AI Engineer
Full-time Hybrid (Antwerp, Belgium)Job Details
As an AI Engineer, you’ll work closely with the founders and our R&D team on XFA’s next security layer: securing AI agents on the devices companies don’t control. AI agents now read files, call tools, and act on company data from personal laptops, contractor machines, and other unmanaged devices. You’ll help give every agent a verifiable identity tied to a human sponsor, grant it only the authority its task needs, detect when it is manipulated or goes off script, and do all of that without invading the user’s privacy.
This role is perfect for an experienced engineer at the intersection of AI and security engineering. You understand how large language models and agents work under the hood, and you’re just as comfortable reasoning about threat models, key management, and hardware-backed security such as secure enclaves and TPMs. You’ll work across on-device services, our cloud platform, and our AI tooling, including our MCP server.
This position is a unique opportunity to help define how AI agents are secured in the real world, from research all the way to production.
About XFA
XFA is a growing Belgian start-up that creates game-changing cybersecurity technology to protect users and businesses around the world.
While legacy technologies rely on complexity to secure devices, XFA automatically finds all unknown and unsafe devices, and blocks them at login to ensure device security — without intrusive device control.
As we continue to expand, we’re looking for ambitious people to join us in shaping the future of cybersecurity.
Responsibilities
- Design and build identity and authentication for AI agents: short-lived credentials tied to a human sponsor and bound to the agent’s process with hardware-backed keys (Secure Enclave, TPM 2.0).
- Develop policy-based authorization and delegation for agents, so authority narrows at every step when one agent hands work to another and never exceeds what the task needs.
- Build on-device enforcement where agents actually act, starting with MCP tool calls, with low-latency local decisions that don’t break the user’s workflow.
- Detect threats to and from AI agents: unknown agents, behavior that drifts from an agent’s expected scope, and prompt injection or tampering in inputs, system prompts, memory, and retrieved data, including multimodal content.
- Design privacy-preserving AI pipelines: on-device processing first, filtering personal data before it leaves the device, and confidential computing with remote attestation (e.g. AMD SEV-SNP, Intel TDX, AWS Nitro Enclaves) where server-side processing is unavoidable.
- Apply LLMs where they genuinely add value, such as risk assessment and clear, user-tailored security guidance, choosing between prompting, retrieval-augmented generation, fine-tuning, and small local models based on accuracy, latency, and cost.
- Build evaluation pipelines, attack simulations, and automated tests that measure detection quality and keep AI output reliable in production.
- Keep up with the fast-moving landscape of AI agents, emerging attacks, and standards, and turn that knowledge into product.
Requirements
- Several years of experience shipping production software in Golang, Python, Typescript, or a systems language such as Rust or C++.
- A solid understanding of how LLMs and AI agents work: tokens and context windows, embeddings, tool calling, agent orchestration, and the strengths and limitations of different models.
- Hands-on experience building with LLMs (e.g. Claude, GPT, Gemini, or open-weight models), agent frameworks, or the Model Context Protocol (MCP).
- A strong security engineering background: threat modeling, secure system design, applied cryptography, and authentication and authorization protocols (e.g. OAuth 2.0, OpenID Connect, JWT).
- Working knowledge of hardware-backed security: secure enclaves, TPMs, platform key stores, confidential computing, and remote attestation.
- A good grasp of AI-specific attacks, such as prompt injection, data poisoning, and memory or instruction tampering, and how to defend against them.
- A pragmatic, measurement-driven mindset: you know how to evaluate AI output and don’t trust a demo that only works once.
- Excellent communication skills, both asynchronous and synchronous, and comfortable working independently and proactively in a fast-moving start-up.
- Experience with OS internals or endpoint security on macOS or Windows (e.g. Endpoint Security framework, ETW, eBPF) is a strong plus.
- Experience with policy-as-code (e.g. Cedar, OPA), workload identity (e.g. SPIFFE/SPIRE), or privacy-enhancing technologies is a plus.
- Fluent in English; other European languages (e.g., French, German, Dutch) are a plus.
What we offer
- Working in a motivated team, dreaming big.
- Transparency and open communication.
- A high-growth environment with exposure to international markets and industry-leading clients.
- Flexibility in both directions, the results of the work are what is important.
- Work on cutting-edge technology, implementing the latest in AI and Cryptography.
- The opportunity to be part of a fast-growing start-up where you can help shape the company’s future — supported by a collaborative, ambitious team that celebrates wins and encourages growth.
- An attractive salary package, including company insurance, meal vouchers, commute coverage, and a 13th month in accordance with Belgian employment law.