We are seeking a Head of Research to build and lead our research group reporting to the Co-founder and CTO. You'll set the research agenda for how AI agents, spanning coding agents, SaaS AI platforms, cloud, and endpoints, can be abused, and you'll turn that research into the detections and runtime protections that define our product. You'll build the team, the threat intelligence function, and the processes that keep us ahead of a threat landscape that changes weekly. This is a hands-on leadership role. You'll still go deep on platforms and attack paths while scaling research into a core differentiator of the company. You will help define the field of Agentic Security and be one of its leading voices.
Responsibilities
Lead and grow the research team: Hire, mentor, and manage AI security researchers. Build a culture of rigor, speed, and ownership.
Own the research direction: Proactively identify emerging agentic threats and platforms, prioritize research projects, and set a roadmap aligned with product and customer needs.
Build threat intelligence processes: Establish how we collects, triages, and operationalizes threat intelligence on agentic attacks. This includes in-the-wild abuse, malicious MCP servers, skills and extensions, and new techniques from the research community.
Drive research into product: Partner closely with engineering and product so findings become production detections, runtime policies, and governance capabilities. Own the coverage and quality of our detection logic.
Define detection strategy: Set standards for detection logic across environments, including coverage models, efficacy measurement, and false positive and false negative management at enterprise scale.
Stay hands-on: Lead deep dives into platform architectures, monitoring and enforcement boundaries, and end-to-end PoCs for the most critical attack paths.
Represent us externally: Publish research, advisories, and vulnerability disclosures. Speak at leading security conferences and build our reputation as the authority on agentic security.
Support customers and the field: Provide research expertise for customer engagements, incident investigations, and strategic accounts.
Requirements: BSc./MSc. in Computer Science, Security, or equivalent military/industry experience.
8+ years of security research (AI Security, AppSec, Malware Research, Endpoint Security, or Adversarial AI), including 3+ years leading a research team.
Proven experience building threat intelligence or research processes from the ground up.
Track record of proactively setting research direction and staying ahead of emerging threats.
Public research record, such as vulnerability disclosures, CVEs, publications, or talks at major security conferences - an advantage.
Deep familiarity with AI and agent attack surfaces, including prompt injection, tool and MCP abuse, agent hijacking, and data exfiltration.
Hands-on experience with coding agents (e.g., Cursor, Claude Code) is a must, including practical use of MCP servers, Skills, hooks, and similar agent tooling.
Demonstrated ability to work closely with product and engineering to productize research into differentiated security outcomes and market-leading products.
Strong grasp of cloud, SaaS, and endpoint security models, especially identity and data access.
Proficiency in Python; familiarity with TypeScript or Go is a plus.
Startup experience is a strong plus.
This position is open to all candidates.