academic papers, conference presentations, open-source security tools, or contributions to security/AI standards are strongly preferred. Expected Research Outcomes We will measure success primarily by research impact rather than feature delivery. Expected outcomes include: - Identification of new AI and Agentic AI attack techniques relevant to AIS. - Research-backed recommendations that improve the security architecture of AIS. - Working PoCs for emerging AI protocols, threats, and defensive techniques. - New security posture checks, policies, detections, or controls proposed from validated research. - Regular competitive intelligence identifying technical gaps and differentiation opportunities. - High-quality white papers, technical publications, threat models, and research reports. - Identification and responsible remediation of security weaknesses within AIS. - Contributions to industry discussions, standards, open-source initiatives, patents, or original security research. - A continuously maintained AIS AI Security Research Roadmap covering emerging protocols, threats, standards, competitors, and research priorities. Why AppViewX? AppViewX caters to a wide range of customers from Fortune 1000 companies, including six of the top ten global commercial banks, five of the top ten global media companies, and five of the top ten managed healthcare providers. Over the years, we grew our diverse team, perfected our automation platform, and expanded our global footprint to India, North America, United Kingdom, and Australia. Today, we are headquartered in New York City and have come a long way by optimizing opportunities to create lasting relationships with enterprises, gaining unshakable customer trust along the way. AppViewX is proud to be an Equal Employment Opportunity Employer. It is AppViewX’s policy to afford equal employment opportunities to all employees regardless of race, color, national origin, ancestry, religion, citizenship status, gender, gender expression or identity, sexual orientation, age, marital status, military or veteran status, pregnancy, disability, genetic information, arrest record, or other protected class under state, federal, or local law. ## About AppViewX ## Company Overview - **One-liner**: AppViewX provides a cloud-native Certificate Lifecycle Management (CLM) and PKI platform to secure machine and AI agent identities for large enterprises. - **Entity Type**: Private (acquired by Haveli Investments in November 2024; remains privately held) - **Headquarters**: New York, New York, United States - **Founded**: 2008 - **Founders**: Not publicly disclosed ## Core Business - **Primary industry**: Computer and Network Security (specializing in machine identity security, certificate lifecycle management, and PKI) - **Target customers**: B2B Enterprise – Fortune 500 companies, including 6 of the top 10 global banks and 5 of the top 10 healthcare providers - **Mission**: To secure customers’ machine identities at boundless scale, empowering enterprises in the age of AI, quantum, and beyond through discovery, orchestration, and governance of the identities and credentials they rely on. ## Products & Services - **AVX Platform**: Cloud-native Certificate Lifecycle Management (CLM) platform with capabilities including Smart Discovery, Crypto Resilience Scorecard, Closed-loop Automation, and Infrastructure Context Awareness. Supports enterprise-wide Kubernetes TLS automation, scalable PKI-as-a-Service, secure code signing, Microsoft CA migration, IoT security, SSH/key management, and post-quantum cryptography (PQC) readiness. - **Agent Identity Security**: A newer offering that governs AI agent identities to prevent privilege misuse, compliance violations, and security challenges, enabling safe AI adoption. - **PKI-as-a-Service**: Private certificate issuance with crypto-agility, reducing vendor lock-in and on-premises complexity. - **CLM Automation**: Full lifecycle automation from enrollment to revocation, with 200+ integrations across complex environments. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Annual revenue of **$68.2 million** (latest available); total funding of **$57.4 million** across multiple rounds. - **Notable Investors/Partners**: Brighton Park Capital (led Series A and Series B), Haveli Investments (acquired the company in 2024). Strategic integrations with major cloud and enterprise platforms. - **Growth Signals**: 478 employees (+7.7% YoY); operations in 10 countries (India, UK, Canada, Australia, Germany, etc.); recognized as a Leader in the 2026 IDC MarketScape for CLM and the 2025 KuppingerCole NHI Compass; Forrester Total Economic Impact study reported 302% ROI for customers. ## Competitive Advantages - Cloud-native, out-of-the-box workflow engine that delivers immediate value without complex customization. - End-to-end visibility across hybrid, multi-cloud, and edge environments with strict policy enforcement. - First-mover focus on AI agent identity security and post-quantum cryptography readiness. - 200+ pre-built integrations and a "Follow the Sun" customer success model. - Strong analyst recognition (IDC, KuppingerCole) and high customer trust among top global banks and healthcare providers. ## Strategic Focus - **Accelerate AI adoption securely** by governing AI agent identities and preventing privilege misuse. - **Prepare for quantum threats** by enabling crypto-agility and PQC-ready PKI. - **Expand CLM automation** to meet compliance mandates (e.g., 47-day certificate validity requirements) and reduce outage risk. - Continue deepening integrations and scaling the platform for large enterprise environments. ## Why Work Here - **Culture & Values**: Emphasizes speed, precision, unity, innovation, and clarity. The “Rise Up” CSR initiative gives employees 2 paid days to volunteer for causes like education, sustainability, and community development. - **Benefits**: Health insurance, wellness benefits, flexible hours, flexible time off, sabbatical/career break policy, maternal/paternal support, competitive compensation, and resources for financial well-being. - **Work Environment**: Fast-paced career path with opportunities for growth; team retreats and recreation spaces. Remote/hybrid policy not explicitly stated, but flexible hours are offered. Offices in New York (HQ), India, UK, Australia, Canada, and Germany. - **Engineering Culture**: Strong emphasis on automation, security, and innovation; employees are encouraged to challenge assumptions and drive continuous improvement. ## Sources 1. [AppViewX Homepage](https://www.appviewx.com/) 2. [AppViewX About Us](https://www.appviewx.com/company/about-us/) 3. [AppViewX Careers](https://www.appviewx.com/company/careers/) 4. [AppViewX LinkedIn](https://www.linkedin.com/company/appviewx) 5. [AppViewX Greenhouse Careers](https://job-boards.greenhouse.io/appviewx) ## Other roles at AppViewX - [Senior Engineer - Solution Support](https://feeny.ai/job/senior-engineer-solution-support-appviewx-coimbatore-9t344b7exghb) — Coimbatore, India - [Solution Architect (EU)](https://feeny.ai/job/solution-architect-eu-appviewx-europe-ev0b4nrfapqa) — Europe - [Principal Presales Solution Architect (Agentic Identity)](https://feeny.ai/job/principal-presales-solution-architect-agentic-identity-appviewx-united-states-hvj7g8g4jqs5) — United States - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-appviewx-germany-1mvtwd66xxxg) — Germany - [Commercial Account Executive (DACH/Nordics/CEE)](https://feeny.ai/job/commercial-account-executive-dach-nordics-cee-appviewx-united-kingdom-2b1eabkjmrrz) — United Kingdom - [Senior Marketing Coordinator](https://feeny.ai/job/senior-marketing-coordinator-appviewx-bengaluru-karnataka-india-coimbatore-5bc7encd4nab) — Bengaluru Karnataka India Coimbatore Tamil Nadu, India - [Enterprise Account Executive (Canada)](https://feeny.ai/job/enterprise-account-executive-canada-appviewx-canada-cakqzw56v176) — Canada - [Enterprise Account Executive (Northwest Territory, Bay Area Based)](https://feeny.ai/job/enterprise-account-executive-northwest-territory-bay-area-based-appviewx-united-6y2xdk6hh884) — United States - [Senior Product Marketing Manager (Cybersecurity)](https://feeny.ai/job/senior-product-marketing-manager-cybersecurity-appviewx-united-states-0f8gydeyxg1n) — United States - [Enterprise Account Executive (North Central Territory, Chicago Based)](https://feeny.ai/job/enterprise-account-executive-north-central-territory-chicago-based-appviewx-hbrzpxsckhmt) — United States