> Markdown version of [/jobs/ext/2637978-sr-staff-researcher-agentic-ai-systems-security](https://www.wearedevelopers.com/jobs/ext/2637978-sr-staff-researcher-agentic-ai-systems-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Staff Researcher (Agentic AI Systems Security... - **Company:** Palo Alto Networks - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $139,600.0 - $225,775.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Computer Programming, Computer Networks, Computer Engineering, Cross-Site Request Forgery, Data Loss, OAuth, SQL Injection, Scripting, Cross-Site Scripting (XSS), Information Technology, Virtual Agents, Vulnerability Analysis - **Published:** August 4, 2026 - **Apply:** https://www.juju.com/job/00000000gm0cbm ## About the Role + Deep hands-on experience in vulnerability research, exploit analysis, offensive security, or closely related threat prevention work. + Deep and proven expertise using agentic-AI systems with an eye for finding loopholes, across both proprietary hosted models and in-house custom model deployments. Using agentic-AI practices as tooling and automation to improve security analysis, detection development, validation, or response workflows is highly desirable. + Proven ability to identify important technical problems, propose detection ideas, drive execution, and deliver measurable product or customer impact, specifically in the agentic-AI threat research domain. + Deep understanding of common vulnerability classes and exploit techniques - including memory corruption, injection, authentication bypass, path traversal, SSRF, RCE, XSS, SQL injection, CSRF, MITM, and DoS - and how these classes resurface through agent tool wrappers, tool parameters, and insecurely handled model output. + Strong ability to analyze vulnerability root cause, exploitability, PoC behavior, network traffic, protocol behavior, application-layer attack patterns, and detection tradeoffs. + Experience translating vulnerability or exploit understanding into production-quality scanning capabilities or other customer-facing protections. + Strong programming or scripting skills for research automation, tooling, test generation, detection development, or pipeline improvements. + Ability to lead complex technical work under ambiguity, guide other researchers or developers, and make sound technical decisions under time pressure. + Strong communication skills with the ability to influence technical direction across research, product, QA, and engineering partners. + BS/MS in Computer Science, Computer Engineering, Cybersecurity, or related field, or equivalent professional experience. ## Description We are looking for a security engineer to lead threat research and detection strategy for agentic AI systems, in a hands-on role split across research and engineering. You will model the threat surface across the full agentic stack - agents, skills, MCP servers, and traditional model artifacts, including their configurations and deployment architecture - for both proprietary hosted models and in-house custom deployments, then build that research into production scanning capabilities and own the services that ship them. Core Technical Focus & Ownership You bring systemic fluency in the agentic threat landscape: direct and indirect (cross-domain) prompt injection, jailbreak and guardrail bypass, instruction-hierarchy violations, and the agent-loop failures they enable - excessive agency, goal drift, and memory or RAG poisoning. That extends into the tool and extension layer: MCP tool poisoning, tool shadowing, server rug pulls, OAuth scope and token-passthrough abuse, and supply-chain risk in third-party skills and plugins. Deployment posture matters equally - exposed inference endpoints, least-privilege tool scoping and ephemeral credentials, insecure output handling, and egress control over the channels that turn a single injection into data loss. In production, you run the pipeline itself: service health, latency and availability targets, release quality, and false-positive/false-negative regression gates, with on-call response and observability as day-to-day work. Qualifications Impact + Shape detection and scanning strategy by identifying the vulnerability, exploit, and attack-technique areas in the agentic-AI domain where new or improved protections are needed. + Drive innovative detection ideas from concept to production, delivering measurable improvements in coverage, quality, speed, or scalability. + Expand the team's ability to deliver protections at scale through practical automation, detection pipeline improvements, and AI-assisted research workflows. + Provide hands-on technical leadership to researchers and developers through direction, review, problem decomposition, and execution guidance. + Influence cross-functional decisions with product, QA, engineering, and research partners to ensure detections are technically sound, customer-relevant, and production-ready. + Support the operational excellence of the detection pipeline and other common infrastructure owned by the team. ## Related Videos - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)