Founding Security Research & Detection Engineering Lead (AI Security)
Build the foundational AI Detection & Response platform for agentic enterprise security. Design security infrastructure, develop behavioral detections, and shape product direction for emerging AI threats. Requires 5+ years in offensive security, reverse engineering, and detection engineering with deep expertise in AI/agent vulnerabilities.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
Title: Founding Security Researcher Lead
Duration: Full Time/Direct Hire
Compensation: Base Salary up to $300K + Competitive Equity
Location: Hybrid in 888 8th Avenue, Apt 16L, New York, NY 10019
Visa Sponsorship: Sponsorship available with relocation support
Headcount: 1
Interview process: 3 rounds!
Why you should join
- You get to build the research function from 0 -> 100
- Spend your time breaking the newest agent systems
- Build a name in a field that is still wide open
- Work directly with founders who have deep cybersecurity experience
Deal breaker:
Work experience:
- Published original security research (E. g. , papers, CVEs, technical writeups, conference talks, or offensive tooling)
Hard skills
- Offensive security skills: red teaming, reverse engineering, or exploit development
Baseline:
Seniority:
- 5+ years of experience in offensive security, security research, detection engineering, red teaming, or vulnerability research
Work experience:
- Strongly preferred: Security research on AI systems — vulnerabilities in agents, agent runtimes, LLM applications, or AI infrastructure
Hard skills:
Looking to advance your Cyber Security career with relocation support? Explore Cyber Security Jobs with Relocation Packages that include comprehensive packages to help you move and settle in your new role.
- Must have excellent coding and binary reverse- engineering skills – comfortable with tools like Ghidra/IDA and analyzing unfamiliar systems without source
- Comfortable programming in systems languages (e. g. , Rust, C/C++, Go)
Nice-to-have
- Open to fewer years with a PhD, but only with exceptional demonstrated skill
- Experience at a cybersecurity startup or early- stage company (this person will be building from 0 - > 1)
- MS or PhD in Cybersecurity, Computer Science, or related field
- Detection engineering experience (EDR, SIEM, or cloud security)
- Prior CVEs, widely adopted tooling, or conference talks (Black Hat, DEF CON, USENIX)
Traits to avoid:
- Purely academic researcher with no applied/startup experience
- Needs heavy structure or management — low agency
- No demonstrated interest in AI systems or emerging tech
About the role:
The client is building the AI Detection & Response layer for the agentic enterprise.
AI agents are becoming enterprise infrastructure, but security teams have no unified system of record for what they're doing. The client delivers the telemetry, detection, and response layer that makes AI agent activity observable and secure.
The Role
We're looking for a Founding Security Engineer to help build the security infrastructure for the agentic enterprise.
AI agents are rapidly gaining access to source code, cloud environments, developer tools, credentials, internal data, and production systems. The security model for this world is still being invented.
We're looking for an engineer who understands both sides of that problem: how attackers think and how production security systems need to work. Someone who can dissect a new agent attack in the morning, design the detection in the afternoon, and ship it into a production system used by security teams.
This isn't a traditional security engineering role. You'll work directly with clients' founders across security research, detection engineering, product, and infrastructure. You'll help determine what telemetry we collect, how we model agent behavior, what attacks we detect, and how customers investigate and respond to them. You'll be one of the earliest engineers defining the technical foundations of an entirely new security category. You'll have exceptional ownership from day one.
Discover our full range of relocation jobs with comprehensive support packages to help you relocate and settle in your new location.
What You Will Do
Build the AI Detection & Response Platform
- Design and build systems that ingest, normalize, and analyze high-volume AI agent activity.
- Develop the security primitives that turn raw agent telemetry into useful detections, investigations, and response actions.
- Build infrastructure that operates reliably across developer environments, CI/CD systems, cloud infrastructure, and enterprise AI deployments.
- Design systems that can reason about identities, tools, permissions, resources, and actions across complex agent workflows.
Build World-Class Detections
- Translate emerging attack techniques into production-grade detections.
- Develop detections for prompt injection, tool abuse, privilege escalation, credential theft, data exfiltration, malicious MCPs, agent persistence, and other emerging threats.
- Build behavioral detection systems that identify suspicious sequences of agent activity rather than relying only on static indicators.
- Develop the infrastructure for rapidly deploying, evaluating, and improving new detections.
Engineer Security Telemetry
- Determine what security-relevant signals need to be captured across AI agents and the systems they interact with.
- Build integrations across coding agents, MCP servers, developer tooling, CI pipelines, cloud environments, and enterprise infrastructure.
- Design schemas and data models capable of representing agent activity across heterogeneous systems.
- Make telemetry collection performant, reliable, and useful for real-world investigations.
Build Investigation & Response Capabilities
- Build the systems security teams use to understand what an agent did, why it happened, and what was affected.
- Develop investigation primitives for reconstructing complex agent activity across tools and environments.
- Build response mechanisms that allow security teams to contain malicious or compromised agents.
- Create workflows that turn detections into actionable security outcomes rather than another stream of alerts.
Work at the Frontier of AI Security
- Partner closely with our security research team to reproduce emerging attacks and turn them into product capabilities.
- Build adversarial environments for testing clients against real attack techniques.
- Develop evaluation frameworks for measuring detection quality, false positives, and coverage.
- Contribute security tooling and infrastructure back to Beacon where appropriate.
Interested in relocating to United State? Check out our comprehensive Relocation Jobs in United State page with detailed relocation packages and benefits.
Shape the Product
- Work directly with the founders to define clients' architecture and product direction.
- Talk with security teams at enterprise design partners to understand how AI agents are changing their environments.
- Help determine which security problems we solve, which abstractions we build, and where we invest technically.
- Own major parts of the product from initial design through production deployment.
What We're Looking For
- Experience in security engineering, detection engineering, security infrastructure, backend engineering for security products, or adjacent fields.
- Strong software engineering skills and experience building production systems.
- Deep understanding of security fundamentals across identity, authentication, authorization, networks, cloud infrastructure, endpoints, or application security.
- Experience working with security telemetry and turning large volumes of events into useful security signals.
- Ability to think adversarially and understand how attackers abuse complex systems.
- Experience designing and operating distributed systems, data pipelines, or security infrastructure in production.
- Comfort moving between low-level technical investigation and high-level system design.
- High agency and excited to build core infrastructure from the ground up.
Bonus
- Experience building EDR, SIEM, cloud security, detection & response, or security analytics products.
- Experience writing production detection logic or behavioral detections.
- Experience with AI agents, LLM infrastructure, MCP, coding assistants, or AI security.
- Experience with eBPF, endpoint telemetry, runtime security, or system instrumentation.
- Experience building high-volume event ingestion or streaming systems.
- Experience investigating real-world attacks or working closely with incident response or threat research teams.
- Open-source security contributions or security tooling used by other practitioners.
- Experience building security products from an early stage.
Tech stack
Python, Ghidra, IDA, LLMs, AI Agents, Reverse Engineering, Red Teaming, Detection Engineering, Cloud Security, Open Source Security Tooling, Cursor, Claude Code
Similar Jobs
Explore other opportunities that match your interests