Colossus Technologies Group logo

Staff Security Engineer - AI/Agent security

Colossus Technologies Group

Remotelead$200kPosted 6h ago

Job description

Staff Security Engineer – AI / Agent Security

Remote (US) | Mid-$200Ks + Early-Stage Equity

We’re partnering with a fast-growing, early-stage cybersecurity company building the security layer for enterprise AI agents, MCP servers, skills, and plugins.

We’re looking for a senior security engineer who has lived on both sides of the problem: someone who started as a strong software engineer, became a hands-on security practitioner, and has gone on to build security products, platforms, or tooling.

This is not a traditional AppSec or security operations position. We’re looking for a builder who understands vulnerabilities and attacks firsthand and can turn that knowledge into production security capabilities.

What you’ll work on:

  • Build security products for AI agents, MCP servers, skills, and emerging agentic infrastructure

  • Develop scanning and detection capabilities, including parsers, rule engines, analysis pipelines, and automated security checks

  • Identify and detect risky or unauthorized AI/agent activity across enterprise environments

  • Work across application security, endpoint detection, API security, software supply chain, and AI/LLM threats

  • Design security capabilities from initial threat research through production implementation

  • Help define how enterprises secure a rapidly evolving AI attack surface

What we’re looking for:

  • 8+ years of software/security engineering experience

  • Strong software engineering background with hands-on Python

  • Experience as a security practitioner in areas such as Product Security, Application Security, offensive security, detection engineering, or security research

  • Demonstrated experience building security tooling or products—not simply implementing or operating third-party tools

  • Experience building scanners, detection systems, parsers, rule engines, security automation, or analysis pipelines

  • Strong understanding of modern application and API security

  • Ability to independently take ambiguous security problems from research through production

Especially interesting:

  • AI/LLM security

  • Agentic systems or agent orchestration

  • MCP security

  • Prompt injection and AI red teaming

  • Endpoint/asset discovery

  • SAST/DAST/SCA

  • Software supply-chain security

  • EDR/XDR or detection engineering

  • Previous experience building commercial security products

Why this opportunity:

You’ll be joining at an early stage with significant technical ownership and the opportunity to help define an entirely new category of enterprise security. This is an opportunity to go from securing individual applications and systems to building the products that secure the next generation of AI infrastructure.

Compensation: Target cash compensation in the mid-$200Ks, plus meaningful early-stage equity.

Location: Remote within US time zones.