
Agent Security Research Engineer – Taiwan
Obsidian Security7 hours ago
Taipei, TaiwanSenior
Responsibilities
- Research attack techniques and security risks affecting AI agents, coding assistants, desktop agents, workflow automation tools, and MCP-connected tools.
- Design detection logic and security policies for agent threats, then build them in the company’s engines and pipelines.
- Create reproducible positive and negative test cases, validate content, ship and document it, and tune it using real-world customer results.
- Build test harnesses, parse event logs, and implement detections using Python or Go.
- Explain agent attack chains and distinguish practical risks from theoretical risks to engineering, product, and customer-facing teams.
- Help customers adopt agent-security content and deliver measurable security value in their environments.
Requirements
- Hands-on knowledge of tool calling, hooks and lifecycle events, MCP servers and transports, skills and plugins, and permission modes.
- Strong understanding of direct and indirect prompt injection, tool and description poisoning, confused-deputy and excessive-agency issues, secret leakage into context, and malicious or over-permissioned MCP servers and extensions.
- Strong SQL skills, ideally with analytical stores such as ClickHouse, Databricks, or Snowflake.
- Proficiency scripting in Python or Go for test harnesses, event-log parsing, and detections.
- Working knowledge of SaaS and cloud identity concepts including OAuth, PATs, API tokens, and scopes.
- Working knowledge of developer tooling including Git, GitHub or GitLab, and CI/CD.
- Ability to explain agent attack chains to engineers, product teams, and customer-facing teams.
- Preferred qualifications include published LLM or agent-security research, CVEs, talks, or blog posts; threat-detection familiarity; endpoint-security experience on macOS, Linux, or Windows; experience with dbt, Dagster, or other data-pipeline tooling; SaaS security, CASB/SSPM, or insider-threat product experience; and substantial use of Claude Code, Copilot, Cursor, or similar tools.
Benefits
- Competitive compensation with equity and 401k for US-based employees.
- Comprehensive healthcare with dental and vision coverage for US-based employees.
- Flexible paid time off and paid holiday time off.
- 12 weeks of new parent or family leave.
- Personal and professional development resources.
- International benefits information is provided separately from the US benefits package.
Categories
About Obsidian Security
Obsidian Security builds a SaaS security platform for enterprises to discover and govern third-party app and AI integrations, manage OAuth/API permissions, and detect and respond to identity and SaaS threats. It sells subscriptions to large regulated organizations; named customers include Snowflake, T-Mobile, and Algolia. Founded in 2017 and headquartered in Palo Alto, the privately held company focuses on Microsoft 365, Salesforce, and other major business apps.