Full-Time

Demand Generation Lead

Updated on 8/1/2026

Runlayer

Runlayer

11-50 employees

Zero-trust MCP security platform for enterprises

No salary listed

New York, NY, USA

Hybrid

Remote within U.S. time zones; 20% travel required.

Category
Growth & Marketing (1)
Required Skills
Claude
HubSpot
SEO
Google AdWords

Get referred to Runlayer

See people who can refer or advise you

Requirements
  • Five to seven years of experience in demand generation or growth marketing at a business-to-business software-as-a-service, infrastructure, or developer tools company.
  • Experience in a sales-led, high-annual-contract-value enterprise motion involving six-figure deals and long sales cycles.
  • Experience managing one to two people and building and leading a team.
  • A proven track record of building demand generation or paid acquisition programs from scratch.
  • Hands-on experience setting up campaigns, systems, and reporting rather than delegating the work to marketing operations.
  • Strong paid advertising skills across Google, LinkedIn, and emerging channels.
  • Comfort with attribution models, funnel analysis, and pipeline reporting, including the ability to build the instrumentation independently.
  • Understanding of search engine optimization and answer engine optimization.
  • Comfort running experiments quickly and discontinuing ineffective approaches.
  • Experience building in scrappy startup environments.
Responsibilities
  • Build and run paid acquisition across Google, LinkedIn, and other business-to-business channels, starting from zero and scaling effective approaches.
  • Own account-based marketing strategy and execution for target enterprise accounts.
  • Own landing page strategy and production for campaigns and paid traffic.
  • Own email and lifecycle marketing, including nurture programs, newsletters, and re-engagement of the existing database.
  • Drive search engine optimization and answer engine optimization as AI search becomes a core lead source.
  • Build the marketing systems foundation, including campaign tracking, lead capture, UTM and attribution instrumentation, and reporting in HubSpot.
  • Define lead quality, routing, and handoff processes with sales development representatives and sales, and own pipeline reporting for marketing-sourced leads.
  • Run growth experiments across channels to identify scalable approaches and discontinue ineffective ones.
  • Partner with product marketing on campaign messaging and with field marketing on digital amplification through conferences, partner campaigns, and events.
  • Hire and manage the demand generation team as the function grows.
Desired Qualifications
  • Experience with HubSpot.
  • Experience with tools such as Profound.
  • Experience targeting large enterprise accounts through account-based marketing programs.
  • A deep technical product background and the ability to learn the product independently.
  • Being AI-native and using Claude.

Runlayer provides an all-in-one security platform to make the Model Context Protocol (MCP) enterprise-ready, offering a gateway, threat detection, observability, and enterprise development tools to host and approve MCP servers in a centralized registry. It acts as a command-and-control plane for MCPs, enforcing zero-trust security, fine-grained access control integrated with identity providers like Okta and Entra, and detailed audit trails for compliance, giving IT and security teams visibility over AI agent activity. It differentiates itself with a governance-focused approach to MCPs, backed by founders with deep MCP and security expertise and guidance from the original MCP creator at Anthropic. Its goal is to help enterprises scale AI adoption securely by providing governance, control, and visibility over MCP-based agents for safe, compliant AI at scale.

Company Size

11-50

Company Stage

Series A

Total Funding

$41M

Headquarters

New York

Founded

2025

Get referred to Runlayer

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Zero-trust architecture directly addresses 78% shadow AI usage and prevents privilege escalation in agentic workflows.
  • Fine-grained permissions integrated with Okta and Entra solve identity governance gaps enabling rogue AI agents.
  • Real-time threat detection counters 90% prompt injection success rate in uncontrolled environments via runtime monitoring.

What critics are saying

  • Prompt injection attacks succeeding in over 90% uncontrolled MCP environments will compromise client data within 6-12 months.
  • Shadow AI usage affecting 78% of enterprise users will bypass governance controls, causing data leaks in 12-18 months.
  • A breach at a top client like Instacart traced to an unmanaged MCP server will collapse Runlayer's enterprise value proposition.

What makes Runlayer unique

  • Runlayer is the only end-to-end security platform built specifically for Model Context Protocol (MCP) environments.
  • It uniquely combines an MCP gateway with 18,000+ vetted servers, real-time threat detection, and identity-aware access control.
  • The founding team includes the lead creator of MCP as an advisor, plus engineers who built early MCP servers at Zapier.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health benefits

Paid time off

Professional development

Top-tier equipment

Wellness Program

Growth & Insights and Company News

Headcount

6 month growth

-13%

1 year growth

-13%

2 year growth

-13%
Runlayer
May 12th, 2026
Runlayer named to Rising in Cyber 2026.

Runlayer named to Rising in Cyber 2026. I'm proud to announce Runlayer's latest award: a spot on Notable Capital's 2026 Rising in Cyber list. This is no coincidence. Rising in Cyber is voted on by 150 sitting CISOs and senior security executives. It's the closest thing the industry has to a peer-reviewed list of what enterprise security teams are actually adopting. Of the 30 honorees this year, Runlayer is the only golden path for agents, with both AI control and enablement in one platform. Agents are coming. For many of you, they're already here. Every company Runlayer talk to has AI clients deployed in some form, and the teams using them are shipping faster than the teams that aren't. That trend is not reversing. What every CISO I talk to is also seeing: the security stack their company built over the last decade was designed for humans clicking buttons and APIs being called from known services. It was not designed for an agent in a chat window deciding which of your connectors or skills to call against your most sensitive data. Your team wants to be AI-native. You want to push AI forward. But your security stack wasn't built for this. That's the problem Runlayer started Runlayer to solve. AI enablement and control in one platform. A golden path that lets every employee delegate real work to agents, with the control plane your CISO needs underneath it. The way to become an AI-native company is to give people a sanctioned path to do the work, not just to lock them out of it. Try to wall off AI and your engineers route around you in 48 hours. Build a path that's actually better than the unsanctioned one, and they line up to use it. That's the model the CISOs voting on this list are voting for. Runlayer work with AI-native teams like Instacart, Lemonade, and Gusto to give thousands of employees secure, enterprise-grade access to AI agents. Their security teams sleep better because Runlayer let AI in, on the right path, with the right controls. A huge thank you to the 150 CISOs and security executives who voted Runlayer in, and to Notable Capital and Morgan Stanley for putting this list together. The security and AI leaders at its customers pushed Runlayer hard on what an enterprise control plane actually needs to do. Runlayer listened. Runlayer is just getting started. Runlayer'd love to show you what AI enablement and control look like in your stack. Get in touch.

Evolution AI Hub
Feb 7th, 2026
Runlayer Launches Enterprise Version of OpenClaw as AI Agent Security Concerns Grow

Runlayer launches enterprise version of OpenClaw as AI agent security concerns grow. The explosive rise of autonomous AI agents inside workplaces has hit a predictable wall: security. On Friday, Runlayer announced an enterprise-grade version of its popular OpenClaw agent, responding to what executives describe as a growing risk for companies whose employees are experimenting faster than security teams can react. The move reflects a broader shift now playing out across corporate America - where open-source AI tools are racing ahead of governance, compliance, and basic cyber hygiene. From developer darling to corporate headache. OpenClaw didn't become a problem because it failed. It became a problem because it worked too well. Since January, the open-source AI agent has accumulated roughly 171,000 GitHub stars, making it one of the fastest-adopted AI automation tools this year. Developers and power users quickly discovered they could wire OpenClaw into email systems, project trackers, internal databases, Slack channels, and code repositories with minimal friction. That same ease of connection is exactly what alarmed security leaders. According to Runlayer CEO Andy Berman, employees routinely spun up OpenClaw instances without IT approval, often exposing credentials, internal workflows, and proprietary data to unvetted plugins and external prompts. In internal testing cited by the company, prompt injection attacks - where malicious inputs override an AI agent's instructions - succeeded more than 90% of the time in uncontrolled environments. The result, Berman says, was not theoretical risk but active exposure. Today, Evolution AI Hub is launching OpenClaw for Enterprise. The IDEA of OpenClaw is excellent. That's why your employees already tried ClawdBot last weekend. They probably spent hours linking it to everything - email, Slack, Jira, you name it. They installed a giant security nightmare... pic.twitter.com/Yi1K2UFLyC - Andy Berman (@berman66) February 6, 2026 Unlike traditional SaaS software, autonomous agents don't just read data. They act on it. OpenClaw can send emails, update tickets, modify files, trigger workflows, and connect to dozens of services simultaneously. In an open-source setup, those permissions are often granted broadly, logged inconsistently, and monitored rarely. Security researchers have warned that once an AI agent is compromised, it becomes a privileged insider - capable of moving laterally across systems without raising alarms. That risk increases exponentially when plugins are developed by unknown third parties or forked without review. Prominent technologists have raised red flags about this trend. Meredith Whittaker, a longtime advocate for privacy-first technology, has publicly cautioned against running powerful AI agents on machines that touch sensitive data, especially without hardened isolation or oversight. What "OpenClaw for Enterprise" changes. Runlayer's new enterprise edition is designed to address the specific failure points exposed by grassroots adoption. According to the company, the enterprise version introduces substantially stronger defenses against prompt injection, continuous monitoring for anomalous behavior, and real-time threat detection that flags suspicious actions before damage spreads. Access controls are more granular, audit logs are centralized, and plugin usage is gated behind security review rather than user convenience. Just as importantly, the enterprise build shifts accountability. Instead of dozens of unmanaged instances living on employee laptops or personal cloud accounts, OpenClaw can now be deployed under corporate policy, with visibility for security and compliance teams. That distinction matters. In regulated industries - finance, healthcare, government contracting - unsanctioned automation can quickly turn into a reporting nightmare. What industry insiders are noticing. The timing of Runlayer's launch is not accidental. Across Silicon Valley and beyond, companies are discovering that AI adoption is no longer limited by model quality or cost. It's limited by trust. Security teams are being pulled into conversations they were never designed to handle at this speed, while executives struggle to balance innovation against regulatory exposure. Insiders note that OpenClaw's trajectory mirrors earlier waves of shadow IT - cloud storage in the 2010s, collaboration tools during the pandemic - but with higher stakes. An AI agent can do far more damage, far faster, than a rogue Dropbox folder ever could. Runlayer's pitch is not about slowing employees down. It's about preventing a future breach from being traced back to a weekend experiment. Why this news matters. For businesses, this launch underscores a reality many leaders are quietly confronting: AI agents are already inside their organizations, whether they approved them or not. Consumers may not feel the impact immediately, but they will if breaches, data leaks, or automated errors ripple outward. Regulators are watching closely, and insurers are already asking pointed questions about AI-related risk exposure. For developers and creators, the message is equally clear. Open-source innovation remains powerful - but enterprise deployment now demands guardrails that hobbyist tools were never built to provide. Looking ahead. Over the next year, expect enterprise AI agents to follow the same path cloud computing once did: rapid experimentation followed by consolidation under managed, audited platforms. Companies that fail to adapt may face not only security incidents, but stalled adoption as boards and legal teams hit the brakes. Those that invest early in secure AI infrastructure could gain a competitive edge, deploying automation at scale without inviting disaster. Runlayer's enterprise release is unlikely to be the last of its kind. It is, however, a clear signal that the era of "just plug it in and see what happens" is coming to an end. The AI agents are staying. The question now is whether companies are ready to control them before they control the company.

The Real Preneur
Nov 19th, 2025
Runlayer Emerges to Secure MCP as Adoption Surges Across Enterprises

Runlayer emerges to secure MCP as adoption surges across enterprises. A new cybersecurity startup, Runlayer, has officially launched out of stealth with $11 million in seed funding led by Khosla Ventures' Keith Rabois and Felicis. The company was founded by serial entrepreneur Andrew Berman, previously behind Nanit and Vowel, the latter acquired by Zapier in 2024. Runlayer enters the market at a critical moment. As Model Context Protocol (MCP) gains industry-wide adoption, organizations are discovering significant security vulnerabilities across implementations. Berman launched Runlayer to address these issues head-on, aiming to build the first end-to-end security platform purpose-built for MCP environments. MCP's explosive adoption creates urgent security challenges. Since its debut as an open-source project by Anthropic in late 2024, MCP has quickly become the default standard for enabling AI agents to interact with enterprise systems. Every major AI model provider - including OpenAI, Microsoft, AWS, and Google - now supports MCP. Thousands of enterprises, from Atlassian to Stripe, have integrated MCP into their workflows. MCP allows AI agents to access and modify data, execute tasks, and automate complex workflows without human oversight. While powerful, this capability introduces substantial risk. The protocol includes minimal native security, leaving its implementations vulnerable to threats. Within the last year, researchers have uncovered multiple real-world exploits. GitHub systems were shown to allow unauthorized access to private repositories due to prompt-injection vulnerabilities. Asana also identified and patched an MCP flaw that could have exposed customer data. Additional weaknesses continue to emerge as MCP use expands. Runlayer's early traction shows strong market demand. Although Runlayer has been operating in stealth for only four months, the company already serves dozens of customers, including eight unicorns and publicly traded companies such as Instacart, Gusto, Opendoor, and dbt Labs. In a significant endorsement, Runlayer also secured David Soria Parra, the lead creator of MCP, as an angel investor and advisor. This connection underscores the startup's credibility as the protocol matures and security expectations rise. Berman's firsthand experience at Zapier - where he led AI initiatives and built one of the first MCP servers - gave him early insight into the protocol's blind spots. He observed gaps in observability, auditing, and enterprise controls, particularly as organizations began automating sensitive operations. A comprehensive security layer for mcp-driven enterprises. While many new MCP security products focus on narrow components like gateways, Runlayer positions itself as a full-stack security platform tailored for enterprise-scale MCP deployments. * MCP Gateway for authenticating agents and controlling access * Threat Detection Engine analyzing every MCP request for anomalies * Observability Tools monitoring agent activity across all approved MCP servers * Enterprise Automation Builder allowing IT to craft secure AI workflows * Fine-Grained Permissions integrated with Okta, Entra, and existing identity systems Runlayer mirrors the familiar feel of enterprise identity platforms: business users see an Okta-style catalog of vetted MCP servers. The system maps each AI agent's permissions directly to the user's existing access levels, preventing privilege escalation. Standing out in a crowded but growing market. MCP's rapid rise has led to a wave of security startups, with companies like Cloudflare, Docker, Wiz, and several early-stage firms launching dedicated tools. However, Runlayer argues that its depth, breadth, and expertise set it apart. The founding team includes experienced engineers from Zapier - Tal Peretz and Vitor Balocco - and is supported by advisors such as Cursor's head of security Travis McPeak and Neon founder Nikita Shamgunov. According to Berman, the speed of MCP adoption has outpaced the safety frameworks that enterprises rely on. That creates an urgent need for solutions that manage risk at scale while preserving agent autonomy. "What we saw was a protocol adopted faster than the security ecosystem could keep up," Berman said. "Enterprises need visibility and guardrails before deploying AI agents into critical systems - and that's what Runlayer is here to solve." Positioned for enterprise AI's next phase. As organizations integrate AI agents into finance, HR, operations, and product systems, securing MCP will become a core requirement. Runlayer's early customer base and high-profile backers signal growing awareness of these risks. If MCP becomes as foundational as APIs or cloud infrastructure, companies like Runlayer could become essential to the next generation of enterprise AI stacks. For now, the startup is betting that a unified security layer - built by early contributors to the ecosystem - will help enterprises adopt AI responsibly and at scale.

TechCrunch
Nov 17th, 2025
MCP AI agent security startup Runlayer launches with 8 unicorns, $11M from Khosla’s Keith Rabois and Felicis | TechCrunch

Three-time founder Andrew Berman is back with a startup that helps IT ensure business users' AI agents operate securely.