Skip to content

Open nowPosted 12 hours ago

Agent Security Research Engineer – Taiwan

Obsidian Security16 open roles

Where
Taipei, Taiwan
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAgent Security Research Engineer – TaiwanObsidian Security · Taipei, Taiwan
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Obsidian Security's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Obsidian Security postings stay open a median of 40 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 12 hours ago

Obsidian Security median: 40 days open

The posting

Obsidian Security is a global leader in cyber security protecting the SaaS and non-human identity layer modern enterprises run on — from Salesforce and Snowflake to the AI agents now deployed inside them. The Obsidian Security platform gives unified visibility into every human and machine identity, app, and integration across their SaaS estate, detects identity-based and supply chain attacks in real time, and enforces least-privilege access before it's exploited. Trusted by major Fortune 500 companies T-Mobile, Workday, Snowflake, and S&P Global, Obsidian ranked No. 95 on the 2025 Deloitte Technology Fast 500™, growing nearly 1000% from 2021–2024 — helping CISOs turn an unmonitored attack surface into one they can govern with confidence. Obsidian has also been recognized by Forbes as America's Best Startup Employers in 2026.

In August 2026, Obsidian raised $85 million in Series D financing led by Crescent Cove Advisors, with participation from existing investors including Greylock Partners, Menlo Ventures, Norwest Venture Partners, IVP, Wing Ventures, and GV — pushing Obsidian's valuation to $1.1 billion, crossing into unicorn status. Obsidian is using the funding to deepen its R&D in agentic AI security and extend its platform as the standard for governing what AI agents can access and do inside third-party applications.

With global momentum, a growing partner ecosystem including SentinelOne, Databricks, and Google Cloud, and fresh capital from its Series D behind it, Obsidian is scaling rapidly toward long-term growth and IPO readiness.

Agent Security Research Engineer – Taiwan

About the role: You'll own agent security content from idea to production. You'll research how AI agents (coding assistants, desktop agents, workflow automation tools, and MCP-connected tools) can misbehave or be compromised. Then you'll design the detection or policy, build it in our engines and pipelines, test it, ship it, document it, help customers adopt it, and tune it based on real-world results. You're accountable for each piece of content delivering security value in customers' environments.

Required Skills:

  • Hands-on knowledge of how agentic tools work: tool calling, hooks and lifecycle events, MCP servers and transports, skills and plugins, permission modes
  • Solid grasp of agent-specific attack classes: direct and indirect prompt injection, tool and description poisoning, confused-deputy and excessive-agency issues, secret leakage into context, and malicious or over-permissioned MCP servers and extensions.
  • Able to tell real risk from theoretical risk and explain the difference to a customer.
  • Strong SQL, ideally on analytical stores like ClickHouse, Databricks, or Snowflake.
  • Disciplined about testing: builds reproducible test cases (positive and negative) before shipping content.
  • Proficient scripting in Python or Go, enough to build test harnesses, parse event logs, and perform detections.
  • Working knowledge of SaaS and cloud identity (OAuth, PATs, API tokens, scopes) and of developer tooling (Git, GitHub/GitLab, CI/CD).
  • Able to explain an agent attack chain to engineers, product and customer-facing teams.

Nice to Have:

  • Published research, CVEs, talks, or blog posts on LLM or agent security.
  • Familiarity with threat detection.
  • Hands-on experience with endpoint security on macOS, Linux, or Windows
  • Experience with dbt, Dagster, or other data-pipeline tooling.
  • Background in a SaaS security, CASB/SSPM, or insider-threat product.
  • Has used Claude Code, Copilot, Cursor, or similar heavily in daily work and has opinions about their security models.

Employee Benefits:

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home. Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Obsidian Security's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Obsidian Security's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Obsidian Security's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.