At a Glance
- Tasks: Join us to enhance AI security and develop innovative threat models for our cutting-edge product.
- Company: Dynamic tech start-up focused on AI security with a collaborative culture.
- Benefits: Competitive salary, unlimited vacation, flexible hours, and professional development budget.
- Other info: Exciting growth opportunities in a fast-paced environment.
- Why this job: Make a real impact in AI security while shaping the future of our product.
- Qualifications: 5+ years in hands-on security roles with strong technical skills.
The predicted salary is between 135000 - 200000 £ per year.
We are building Watcher, a coding agent security product. We are looking for a security & control expert to help us design better threat models and control protocols against AI adversaries, and improve the effectiveness and security of Watcher.
A security & control expert embedded in the product team with three functions:
- Research: Supporting Apollo's monitoring research with threat modeling, attack design, red‑team, and trajectory analysis (~50%).
- Expert view: Bring a security expert’s view of what security buyers need to make Watcher a better product (~25%).
- Product security: Improve the security posture of Watcher and Apollo's product infrastructure (~25%).
This is truly a “start‑up role” in the sense that you have many responsibilities and have significant say in shaping the direction of the role. It is an individual contributor role but could lead to management responsibilities eventually, if desired.
Security support for research (50%):
- Threat modeling for coding agents: Develop threat models for coding agents under the assumption that they could be misaligned or compromised. This includes near‑term threats, such as AI agents leaking private internal data, and long‑term threats, such as agents sabotaging safety research.
- Failure mode library and literature: Maintain our library of coding agent failure modes and keep it comprehensive, accurate, and current. Stay up to date with the academic and industry literature on coding agent security, AI security, and adjacent fields.
- Attack design for monitor development: Design realistic attack trajectories and example exploits for monitor development and backtesting, working with the research team to ensure monitors are trained and evaluated against credible adversarial behaviour.
- Trajectory adjudication: Serve as security adjudicator for flagged trajectories. When monitors flag ambiguous agent behaviour, determine whether it represents a genuine attack, a benign‑but‑unusual workflow, or needs deeper investigation.
- Red‑teaming Watcher: Red‑team and improve Watcher's monitors and policies, document findings, and feed them into product improvement.
Security expertise for product (25%):
- Failure mode prioritization and CISO perspective: Understand which failure modes are the biggest problems and prioritise systematically what is most useful to solve for security buyers.
- Customer engagement and landscape awareness: Join customer/prospect calls to understand security needs firsthand and map them onto the threat models and library of failure modes.
- Customer‑facing security artifacts: Own security questionnaire responses, product security whitepapers, and support for customer pen‑tests.
Improving security posture for product (25%):
- Attack surface, infrastructure, and isolation: Own AppSec standards for the product engineering team. Reduce attack surface for all product‑related deployments.
- Data handling and multi‑tenancy: Define security requirements for tenant isolation, encryption at rest/in transit, access controls, and data retention policies for customer coding agent transcripts.
- Product threat model and incident response: Co‑own the product‑specific threat model with the product team lead and keep it up to date.
Development tasks:
- Develop a comprehensive coding agent threat model.
- Improve our database of failure modes.
- Prioritize failure modes that Watcher should cover.
- Design a security roadmap for keeping customer data for Watcher secure.
Must‑haves:
- 5+ years in security roles in a hands‑on technical capacity.
- Think structurally about threat modeling and failure modes.
- Direct experience with application, cloud or product security.
- Strong understanding of enterprise security buyer concerns.
- Comfortable working in a small, fast‑moving team.
- Strong written communication.
Strong nice‑to‑haves:
- Experience with AI/ML systems security.
- Detection engineering, SOC, or incident analysis experience.
- Red‑teaming or offensive security background.
Benefits:
- Market competitive salary, equity, and competitive benefits.
- Flexible work hours and schedule.
- Unlimited vacation and sick leave.
- Comprehensive health, dental and vision insurance.
- Retirement savings with competitive employer matching.
- Paid work trips, including staff retreats and relevant conferences.
- A yearly $1,000 professional development budget.
- Relocation support and visa fees (if applicable).
Time Allocation: Full‑time
Location: In‑person role working out of London or San Francisco office. Flexible working hours and some WFH arrangements.
Visa Sponsorship: We sponsor visas in both the UK and US.
Equality Statement: Apollo Research is an Equal Opportunity Employer. We value diversity and are committed to providing equal opportunities to all.
AI Security & Control Engineer employer: Apolloresearch
Apollo Research is an exceptional employer, offering a dynamic work environment in either London or San Francisco, where you can contribute to groundbreaking AGI safety research. With flexible working hours, unlimited vacation, and a strong emphasis on employee growth through professional development budgets, we foster a culture of collaboration and innovation. Our commitment to diversity and inclusion ensures that every team member feels valued and empowered to make a meaningful impact.