Get more replies from employers
Send a job-specific resume in minutes.
Refractal in London seeks a founding AI Security Engineer/Researcher to break agentic systems, develop repeatable evaluations, and shape our security roadmap. You will work directly with the founders and early customers, turning insights into production safeguards and policy controls.
You will build exploit chains, automate adversarial testing, and contribute to public research while growing into senior technical leadership. Visa sponsorship and equity accompany a competitive package.
Refractal is building security infrastructure for autonomy. Our founding team combines technical pedigree from MIT, NASA, Microsoft, and government with commercial experience in VC and startups. We have also been recognised by MIT's flagship CSAIL AI lab as part of CSAIL Alliances, as well as being selected for Google's highly selective Gemini Cybersecurity Startup Forum.
We are today working with leading startups and a European government to secure their AI deployments. This role is an opportunity to join an ambitious, fast-paced startup at the very earliest stages.
For most of the last decade, AI safety and security lived inside the frontier labs. They were the only ones thinking seriously about how those systems fail, get manipulated, or behave in ways they did not intend.
This is no longer the case. 2026 has become the year of AI Security; every company serious about deploying AI is now facing real adversaries in production, with real data and consequences. At the same time, the risks have moved beyond the model(s) themselves: agents are being given credentials, tools, and decision-making authority faster than governance or security can catch up. Advanced prompt injection, goal hijacking, tool misuse, multi-agent collusion, and agentic data exfiltration — all of these are happening today.
The frontier labs are focused on securing their own models, and traditional cyber companies are not built for this problem. The deployment layer is unclaimed. There is an opportunity to build a category-defining infrastructure company for secure autonomy.
Your job is to break agentic systems before adversaries do, and turn what you learn into repeatable evaluations, customer insights, and production security controls.
You will work directly with the founders and our earliest customers. Your research will materially influence both our product roadmap and how consequential AI systems are deployed.
You have an adversarial mindset and a builder's instinct. When you encounter a new system, you naturally ask where its assumptions break, what it trusts, and how those trust relationships could be exploited. You are interested in AI security as a systems discipline. You understand that the most consequential failures can emerge from the agent harness and specific use case.
You enjoy research, but only when grounded in real-world application. You can move fluently from an ambiguous attack hypothesis to a working proof of concept.
Most importantly, you want to help create the security foundations that allow autonomous systems to be deployed safely at scale.
We care more about demonstrated ability than a particular credential or number of years in industry.
Particularly strong signals include:
We do not expect any candidate to have worked across all of these areas.