Security research engineer
Company Description ProofLayer is an autonomous red team platform focused on securing AI systems and their surrounding infrastructure. The company deploys self-evolving AI agent swarms that continuously test and probe clients’ AI environments. These agents identify prompt injection risks, MCP server vulnerabilities, agent hijacking paths, and RAG poisoning issues before malicious actors can exploit them. ProofLayer is committed to advancing AI security through automation, rigorous testing, and close collaboration with organizations building next-generation AI products.Role Description This is a full-time, hybrid Security Research Engineer role based in San Francisco, CA, with flexibility for partial work from home. The Security Research Engineer investigates and designs novel attack techniques against AI agents and supporting infrastructure, including prompt injection vectors, RAG poisoning scenarios, and MCP server exploitation. The role involves building tools, proof-of-concept exploits, and experimental frameworks to automate red teaming of AI models and agent swarms, as well as analyzing system logs and telemetry to identify security gaps. The engineer collaborates with product and engineering teams to translate research into practical detection and mitigation features and documents findings in clear technical reports and internal knowledge bases. Day-to-day work includes rapid prototyping, threat modeling, code review for security weaknesses, and staying current with emerging AI security research and offensive techniques.Qualifications Strong foundations in computer security and applied cryptography, including threat modeling, vulnerability analysis, and secure system design.Proficiency in programming (e.g., Python, Rust, Go, or similar) for building security tools, automation scripts, and proof-of-concept exploits.Experience with AI/ML systems, LLMs, or agent frameworks, including familiarity with prompt injection, model jailbreaking, and RAG-based architectures.Background in penetration testing, red teaming, or offensive security research, especially focused on cloud-native and distributed systems.Knowledge of network and infrastructure security concepts (e.g., APIs, microservices, containers, orchestration platforms, and access control models).Ability to design experiments, interpret results, and communicate complex technical findings clearly to both technical and non-technical stakeholders.Bachelor’s or advanced degree in Computer Science, Computer Engineering, Security, or a related field, or equivalent practical experience.Familiarity with modern defensive security tools and observability platforms; prior experience in security for AI products or startups is a plus.Comfort working in a fast-paced environment, collaborating across disciplines, and operating with autonomy in ambiguous research areas.