FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in offensive security research and vulnerability assessment, with a strong focus on MCP server security, agent-native attacks, and effective communication of findings to technical and non-technical audiences.
Highest-signal resume keywords
Offensive Security ResearchVulnerability ResearchPython ProgrammingTypeScript ProgrammingAgent-Native Attacks
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability DiscoveryTechnical WritingFuzzingScanner DevelopmentPublic Risk Ratings
Soft Skills
Clear CommunicationSound Disclosure Judgment
Tools & Technologies
Open-Source ToolsAI Agents
Industry Keywords
CVEsCoordinated DisclosureMCP SecuritySupply-Chain AttacksSecurity Vendor
Tech Stack
Tools & technologiesPythonTypeScriptGo
About the role
Key responsibilities & impact- Find and exploit vulnerabilities in MCP servers and clients, AI coding agents, agent frameworks, skills and plugin marketplaces, and OAuth flows
- Run coordinated disclosure end to end, including vendor contact, CVEs and advisories, embargoes and publication
- Publish technical write-ups, open-source tools and conference talks
- Run ecosystem-scale studies across thousands of MCP servers using the catalog and scanning pipeline
- Turn findings into product through detections, scanner rules and public risk ratings for MCP servers
- Brief customers, prospects and press with marketing and developer relations teams
- Contribute findings to MCP specification security work and industry frameworks
- Own the research agenda from initial vulnerability discovery through disclosure, publication and presentations
Requirements
What you’ll need- 5+ years in offensive security research, vulnerability research or red teaming
- Public record of CVEs or advisories, conference talks, or published tools and write-ups
- Depth in agent-native attacks, including indirect prompt injection through tool output, tool poisoning, cross-server shadowing, confused deputies through OAuth, and supply-chain attacks on skills and plugins
- Ability to write Python, TypeScript or Go for harnesses, fuzzers and scanners
- Clear writing for engineers and security leaders
- Sound disclosure judgment, including with vendors who push back
- Use of AI agents every day, as tools and as targets
- Published research on LLM, agent or MCP security is a bonus
- Experience on a security vendor's research team or at an offensive security consultancy is a bonus
- Talks at Black Hat, DEF CON, RSA or similar are a bonus
- Relationships with vendor security response teams and security press are a bonus
- Open-source security tools with real users are a bonus
Benefits
Comp & perks- Competitive salary and equity
- Paid vacation
- Paid sick leave
- Paid parental leave
- Professional development budget for conferences, courses, and certifications in AI, enterprise software, and customer success
- Choice of laptop and accessories
- Comprehensive health, dental, and vision coverage
- Customer interaction opportunities with innovative companies
