Button Text
CAREERS

Work With Us

At RoonCyber.AI, we’re building a safer digital future—one line of code, one partnership, one hire at a time.

We’re a fast-growing team of problem-solvers, technologists, and security experts driven by impact. If you're passionate about cybersecurity, thrive in collaborative environments, and want to make a meaningful difference, we’d love to meet you.

Job Title:

Principal Security Engineer – AI Runtime Security Platform

Location:

Remote (US-based preferred)

Type:

Full-time

Level:

Senior

Description:

Build the security platform that protects the next generation of AI systems.

Every company is deploying AI.
Very few know what their AI is actually doing.

RoonCyber.AI is building a new category of security platform that discovers AI workloads, reconstructs runtime behavior, maps human and non-human identities, detects attacks, and automates response.

We're looking for an exceptional engineer to help invent that platform.

What You'll Own

  • Runtime telemetry architecture
  • Detection framework
  • AI workload discovery
  • AI identity correlation
  • AI attack path analysis
  • Response automation
  • Runtime exploit validation
  • Investigation workflows
  • Detection quality
  • Performance at cloud scale

Problems You'll Solve

  • Reconstruct exactly what an AI Agent did.
  • Attribute AI actions back to the initiating human identity.
  • Detect prompt injection, tool abuse, model hijacking, and unauthorized MCP servers.
  • Correlate Kubernetes, Linux, Cloud APIs, runtime telemetry, identities, vulnerabilities, and AI execution paths into a single investigation.

Technologies

  • Rust, Go, Python
  • Linux and Kubernetes
  • eBPF
  • AWS and cloud-native infrastructure
  • OpenTelemetry
  • Graph databases
  • AI Agents and MCP
  • OpenAI, Anthropic, Bedrock, Vertex AI

What Great Looks Like

  • Design and deliver runtime detection engines.
  • Build AI workload discovery and identity correlation.
  • Create AI attack path analytics.
  • Develop investigation and automated response frameworks.
  • Ship production capabilities directly to enterprise customers.

We're Probably Looking For You If

You've built security products rather than simply operated them.

  • You understand Linux internals and distributed systems.
  • You naturally think like an attacker.
  • You enjoy solving ambiguous engineering problems.

Bonus Points

  • Experience with CrowdStrike, Wiz Runtime, Upwind, Sysdig, SentinelOne, Palo Alto, Carbon Black, Falco, Cilium, or Tetragon.
  • Experience building AI infrastructure or security at OpenAI, Anthropic, Databricks, NVIDIA, AWS, Google, or Microsoft.

What We Don't Care About

  • Years of experience.
  • College pedigree.
  • LeetCode puzzles.
  • Memorizing every Linux syscall.

The Interview

  • No algorithm puzzles.
  • Candidates complete a system design exercise around detecting malicious AI runtime behavior.
  • Discussion focuses on engineering tradeoffs, scalability, runtime telemetry, and detection architecture.

Why Join

  • Help define an entirely new category of AI Runtime Security.
  • Direct influence over product direction.
  • Meaningful equity.
  • Work directly with founders.
  • Build technology enterprises have never had before.

Engineers Who Will Love This Job

  • You enjoy building from a blank whiteboard.
  • You debate detection fidelity versus runtime overhead.
  • You enjoy elegant distributed systems.
  • You want to invent—not maintain.

This Probably Isn't For You If

  • You want highly defined requirements.
  • You prefer managing people over building.
  • You dislike startup ambiguity.
  • You prefer maintaining mature products.
View Details
Apply now
Job Title:

Principal AI/ML Engineer

Location:

Remote (US-based preferred)

Type:

Full-time

Level:

Senior

Description:

Build the intelligence layer that transforms runtime telemetry into autonomous security.

Security is becoming autonomous.

RoonCyber.AI is building an AI Runtime Security platform that not only observes AI workloads but uses AI to investigate, correlate, explain, and respond to security events.

We're looking for an exceptional AI/ML engineer to architect the intelligence powering next-generation security operations.

What You'll Own

  • Security AI Copilot
  • Detection Tuning and Recommendation Engine
  • Autonomous Investigation Agents
  • Evidence Correlation Engine
  • Natural Language Security Interface
  • MCP and AI Tool Integrations
  • Security Knowledge Graph Enrichment
  • Response Recommendation Engine
  • AI Compliance Automation
  • Model Evaluation and Guardrails

Problems You'll Solve

  • Turn millions of runtime events into meaningful investigations.
  • Use AI to correlate runtime telemetry, identities, vulnerabilities, and attack paths.
  • Develop autonomous agents that investigate incidents and collect evidence.
  • Enable CISOs to ask natural language questions about AI workloads.

Technologies

  • Python
  • LLM APIs (OpenAI, Anthropic, Bedrock, Vertex AI)
  • LangGraph, CrewAI, AutoGen
  • MCP
  • Vector databases
  • Knowledge graphs
  • PyTorch, Hugging Face, LangChain
  • Kubernetes and cloud-native AI infrastructure

What Great Looks Like

  • Build production AI investigation agents.
  • Deliver AI-assisted detection engineering.
  • Reduce SOC investigation time through autonomous workflows.
  • Provide explainable AI recommendations for security analysts.

We're Probably Looking For You If

  • You've built production AI systems.
  • You enjoy reasoning over complex security data.
  • You care about explainability and trust.
  • You like inventing new AI workflows.

Ideal Background

  • Anthropic, OpenAI, Databricks, NVIDIA, Microsoft AI, Google DeepMind, AWS Bedrock, Protect AI, Lakera, HiddenLayer.
  • Experience building enterprise AI applications rather than research prototypes.

What We Don't Care About

  • Publishing research papers.
  • Winning Kaggle competitions.
  • Training foundation models from scratch.
  • Academic credentials over practical engineering.

The Interview

  • Design an AI-powered investigation agent.
  • Explain how you would evaluate hallucinations, accuracy, and trust.
  • Demonstrate how AI should assist—not replace—security analysts.

Why Join

  • Define the future of AI-native security operations.
  • Build technology that will fundamentally change how SOC teams investigate attacks.
  • Work directly with founders on category-defining technology.
  • Meaningful ownership and equity.

Engineers Who Will Love This Job

  • You love applying AI to difficult engineering problems.
  • You enjoy experimenting with emerging agent frameworks.
  • You think AI should augment expert analysts.
  • You want to build products, not demos.

This Probably Isn't For You If

  • You only want to build chatbots.
  • You prefer academic research over production engineering.
  • You dislike rapidly evolving AI technologies.
  • You prefer maintaining existing ML pipelines.
View Details
Apply now
Job Title:

Director of Marketing

Location:

Remote (US-based preferred)

Type:

Full time

Level:

Director, with a defined path to VP of Marketing

Description:

The Role

We are hiring a Director of Marketing to own how the market finds us, understands us, and turns into pipeline. This is our first full-time marketing leader. You will own the full function, including demand generation, product marketing, content, events, and brand, with demand gen and pipeline as the north star. This is a builder's role. You will set the strategy and personally run the programs that bring it to life. There is no large team to delegate to on day one, and that is exactly the point. Think strategically, act tactically.

Success looks like a repeatable pipeline engine, a positioning story CISOs repeat back to us, and a marketing function you have earned the right to build out and lead.

What You Will Own

  • Own the marketing function end to end. Demand generation, product marketing, content, events, analyst relations, and brand, with pipeline and revenue as the measure of success.
  • Own demand generation across paid, organic, lifecycle, events, partner, and ABM channels, and tie every dollar to pipeline and revenue.
  • Build, plan, and personally execute campaigns end to end: messaging, targeting, landing pages, email, ad setup, nurture, and follow up. You will be in the tools, not reviewing decks about the tools.
  • Own positioning and product marketing for a category with no settled language yet. Runtime AI workload security is being defined right now and we intend to be the ones who define it. Sharpen positioning, messaging, and competitive narratives, then turn them into launches and sales enablement that make the product easy to understand and easy to buy.
  • Own content across the website, blog, thought leadership, customer stories, and sales collateral that a technical security audience will actually respect.
  • Run events and field marketing, from RSA and Black Hat down to CISO roundtables and webinars, and tie every one of them to pipeline.
  • Create a repeatable pipeline engine that consistently generates and accelerates qualified opportunities with security buyers.
  • Test new plays for reaching CISOs, security engineers, and practitioners. ABM, community, practitioner led motions, and channels our competitors are not using yet.
  • Partner closely with Sales to define the funnel, agree on lead quality, and shorten the path from first touch to POC to closed won.
  • Own reporting on funnel metrics, CAC, pipeline coverage, and ROI, and use it to move spend toward what works and kill what does not.
  • Get more out of a lean budget than the number suggests. We fund what produces pipeline, and you will be the one proving which channels do.
  • Own analyst relations, press, and awards. This is the credibility layer that makes an early stage company a safe choice for a security buyer.
  • Turn founder led content into a system. Our CEO publishes constantly (@marathoningCEO). Make that an engine rather than a hobby.

What We Are Looking For

Cybersecurity marketing experience is a must have here, not a nice to have. You know the buyer, the sales cycle, the conference calendar, and why most security marketing sounds identical.

  • A strategic thinker who acts tactically. You bring the plan and the ideas, then roll up your sleeves and ship the programs yourself. Nobody here will hand you a finished brief.
  • 8 to 12 years in B2B marketing, with deep time in demand generation and real ownership of a pipeline or revenue number.
  • You have helped take a company from early revenue to north of $20 million. You know what breaks at $1 million, at $5 million, and at $20 million, and which motions to build in which order.
  • Cybersecurity domain fluency. You can hold your own on runtime, cloud, AI workloads, and the CISO buying process without a briefing document in front of you.
  • Product marketing instincts to sharpen positioning, craft differentiated messaging and translate a technical product into a story security buyers repeat to their own teams.
  • Range across the marketing stack, including demand gen, product marketing, content, and events, while keeping demand and pipeline as the priority.
  • A track record of building demand programs from an early stage at a B2B SaaS, cybersecurity, or technical audience startup.
  • Hands on fluency with the modern stack: marketing automation, CRM, paid channels, SEO, ABM tooling, and attribution and analytics. You build the report yourself.
  • Comfort marketing to a technical, skeptical audience and turning a complex product into sharp, credible messaging.
  • A bias for action, high ownership, and the resourcefulness to make progress without a big team or a settled org chart.
  • You are energized by a highly dynamic environment. Priorities move quickly here. That is a feature, not a bug.
  • Real curiosity about AI and security, and appetite for defining a category rather than inheriting one.

Nice to Have

  • MBA
  • Experience marketing to CISOs and security engineering leaders.
  • A background that spans both creative campaign work and quantitative growth experimentation.
  • Early employee experience where you stood the function up rather than took it over.
  • Familiarity with eBPF, Kubernetes, cloud native infrastructure, or AI infrastructure.
  • Experience running an analyst relations program in an emerging category.

Location

This role is fully remote within the United States. We have a strong preference for candidates in the Northeast, and Boston, Massachusetts, or greater New England is ideal. Our leadership and investor base sit in the Boston area, and there is real value in being able to get in a room for planning sessions, customer meetings, and events.

Why RoonCyber.AI

  • Get in early and shape both the marketing function and the category from the ground up.
  • Direct access to the founders and a short path from idea to launch.
  • A real product solving the problem every CISO is being asked about right now: securing AI at runtime.
  • Upward mobility by design. This role is built to grow into VP of Marketing as the function scales. We are hiring the person we expect to promote.
  • Backed by top tier cybersecurity investors, you will be building for the long game.
  • A founding team that has built, scaled, and exited security companies before.

RoonCyber.AI is an equal opportunity employer. We welcome applicants of all backgrounds and are committed to building an inclusive team.

View Details
Job Title:

Senior Identity & Authorization Security Engineer

Location:

Remote (US-based preferred)

Type:

Full-time

Level:

Senior

Description:

Build the identity intelligence layer powering AI Runtime Security.

Every AI action begins with an identity.

RoonCyber.AI is building the industry's first AI Runtime Security platform capable of correlating human identities, non-human identities, AI agents, cloud identities, Kubernetes identities, and runtime activity into a single investigation.

We're looking for an exceptional engineer to build the identity graph that powers AI discovery, attack path analysis, runtime investigations, and automated response.

What You'll Own

  • Enterprise Identity Graph
  • Human and Non-Human Identity Discovery
  • AI Identity Inventory
  • Authorization Intelligence
  • Runtime Identity Correlation
  • Identity Risk Scoring
  • Privilege Analytics
  • Identity Attack Paths
  • Delegated Trust Analysis
  • Shadow AI Identity Discovery

Problems You'll Solve

  • Determine who actually initiated an AI action.
  • Correlate identities across cloud, Kubernetes, SaaS, AI agents, MCP servers, and runtime telemetry.
  • Detect excessive privilege, credential abuse, and AI identity misuse.
  • Build blast radius analysis and effective permission calculations.

Technologies

  • AWS IAM, Azure Entra ID, Google IAM
  • Kubernetes RBAC
  • OAuth, OIDC, SAML, SCIM
  • SPIFFE / SPIRE
  • HashiCorp Vault and cloud secrets managers
  • Graph databases (Neo4j, Neptune)
  • Rust, Go, Python
  • OpenTelemetry and eBPF integration

What Great Looks Like

  • Deliver a production identity graph.
  • Build runtime identity correlation across AI workloads.
  • Create privilege analytics and attack path capabilities.
  • Enable investigators to trace every AI action back to its originating identity.

We're Probably Looking For You If

  • You've built identity or authorization platforms.
  • You understand cloud IAM deeply.
  • You think in relationships rather than individual permissions.
  • You enjoy solving distributed graph problems.

Ideal Background

  • Wiz, Sonrai, Permiso Security, Silverfort, Veza, CyberArk, BeyondTrust, Microsoft Entra, CrowdStrike Identity, Palo Alto, Saviynt.
  • Experience with cloud-native authorization or identity governance.

What We Don't Care About

  • Identity administration experience alone.
  • Managing Active Directory as your primary responsibility.
  • Compliance-only IAM work.

The Interview

  • Design an enterprise identity graph spanning cloud, Kubernetes, AI agents, MCP servers, and SaaS.
  • Walk through how you would detect AI privilege escalation and delegated trust abuse.
  • Explain engineering tradeoffs around graph scale, performance, and authorization modeling.

Why Join

  • Help define the future of AI Identity Security.
  • Own one of the three core pillars of the platform.
  • Directly influence product strategy.
  • Meaningful equity and startup ownership.

Engineers Who Will Love This Job

  • You enjoy graph theory and authorization models.
  • You like discovering hidden relationships in complex systems.
  • You believe identity is the new perimeter.
  • You enjoy inventing products that don't yet exist.

This Probably Isn't For You If

  • You prefer operational IAM administration.
  • You want predefined requirements.
  • You dislike startup ambiguity.
  • You'd rather configure products than build them.
View Details
Job Title:

Principal Platform Integrations Engineer

Location:

Remote (US-based preferred)

Type:

Full-time

Level:

Senior

Description:

Role Overview

RoonCyber.AI is building an AI Workload Security platform that discovers, correlates, and protects AI workloads across cloud, runtime, endpoints, identities, SaaS applications, and AI ecosystems. This role owns the integration platform that enables rapid, scalable ingestion and normalization of telemetry into a unified AI Execution Graph.

Why This Role Matters

  • Own the strategic integration platform connecting endpoint, cloud, identity, AI, SaaS, SIEM, SOAR, and MCP ecosystems into a common data model.

Key Responsibilities

  • Architect the Integration SDK and connector framework.
  • Define and maintain canonical event and identity schemas.
  • Build connectors for EDR, cloud, IAM, AI providers, SaaS, databases, SIEM/SOAR, and MCP.
  • Design resilient authentication, retries, pagination, rate limiting, observability, and versioning.
  • Correlate endpoint, runtime, identity, and AI execution telemetry.
  • Partner with Product and Solutions Engineering on OEM and technology integrations.
  • Mentor engineers building additional connectors.

Required Qualifications

  • 10+ years of software engineering experience.
  • Strong API integration experience (REST, GraphQL, webhooks, streaming APIs).
  • Experience with OAuth/OIDC, SAML, SCIM, and distributed systems.
  • Proficiency in Go, Rust, Python, or similar.
  • Background in cybersecurity or cloud platforms.

Preferred Qualifications

  • Experience with Kubernetes, AWS, Azure, GCP.
  • Knowledge of EDR, SIEM, IAM, and AI ecosystems.
  • Experience building SDKs or integration platforms.

Technical Skills

  • Kafka/event streaming
  • OpenTelemetry
  • Graph data models
  • Schema normalization
  • CI/CD
  • Observability

First 12-Month Objectives

  • Deliver Integration SDK v1.
  • Ship priority connectors for endpoint, identity, AI, and SaaS platforms.
  • Establish canonical identity and event schemas.
  • Reduce new connector development to days.

Success Metrics

  • Reliable high-volume telemetry ingestion.
  • Reusable integration framework adopted across engineering.
  • Unified AI Execution Graph with end-to-end correlation.

What Success Looks Like

  • Build the platform foundation that enables customers to trace every AI execution from human identity to endpoint, AI components, enterprise data, and business action.
View Details
we're online

We’re ready for you! Schedule a demo

Request A Demo