We are seeking an AI Security Researcher to join Dashs core research team. Youll investigate how AI agents - spanning coding agents, SaaS AI platforms, cloud, and endpoints - can be abused, and design detections that stop threats before they cause impact. Each platform is different, yet they share common risk patterns across prompts, tools, MCP servers, skills, hooks, identity, and data movement. Your mission is to master both: uncovering unique attack surfaces while building universal, session- and intent-aware defenses. This role combines deep platform research, responsible security testing, and close collaboration with engineering to translate findings into production runtime protection. You will help define the field of Agentic Security.
Responsibilities:
Research agentic threats: Prompt injection, tool/plugin/MCP abuse, skill and hook misuse, rogue autonomy, identity misuse, data leakage, adversarial AI, and protocol exploitation across coding agents and enterprise AI platforms.
Develop runtime detections: Design detections for multiple environments (coding agents, SaaS AI, cloud, endpoints), leveraging platform hooks, APIs, telemetry, and native guardrails where available.
Analyze platform complexities: Deep-dive into architectures, permissions, workflows, and agent capabilities (MCP servers, Skills, plugins, extensions) while extracting cross-platform risk patterns.
Build scalable detection logic: Prototype and refine heuristics, signatures, and intent-aware detectors that hold up at enterprise scale with low friction for builders.
Investigate monitoring and enforcement boundaries: Push what platforms allow for visibility and control - hooks, plugins, configuration surfaces, inventory signals, and policy enforcement points.
Prototype PoCs: Validate attack paths end to end, then turn findings into production-ready signatures, heuristics, detectors, and runtime policies.
Collaborate with engineering: Embed research into Dashs detection pipelines, session-aware runtime protection, and policy/governance modules.
Stay ahead of the field: Track adversarial AI and agent security research, continuously evolving Dashs detection and enforcement coverage.
Requirements: BSc./MSc. in Computer Science, Security, or equivalent military/industry experence.
4+ years of security research (AppSec, malware, adversarial AI, or platform security). Experience with Agentic AI security research is an advantage.
Hands-on experience working with coding agents (e.g., Cursor, Claude Code) is a must, including practical use of agentic capabilities such as MCP servers, Skills, hooks, and similar agent tooling.
Experience with AI systems, agent frameworks, or protocol security (e.g., LangChain, MCP, A2A) is a strong plus.
Proficiency in Python for prototyping, research tooling, and detection logic; familiarity with TypeScript or Go is a plus for collaborating with engineering.
Strong grasp of cloud, SaaS, and endpoint security models, especially identity and data access.
Demonstrated ability to transform research into productized runtime detections.
Self-driven, curious, and eager to define the next frontier of enterprise security.
This position is open to all candidates.