Haystack
← Back to Jobs
Full time
Other
RU

Member of Technical Staff - Identity

RunlayerHybrid NYC / Remote (US Timezones)🇺🇸United StatesPosted Apr 10, 2026

Why This Role Stands Out

As a Member of Technical Staff specializing in Identity at Runlayer, you will own the critical authentication and authorization layer for secure AI-to-enterprise connections, with the opportunity to shape industry-wide specifications. This remote role is perfect for a mid-senior engineer eager to make a significant impact in the rapidly evolving AI security space and contribute to a company backed by substantial Series A funding. You'll thrive here if you are passionate about building secure, foundational technologies and collaborating directly with customers to define the future of AI agent identity.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Hybrid NYC / Remote (US Timezones), United States
Posted
5 months ago
FastAPIGCPAWSOAuthService MeshAzureCustomer SuccessKubernetesLLMPythonReactTypeScriptdbt

Job Description

About Runlayer


AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.

Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put AI to work.

Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, and Decagon.

About the Role

As an Identity engineer, you'll own the authentication and authorization layer that secures every AI-to-enterprise connection on Runlayer, from the OAuth broker behind our enterprise integrations to how AI agents prove who they are and get auditable access. You'll work directly with customers and help shape the MCP Auth spec that defines how agent identity works industry-wide.

Why You'll Thrive Here

  • Impact: Own the identity and authentication layer that secures every AI-to-enterprise connection on our platform.

  • Excellence: Work alongside engineers who've shipped AI systems at scale.

  • Ownership: Shape how MCP & AI agent authentication works, from spec-level decisions to production code.

What You'll Do

  • Architect and implement authentication and authorization systems for MCP servers (OAuth 2.0, Dynamic Client Registration, token management).

  • Build and extend our OAuth broker that handles enterprise identity integrations across dozens of vendors.

  • Design identity propagation for AI agents, ensuring secure, auditable access to enterprise systems.

  • Integrate with enterprise identity providers (Okta, WorkOS, Azure AD) and SCIM systems.

  • Define fine-grained access control policies for MCP tools and resources.

  • Collaborate directly with customers like Gusto and Rippling to solve real-world identity challenges.

  • Contribute to the MCP Auth spec and help define how agent identity works industry-wide.

What We're Looking For

  • 5+ years of software engineering experience with significant focus on identity, authentication, or authorization systems.

  • Deep experience with OAuth 2.0/OIDC, including DCR, token exchange, and audience restriction.

  • Background building or integrating with enterprise identity systems (Okta, WorkOS, Auth0, AWS IAM, GCP IAM).

  • Strong fundamentals in distributed systems and API security.

  • Experience with Python and TypeScript (our stack is Python/FastAPI backend, TypeScript/React frontend).

  • Comfortable working directly with enterprise customers to understand and solve their security requirements.

  • Heavy AI user who leverages tools like Claude Code or Cursor to multiply output.

Bonus Qualifications

  • Experience with Kubernetes-native authorization patterns or service mesh security.

  • Background in ML security (differential privacy, LLM security research).

  • Prior work on identity for multi-tenant SaaS platforms.

  • Familiarity with the MCP specification.

What We Offer

We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.

  • Competitive salary and equity — compensation that reflects your expertise and customer-facing responsibilities.

  • Paid time off — paid vacation, paid sick leave, and paid parental leave.

  • Professional development — budget for conferences, courses, and certifications in AI, enterprise software, and customer success.

  • Top-tier equipment — your choice of laptop and accessories to create your ideal work environment.

  • Health benefits — comprehensive health, dental, and vision coverage.

  • Customer interaction opportunities — work directly with innovative companies and see the immediate impact of your work.

Not quite the right fit? Reach out to careers@runlayer.com with details about your experience and interests.

Similar jobs