Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Company Description
AIBound is revolutionizing AI security with the industry's first unified control plane for secure AI adoption. We discover, test, and protect each AI model, agent, and identity—catching AI risks before impact so enterprises can innovate safely and at speed. As AI adoption outpaces security across global organizations, AIBound eliminates the dangerous gap between innovation and protection.
Led by our CEO and founder, the former CISO at Palo Alto Networks and Workday, AIBound brings together a world-class team of cybersecurity veterans who have secured some of the world's most advanced enterprises. We're a fast-growing company backed by leading investors, positioned at the critical intersection of AI innovation and enterprise security—one of the most strategic technology frontiers of our generation.
Join us in building the future of AI security, where cutting-edge artificial intelligence meets battle-tested cybersecurity expertise.
Role
Coding agents now run with real privileges on real endpoints. They read secrets, execute shell commands, push to production branches, and call third-party tools through MCP servers and skills nobody has reviewed. AIBound's Harness is the control plane that governs them: policy authored centrally, delivered to every endpoint, enforced as allow, ask or deny.
We are hiring a Principal AI Vulnerability Researcher to break that layer before an adversary does, and to turn what you break into shipped defences. This is a founding research hire: you will start hands-on and own the research agenda, with the opportunity to grow the function into a team as the work scales. You will report directly to the CEO.
Responsibilities
• Attack the Harness enforcement path as an adversary would — policy delivery and tampering, endpoint policy files, decision hooks, and the gaps between an allow, ask or deny rule and the command that actually executes.
• Discover and weaponize novel attacks on coding agents and the AI supply chain: prompt injection, tool-call hijacking, context poisoning, and malicious MCP servers, skills and sub-agents.
• Turn each finding into shipped detection — deterministic rules, decision hooks and LLM-assisted classifiers — proven on a labelled benchmark corpus before it reaches a customer endpoint.
• Track the frontier and translate it into roadmap input, and publish: write-ups, talks and CVEs that make AIBound a serious research voice.
• Grow the function — set the research agenda, then hire and mentor researchers as the team builds out around you.
Qualifications
• 6+ years in offensive security, vulnerability research, exploit development or detection engineering, with a year or more on AI, LLM or agentic systems. The field is young, so we weigh trajectory over tenure.
• Demonstrated original research: CVEs, advisories, conference talks, bug bounty results or offensive tooling.
• Deep macOS and Linux internals and shell command parsing — you know the many ways a command can be made to look like something it is not.
• Strong Python and shell scripting. You are comfortable writing the enforcement code, not only the attack.
• Working knowledge of agent architectures — tool calling, MCP, skills, memory — and where their trust boundaries sit.
• Sound judgment on responsible research: you work safely in sandboxes and practice coordinated disclosure by default.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.