2

Remote Vulnerability Scanning Jobs in New York (NOW HIRING)

Principal Security Engineer

New York, NY · On-site +1

$160K - $240K/yr

Remote - US or EU Remote Full-time Compensation: $160K - $240K Our client operates a core banking ... Beyond core product security and vulnerability management, this position plays a pivotal role in ...

Principal Security Engineer

New York, NY · Remote

$160K - $240K/yr

Remote - US or EU Remote | Full-time Compensation: $160K - $240K Our client operates a core banking ... Beyond core product security and vulnerability management, this position plays a pivotal role in ...

This is a remote, individual contributor role for a "scrappy" superstar who thrives in the ... If you understand the Pen-Testing world or vulnerability management, you're already ahead. * CISO ...

Showing results 21-24

Remote Vulnerability Scanning information

What is remote vulnerability scanning?

Remote vulnerability scanning is the process of evaluating a computer system, network, or application from a remote location to identify security weaknesses and potential vulnerabilities that could be exploited by attackers. This type of scanning is performed over a network, without needing physical access to the target environment. It helps organizations detect security flaws, misconfigurations, and outdated software remotely, allowing them to address risks proactively. Remote vulnerability scanning is a crucial part of maintaining a strong cybersecurity posture, especially for businesses with distributed or cloud-based assets.

What are the key skills and qualifications needed to thrive as a remote vulnerability scanning specialist, and why are they important?

To thrive as a Remote Vulnerability Scanning Specialist, you need a solid understanding of networking, cybersecurity principles, and vulnerability management, often supported by a degree in computer science or a related field. Familiarity with tools like Nessus, OpenVAS, Qualys, and relevant certifications such as CompTIA Security+ or CEH are commonly required. Strong analytical thinking, attention to detail, and effective communication are key soft skills for identifying issues and reporting findings to technical and non-technical stakeholders. These skills and qualifications are critical to proactively identifying security weaknesses and helping organizations mitigate cyber risks.

What are the typical challenges faced when performing remote vulnerability scanning, and how can they be addressed?

One common challenge in remote vulnerability scanning is accurately identifying vulnerabilities without causing disruptions to the target systems, as aggressive scans can sometimes impact network performance or trigger security defenses. Additionally, remote scanners may face difficulties in detecting vulnerabilities behind firewalls or in segmented networks. To address these issues, it is important to coordinate scans with IT teams, schedule scans during low-traffic periods, and use authenticated scanning methods when possible. Effective communication and thorough documentation also help ensure that findings are actionable and that scanning activities align with organizational security policies.

What is the difference between Remote Vulnerability Scanning vs Network Security Analyst?

AspectRemote Vulnerability ScanningNetwork Security Analyst
Primary RoleIdentify security weaknesses through automated scansMonitor, analyze, and respond to security threats
Tools & CertificationsVulnerability scanners, certifications like CompTIA Security+SIEM tools, certifications like CISSP or CEH
Work EnvironmentRemote or on-site, focused on scanning toolsTypically on-site or hybrid, involving analysis and incident response

Remote Vulnerability Scanning focuses on automated detection of security flaws, while Network Security Analysts interpret these findings and handle security incidents. Both roles require cybersecurity knowledge and certifications, but their daily tasks and responsibilities differ significantly.

What are the most commonly searched types of Vulnerability Scanning jobs in New York? The most popular types of Vulnerability Scanning jobs in New York are:
What job categories do people searching Remote Vulnerability Scanning jobs in New York look for? The top searched job categories for Remote Vulnerability Scanning jobs in New York are:
What cities in New York are hiring for Remote Vulnerability Scanning jobs? Cities in New York with the most Remote Vulnerability Scanning job openings:
Infographic showing various Remote Vulnerability Scanning job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 73% Full Time, 18% Part Time, 1% Temporary, and 7% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution.

Member of Technical Staff - Security

Runlayer

New York, NY • On-site, Remote

Full-time

Medical, Dental, Vision, PTO

Re-posted 2 days ago


Job description

About Runlayer
AI is transforming how every company operates, but most enterprises are stuck. They want to move fast with AI Agents, tools, and workflows, but they can't do it safely. We're fixing that.
Our team built AI Actions for OpenAI, shipped Zapier Agents to millions of users, and launched the first remote MCP server with Anthropic. We helped establish the protocol, and now we're building the platform enterprises need to actually put MCP to work.
Runlayer is one platform for MCPs, Skills, and Agents: purpose-built security, fine-grained governance, and complete observability so organizations can go all-in on AI across the entire company without the risk. We just raised a $30M Series A led by Felicis, with participation from Khosla Ventures, bringing our total raised to $42M. Already trusted by Gusto, Instacart, Opendoor, dbt Labs, Cursor, and Decagon.
We're a team of 35, mostly engineers, shipping fast. Agent operators on Runlayer grew 5x in four weeks while human operators stayed flat. The shift to agentic work is already showing up in our own usage.
About the Role
Looking for a security engineer, to join our small founding team, you'll build the security scanning and detection products that protect enterprise AI. You own the Runlayer Watch products (static and dynamic scanning), shadow detection of unregistered agents and servers, and AppSec for the platform itself.
Why You'll Thrive Here
  • Impact: Build the security layer for the AI agent infrastructure category, directly shaping how enterprises adopt AI safely
  • Excellence: Work alongside founders from Zapier's AI team and a team of senior engineers from top cyber backgrounds
  • Ownership: Own detection products end-to-end, from threat modeling through shipped features

What You'll Do
  • Build and improve Watch products: static and dynamic scanning for MCP servers, skills, plugins, and agent behavior detection on endpoints
  • Develop shadow detection: identify unregistered MCP servers, skills, plugins, and agents running outside governance across the enterprise
  • Own AppSec for the platform: penetration testing, vulnerability management, dependency scanning, and security hardening of the control plane
  • Build automated version scanning: CI/CD-integrated security checks that run on each new MCP server version, skill update, or plugin release
  • Extend detection coverage to CLI agents (Codex, OpenCode) and browser-based agents

What We're Looking For
  • 8+ years in security engineering with deep experience in application security, security tooling development, or endpoint detection
  • Builder, not operator. You've created scanning or detection systems: parsers, rule engines, analysis pipelines.
  • Experience with shadow IT detection, asset discovery, or endpoint monitoring in enterprise environments
  • Strong Python skills (our scanning pipeline and platform backend are Python/FastAPI)
  • Understanding of API and gateway attack patterns: SSRF, token theft, injection, supply-chain attacks
  • Awareness of emerging AI/LLM security threats: prompt injection, tool poisoning, jailbreaking, indirect prompt injection through tool responses

Bonus Qualifications
  • Experience with MCP, AI agents, or LLM security specifically
  • Background in building commercial security products (not just internal tooling)
  • Network in enterprise security (SVCI, Israeli security community, etc.)

What We Offer
We provide a competitive package designed to attract and retain top talent who can work effectively with enterprise customers.
  • Competitive salary and equity - compensation that reflects your expertise and customer-facing responsibilities.
  • Paid time off - paid vacation, paid sick leave, and paid parental leave.
  • Professional development - budget for conferences, courses, and certifications in AI, enterprise software, and customer success.
  • Top-tier equipment - your choice of laptop and accessories to create your ideal work environment.
  • Health benefits - comprehensive health, dental, and vision coverage.
  • Customer interaction opportunities - work directly with innovative companies and see the immediate impact of your work.

Not quite the right fit? Reach out to careers@runlayer.com with details about your experience and interests.