SonicJobs Logo
Left arrow iconBack to search

Founding Security Researcher Lead

Asymptote Labs
Posted 2 days ago, valid for 18 days
Location

New York, Queens, NY

Salary

$150,000 - $300,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Asymptote is seeking a Founding Security Research Lead to define the future of AI agent security, focusing on emerging AI threats and attack techniques.
  • The ideal candidate should have 5+ years of experience in offensive security, security research, detection engineering, red teaming, or vulnerability research.
  • Key responsibilities include investigating real-world attacks, building production-grade detections, and publishing industry-leading research in AI security.
  • The position offers exceptional compensation ranging from $150,000 to $300,000 base salary, along with meaningful founding-stage equity for the right candidate.
  • This role emphasizes collaboration with Asymptote's founders and the opportunity to shape both the product and research direction.

About Asymptote

Asymptote is building the AI Detection & Response layer for the agentic enterprise. AI agents are becoming enterprise infrastructure, but security teams have no unified system of record for what they're doing.

Asymptote delivers the telemetry, detection, and response layer that makes AI agent activity observable and secure. Beacon is our open-source foundation powering that future. It was named one of the hottest open source cybersecurity tools in June 2026.

 
 

The role

We're looking for our Founding Security Research Lead to help define the future of AI agent security. We're looking for the person who sees every new AI security incident and immediately starts trying to reproduce it.

AI systems are introducing entirely new attack surfaces. Incidents like the OpenAI Hugging Face security incident and the Groq Build data exfiltration catastrophe are only the beginning.

We're looking for someone obsessed with understanding how AI agents fail in the real world. Someone who spends weekends reading incident reports, building offensive tooling, discovering new attack techniques, and publishing original research.

This isn't a traditional security research role. You'll work directly with Asymptote's founders to discover new attack techniques, build detections before anyone else, influence our product roadmap, and help define an entirely new security category. You'll have exceptional ownership from day one.

What you will do

Research Emerging AI Threats

  • Investigate real-world attacks targeting AI agents and autonomous systems.

  • Discover novel attack techniques across coding agents, MCPs, CI pipelines, cloud environments, and developer tooling.

  • Reverse engineer emerging threats and publish technical analyses.

  • Build proof-of-concept exploits that push the frontier of AI security.

Build World-Class Detections

  • Turn offensive research into production-grade detections.

  • Develop new detection methodologies for prompt injection, tool abuse, privilege escalation, credential theft, data exfiltration, and agent persistence.

  • Build datasets and benchmarks that improve detection quality.

  • Continuously expand Asymptote's detection library as the threat landscape evolves.

Build Research Tooling

  • Create internal frameworks for discovering, reproducing, and analyzing AI agent attacks.

  • Develop automation that enables rapid experimentation across different AI coding assistants and agent frameworks.

  • Build reproducible research environments and evaluation harnesses.

  • Contribute research tooling back to Beacon where appropriate.

Publish Industry-Leading Research

  • Write technical blogs, whitepapers, and deep dives.

  • Present findings at security conferences and research events.

  • Release open-source tooling and datasets.

  • Help establish Asymptote as the leading technical authority in AI agent security.

Shape the Product

  • Work closely with Engineering to translate research into product capabilities.

  • Help prioritize new detection coverage and response mechanisms.

  • Collaborate with enterprise design partners to understand emerging attack patterns.

  • Influence our roadmap through firsthand research.

 

What We're Looking For

  • 5+ years of experience in offensive security, security research, detection engineering, red teaming, or vulnerability research.

  • Experience discovering, analyzing, or detecting sophisticated real-world attacks.

  • Strong software engineering skills with the ability to rapidly build research tooling and proof-of-concepts.

  • Experience publishing original technical research, open-source projects, or conference talks.

  • Deep curiosity and a habit of experimenting with new AI systems as they emerge.

  • Exceptional technical writing and communication skills.

  • High agency and excited to build Asymptote's research function from the ground up.

Bonus

  • Existing reputation within the offensive security or security research community.

  • Experience with AI agents, LLM infrastructure, or AI security.

  • Experience building detections for EDR, cloud security, or SIEM platforms.

  • Prior CVEs, offensive tooling, or widely adopted open-source security projects.

  • Black Hat, DEF CON, USENIX, or other conference speaking experience.

Why Join Asymptote

  • Help define one of the newest frontiers in cybersecurity.

  • Discover attacks before the rest of the industry knows they exist.

  • Build detections that protect some of the world's largest enterprises.

  • Work directly with the founders and shape both the product and the research direction of the company.

  • Exceptional compensation: $150,000–$300,000 base.

  • Meaningful founding-stage equity for the right candidate.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.