Agentic AI Security Engineer

Howard Hughes Medical Institute

Ashburn (VA)

On-site

USD 149,000 - 264,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Howard Hughes Medical Institute is seeking a security engineer to design and operate the safetystack for agentic AI at Janelia, ensuring safe execution of agent code on OpenShift and HPC platforms.

You will implement sandboxing, guardrails, and full observability with auditable sessions, while contributing to foundational architecture decisions and open-sourcing efforts.

Qualifications

  • Hands-on experience operating LLM agents and dealing with their failures or deep sandbox/container-security expertise.
  • Linux and Kubernetes/OpenShift isolation depth with precise understanding of containerization vs sandboxing.
  • Knowledge of agent architectures: tool-calling protocols, approval gates, judge models, guardrail frameworks.
  • Open-source contributions, publications, or production systems you can discuss in depth.
  • Minimum 5 years in security, systems/SRE, or ML systems engineering.

Responsibilities

  • Research, develop, deploy, operate, and analyze the safetystack for agentic AI at Janelia.
  • Design sandboxed, reproducible execution environments with kernel- and VM-level isolation.
  • Implement guardrails and observability, with audit logging and post-incident analysis.

Skills

Sandboxing
Security engineering
LLM agent experience
Kubernetes/OpenShift
Adversarial testing
Observability

Education

Bachelor's degree in a relevant field

Tools

OpenShift
Kubernetes
Linux
HPC cluster

Job description

Primary Work Address: 19700 Helix Drive, Ashburn, VA, 20147

AI@HHMI at Janelia integrates AI agents across the researchprocess. These tools write and execute code, optimize experimentaland model parameters, and drive instruments.

Letting AI agents act on shared research infrastructure requiresserious safety engineering. The relevant failure mode is usuallynot a malicious attacker but a capable, misdirected tool runningwith legitimate user permissions at machine speed: hallucinatedcommands, instructions hijacked by retrieved content, runawayloops, sandbox escapes. We are hiring the engineer who owns thisproblem.

The role

You will research, develop, deploy, operate, and analyze the safetystack for agentic AI at Janelia:

  • Sandboxing. Hardened, reproducible executionenvironments for agent code (kernel- and VM-level isolation,network egress control) on our OpenShift platform and HPC cluster,validated by adversarial testing.
  • Guardrails. Policy enforcement on agent inputs, outputs,and tool calls; judge models; human approval gates; independentsafeguard services that sessions can be routed through,individually or chained.
  • Observability. Attributable audit logging, full-tracecapture, real-time monitoring, and post-incident analysis of agentsessions.

You will join early enough to make the foundational architecturedecisions, and you will operate what you design. We expect andsupport open-sourcing and publishing this work.

The environment

A large NVIDIA GPU cluster (B300/H200/H100 class) runningself-hosted open-weight models and frontier commercial models;collaborations with industry (Anthropic and Google); scientistsacross biology, physics, and ML as your users; the long-termstability of a philanthropy-funded research institute.

What we look for
  • Hands-on experience operating LLM agents and dealing with theirfailures, or deep sandbox/container-security expertise with clearability to move into the agentic domain.
  • Linux and Kubernetes/OpenShift isolation depth, including aprecise understanding of the difference between containerizationand sandboxing.
  • Working knowledge of agent architectures: tool-callingprotocols (e.g., MCP), approval gates, judge models, guardrailframeworks, and the limits of each.
  • Evidence over certifications: open-source contributions,publications or technical writing, disclosed findings, orproduction systems you can discuss in depth.
  • Minimum 5 years in security, systems/SRE, or ML systemsengineering.
Physical Requirements

Remaining in a normal seated or standing position for extendedperiods of time; reaching and grasping by extending hand(s) orarm(s); dexterity to manipulate objects with fingers, for exampleusing a keyboard; communication skills using the spoken word;ability to see and hear within normal parameters; ability to moveabout workspace. The position requires mobility, including theability to move materials weighing up to several pounds (such as alaptop computer or tablet).

Persons with disabilities may be able to perform the essentialduties of this position with reasonable accommodation. Requests forreasonable accommodation will be evaluated on an individualbasis.

Please Note:

This job description sets forth the job’s principal duties, responsibilities, and requirements; it should not be construed as an exhaustive statement, however. Unless they begin with the word "may", the Essential Duties and Responsibilities described above are “essential functions” of the job, as defined by the Americanswith Disabilities Act.

Hiring Pay Range

Agentic AI Security Engineer: $149,084.80 - $186,356.00

Agentic AI Security Senior Engineer: $181,143.20 -$226,429.00

Agentic AI Security Principal Engineer: $210,803.20 -$263,504.00

Pay Type

Salary

The posted range reflects HHMI’s good faith estimate of the anticipated hiring salary range for this role at the time ofposting. Actual hiring compensation is determined by a candidate’s qualifications, experience, and internal equity.

Compensation and Benefits

Our employees are compensated from a total rewards perspective in many ways for their contributions to our mission, including competitive pay, exceptional health benefits, retirement plans, time off, and a range of recognition and wellness programs. Visitour Benefits atHHMI site to learn more.

HHMI is an Equal Opportunity Employer

We use E-Verify to confirm the identity and employment eligibility of all new hires.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Agentic AI Security Engineer
Agentic AI Security Engineer

Howard Hughes Medical Institute (HHMI) • United States

On-site
USD 149,000 - 264,000
Health benefits
Retirement plans
Time off
+1
Agentic AI Security Engineer
Agentic AI Security Engineer

Howard Hughes Medical Institute (HHMI) • Ashburn (VA), Northern (KY)

On-site
USD 149,000 - 186,000
Health benefits
AI Scientist – Computational Chemistry
AI Scientist – Computational Chemistry

Howard Hughes Medical Institute (HHMI) • Ashburn (VA)

On-site
USD 182,000 - 450,000
Comprehensive health and welfare benefits
Generous training and travel opportunities
On-site childcare
+2
Principal Agentic AI Security Engineer
Principal Agentic AI Security Engineer

AbbVie • North Chicago (IL)

On-site
USD 141,000 - 269,000
Agentic Engineer - Security, US Amazon Dedicated Cloud Security
Agentic Engineer - Security, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Arlington (VA)

On-site
USD 168,000 - 227,000
Agentic Engineer - Security, US Amazon Dedicated Cloud Security
Agentic Engineer - Security, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Jessup (MD)

On-site
USD 168,000 - 227,000
RSUs
Health insurance
401(k) matching
+2
AI Security Engineer
AI Security Engineer

AlignityX • McLean (VA)

On-site
USD 100,000 - 200,000
Agentic Engineer - Security, US Amazon Dedicated Cloud Security
Agentic Engineer - Security, US Amazon Dedicated Cloud Security

Amazon Web Services (AWS) • Herndon (VA)

On-site
USD 168,000 - 227,000
Health insurance
401(k) matching
Paid time off
+1
Agentic AI Security Engineer: Sandbox & Guardrails
Agentic AI Security Engineer: Sandbox & Guardrails

Howard Hughes Medical Institute (HHMI) • Ashburn (VA), Northern (KY)

Hybrid
USD 149,000 - 186,000
Health benefits
Staff Software Engineer, Applied AI
Staff Software Engineer, Applied AI

hackerone • Boston (MA)

On-site
USD 230,000 - 280,000
Health insurance
Equity stock options
Unlimited PTO
+1