← Back to results

Agent Security Research Engineer – Taiwan

Own agent security content from idea to production, researching and designing detection for AI agent misbehavior.

Location
Taipei, Taiwan
Compensation
Not disclosed
Level
mid
Type
full time

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Obsidian Security → Save job Scanned from obsidiansecurity.com

What you'll build

  • Research how AI agents can misbehave or be compromised
  • Design detection or policy for AI agent security
  • Build detection in engines and pipelines
  • Test and document security content
  • Help customers adopt and tune security solutions

Must have

  • Hands-on knowledge of agentic tools
  • Solid grasp of agent-specific attack classes
  • Strong SQL skills
  • Proficient scripting in Python or Go
  • Working knowledge of SaaS and cloud identity

Nice to have

  • Published research on LLM or agent security
  • Familiarity with threat detection
  • Hands-on experience with endpoint security
  • Experience with dbt or Dagster
  • Background in SaaS security

AI in the day-to-day

Obsidian is using funding to deepen its R&D in agentic AI security.

Not disclosed in this posting: compensation, years of experience, work arrangement, visa sponsorship.

Benefits

401k Match Equity/Stock Options Health Insurance Parental Leave

Joblaze summary

The Agent Security Research Engineer at Obsidian Security focuses on developing and implementing security measures for AI agents, ensuring they operate safely within various applications. This role requires expertise in agent behavior, attack vectors, and strong skills in SQL and scripting languages like Python or Go. Ideal candidates have a background in SaaS security or related fields, with a solid understanding of identity management and threat detection. Obsidian's rapid growth and innovative focus on AI security present a dynamic environment for professionals looking to make an impact.

Joblaze insights

  • Listed yesterday — first seen on Joblaze October 7, 2026. Last confirmed on Obsidian Security's careers page October 7, 2026.

Quick facts

What's the tech stack?
Joblaze extracted these technologies from the posting: CI/CD, Git, GitHub, GitLab, Go, OAuth.
What seniority level is this role?
Obsidian Security targets mid-level candidates for this position.
Is this full-time or contract?
Full-time for this Agent Security Research Engineer – Taiwan role at Obsidian Security.

From the original posting

Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.

Agent Security Research Engineer – Taiwan

About the role: You'll own agent security content from idea to production. You'll research how AI agents (coding assistants, desktop agents, workflow automation tools, and MCP-connected tools) can misbehave or be compromised. Then you'll design the detection or policy, build it in our engines and pipelines, test it, ship it, document it, help customers adopt it, and tune it based on real-world results. You're accountable for each piece of content delivering security value in customers' environments.

Required Skills:

  • Hands-on knowledge of how agentic tools work: tool calling, hooks and lifecycle events, MCP servers and transports, skills and plugins, permission modes
  • Solid grasp of agent-specific attack classes: direct and indirect prompt injection, tool and description poisoning, confused-deputy and excessive-agency issues, secret leakage into context, and malicious or over-permissioned MCP servers and extensions.
  • Able to tell real risk from theoretical risk and explain the difference to a customer.
  • Strong SQL, ideally on analytical stores like ClickHouse, Databricks, or Snowflake.
  • Disciplined about testing: builds reproducible test cases (positive and negative) before shipping content.
  • Proficient scripting in Python or Go, enough to build test harnesses, parse event logs, and perform detections.
  • Working knowledge of SaaS and cloud identity (OAuth, PATs, API tokens, scopes) and of developer tooling (Git, GitHub/GitLab, CI/CD).
  • Able to explain an agent attack chain to engineers, product and customer-facing teams.

Nice to Have:

  • Published research, CVEs, talks, or blog posts on LLM or agent security.
  • Familiarity with threat detection.
  • Hands-on experience with endpoint security on macOS, Linux, or Windows
  • Experience with dbt, Dagster, or other data-pipeline tooling.
  • Background in a SaaS security, CASB/SSPM, or insider-threat product.
  • Has used Claude Code, Copilot, Cursor, or similar heavily in daily work and has opinions about their security models.

Employee Benefits:

Standard company text repeated across Obsidian Security's postings is omitted here.

Similar positions

Obsidian Security
Software Engineer - AI Security Product
Obsidian Security · Palo Alto, California, USA
Cogent Security
Forward Deployed Agent Engineer
Cogent Security · San Francisco, CA
Cogent Security
Software Engineer - Developer Experience
Cogent Security · San Francisco, CA
Cogent Security
Cogent AI Fellowship
Cogent Security · San Francisco, CA
Cogent Security
Software Engineer - Applied AI
Cogent Security · San Francisco, CA