AI Security & Control Researcher/Engineer

Apolloresearch

London

On-site

NOK 1,134,000 - 1,890,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Apolloresearch seeks a security & control expert to co-create threat models and robust control protocols for Watcher, an AI-coding agent security product. You will act as an embedded security expert within the product team, driving threat modeling, red-teaming, and security posture improvements while shaping the role's direction.

The role includes threat modeling for coding agents, building a risk-informed library of failure modes, and engaging with customers to translate security needs into

Responsibilities

  • Threat modeling for coding agents under potential misalignment or compromise, including insider-risk like credentials and network access.
  • Design attack trajectories and backtests for monitors and backtesting pipelines.
  • Red-team and improve Watcher's monitors, document findings for product improvements.
  • Own security questionnaire responses, product security whitepapers, and customer-facing incident communications.
  • Improve AppSec standards, container hardening, and vendor security decisions for the product.

Job description

THE OPPORTUNITY

We are building Watcher, a coding agent security product. We are looking for a security & control expert to help us design better threat models and control protocols against AI adversaries, and improve the effectiveness and security of Watcher.

A security & control expert embedded in the product team with three functions:

  1. Research: Supporting Apollo's monitoring research with threat modeling, attack design, red-teaming, and trajectory analysis (~50%),
  2. Expert view: Bring a security expert’s view of what security buyers need to make Watcher a better product (~25%),
  3. Product security: Improve the security posture of Watcher and Apollo's product infrastructure (~25%).

This is truly a “start-up role” in the sense that you have many responsibilities and have significant say in shaping the direction of the role. This is an individual contributor role but could lead to management responsibilities eventually, if desired.

Security support for research (50%)
Threat modeling for coding agents
  • Develop threat models for coding agents under the assumption that they could be misaligned or compromised. This includes near-term threats like AI agents leaking private internal data and long-term threats like agents sabotaging safety research.
  • Treat coding agents through the lens of insider risk: they have credentials, access to code, network access, and the ability to execute arbitrary actions, just like a malicious insider would (see Control agenda).
  • Map out kill chains and attack progressions similar to frameworks like MITRE ATT&CK, adapted for agentic AI. See e.g. the Agentic Loss-of-Control Threat Matrix for an example of a high-quality contribution.
  • Build and maintain our “coding agent security levels” which define what level of robustness Watcher provides against different categories of failure modes. These levels should be concrete, testable, and usable both internally (to guide product priorities) and externally (to communicate our security posture to customers).
Failure mode library and literature
  • Maintain our library of coding agent failure modes and keep it comprehensive, accurate, and current.
  • Stay up to date with the academic and industry literature on coding agent security, AI security, and adjacent fields (prompt injection, deception, accidental security implications, supply chain attacks on AI systems, etc.).
Attack design for monitor development
  • Design realistic attack trajectories and example exploits for monitor development and backtesting, work with the research team to ensure monitors are trained and evaluated against credible adversarial behavior.
Trajectory adjudication
  • Serve as security adjudicator for flagged trajectories. When monitors flag ambiguous agent behavior, determine whether it represents a genuine attack, a benign-but-unusual workflow, or needs deeper investigation, and feed those judgments back into monitor improvement.
Red‑team­ing Watcher
  • Red‑team and improve Watcher's monitors and policies, document findings, and feed them into product improvement.
  • Work with the technical research staff to build adversarial test suites into the backtesting pipeline.
Security expertise for product (25%)
Failure mode prioritization and CISO perspective
  • Understand which failure modes are the biggest problems and prioritise systematically what is most useful to solve for security buyers.
Customer engagement and landscape awareness
  • Join customer/prospect calls to understand security needs firsthand and map them onto the threat models and library of failure modes.
  • Maintain awareness of how enterprises currently secure coding agents (or don't), what tools they use (SIEM, DLP, CSPM), and how Watcher fits into their existing stack.
Customer‑facing security artifacts
  • Own security questionnaire responses, product security whitepapers, and support for customer pen‑tests.
  • Own technical content of customer‑facing communications during incidents.
Improving security posture for product (25%)
Attack surface, infrastructure, and isolation
  • Own AppSec standards for the product engineering team (code review security checklists, dependency scanning, secrets management in CI/CD, container hardening)
  • Own vendor security decisions for product: which SaaS tools can we integrate and what restrictions should we have.
  • Reduce attack surface for all
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Security & Control Researcher
AI Security & Control Researcher

COL Limited • London

Hybrid
NOK 1,716,000 - 3,255,000
Unlimited vacation
Unlimited sick leave
Up to 6 months of paid parental leave
+4
AI Security & Control Researcher
AI Security & Control Researcher

Apolloresearch • London

Hybrid
NOK 1,716,000 - 3,255,000
Flexible work hours
Unlimited vacation
Unlimited sick leave
+7
Product Security Engineer
Product Security Engineer

Apolloresearch • London

On-site
NOK 1,918,000 - 2,511,000
Competitive salary
Equity
Flexible hours
+6
AI Security & Control Architect - Research Engineer
AI Security & Control Architect - Research Engineer

Apolloresearch • London

On-site
NOK 1,134,000 - 1,890,000
AI Red Team Engineer
AI Red Team Engineer

Apolloresearch • London

On-site
NOK 1,539,000 - 2,019,000
Equity
Competitive benefits
Relocation and visa sponsorship
+1
Full-stack Software Engineer (Product)
Full-stack Software Engineer (Product)

COL Limited • London

On-site
NOK 1,890,000 - 2,474,000
Equity
Flexible hours
Unlimited vacation
+3
AI Threat Modeling & Security Researcher
AI Threat Modeling & Security Researcher

COL Limited • London

Hybrid
NOK 1,716,000 - 3,255,000
Unlimited vacation
Unlimited sick leave
Up to 6 months of paid parental leave
+4
Full-stack Software Engineer (Product)
Full-stack Software Engineer (Product)

Apolloresearch • London

Hybrid
NOK 1,124,000 - 1,685,000
Market competitive salary and equity
Unlimited vacation
Comprehensive health, dental andVision
+2
AI Threat Modeling & Security Researcher for Coding Agents
AI Threat Modeling & Security Researcher for Coding Agents

Apolloresearch • London

Hybrid
NOK 1,716,000 - 3,255,000
Flexible work hours
Unlimited vacation
Unlimited sick leave
+7
Forward Deployed Engineer (Product)
Forward Deployed Engineer (Product)

COL Limited • London

On-site
NOK 1,779,000 - 2,715,000
Flexible work hours
Unlimited vacation
Relocation support
+2