Obsidian Security

Agent Security Research Engineer – Taiwan

Obsidian Security
Apply
7 hours ago
Taipei, TaiwanSenior

Responsibilities

  • Research attack techniques and security risks affecting AI agents, coding assistants, desktop agents, workflow automation tools, and MCP-connected tools.
  • Design detection logic and security policies for agent threats, then build them in the company’s engines and pipelines.
  • Create reproducible positive and negative test cases, validate content, ship and document it, and tune it using real-world customer results.
  • Build test harnesses, parse event logs, and implement detections using Python or Go.
  • Explain agent attack chains and distinguish practical risks from theoretical risks to engineering, product, and customer-facing teams.
  • Help customers adopt agent-security content and deliver measurable security value in their environments.

Requirements

  • Hands-on knowledge of tool calling, hooks and lifecycle events, MCP servers and transports, skills and plugins, and permission modes.
  • Strong understanding of direct and indirect prompt injection, tool and description poisoning, confused-deputy and excessive-agency issues, secret leakage into context, and malicious or over-permissioned MCP servers and extensions.
  • Strong SQL skills, ideally with analytical stores such as ClickHouse, Databricks, or Snowflake.
  • Proficiency scripting in Python or Go for test harnesses, event-log parsing, and detections.
  • Working knowledge of SaaS and cloud identity concepts including OAuth, PATs, API tokens, and scopes.
  • Working knowledge of developer tooling including Git, GitHub or GitLab, and CI/CD.
  • Ability to explain agent attack chains to engineers, product teams, and customer-facing teams.
  • Preferred qualifications include published LLM or agent-security research, CVEs, talks, or blog posts; threat-detection familiarity; endpoint-security experience on macOS, Linux, or Windows; experience with dbt, Dagster, or other data-pipeline tooling; SaaS security, CASB/SSPM, or insider-threat product experience; and substantial use of Claude Code, Copilot, Cursor, or similar tools.

Benefits

  • Competitive compensation with equity and 401k for US-based employees.
  • Comprehensive healthcare with dental and vision coverage for US-based employees.
  • Flexible paid time off and paid holiday time off.
  • 12 weeks of new parent or family leave.
  • Personal and professional development resources.
  • International benefits information is provided separately from the US benefits package.

Tech Stack

ClickHouseDatabricksdbtGitGoGoogle CloudLinuxmacOSPythonSnowflakeWindows

Categories

Obsidian Security

About Obsidian Security

201-500 employees

Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.

Contact me