At a Glance
- Tasks: Join us to enhance AI security and develop innovative threat models for our cutting-edge product.
- Company: Dynamic tech start-up focused on AI security with a collaborative culture.
- Benefits: Competitive salary, unlimited vacation, flexible hours, and professional development budget.
- Other info: Exciting growth opportunities in a fast-paced environment with potential for management roles.
- Why this job: Make a real impact in AI security while shaping the future of our product.
- Qualifications: 5+ years in security roles with hands-on technical experience and strong communication skills.
The predicted salary is between 135000 - 200000 £ per year.
We are building Watcher, a coding agent security product. We are looking for a security & control expert to help us design better threat models and control protocols against AI adversaries, and improve the effectiveness and security of Watcher.
A security & control expert embedded in the product team with three functions:
- Research: Supporting Apollo's monitoring research with threat modeling, attack design, red‑team, and trajectory analysis (~50%).
- Expert view: Bring a security expert’s view of what security buyers need to make Watcher a better product (~25%).
- Product security: Improve the security posture of Watcher and Apollo's product infrastructure (~25%).
This is truly a “start‑up role” in the sense that you have many responsibilities and have significant say in shaping the direction of the role. It is an individual contributor role but could lead to management responsibilities eventually, if desired.
Security support for research (50%)
- Threat modeling for coding agents: Develop threat models for coding agents under the assumption that they could be misaligned or compromised. This includes near‑term threats, such as AI agents leaking private internal data, and long‑term threats, such as agents sabotaging safety research.
- Failure mode library and literature: Maintain our library of coding agent failure modes and keep it comprehensive, accurate, and current. Stay up to date with the academic and industry literature on coding agent security, AI security, and adjacent fields.
- Attack design for monitor development: Design realistic attack trajectories and example exploits for monitor development and backtesting, working with the research team to ensure monitors are trained and evaluated against credible adversarial behavior.
- Trajectory adjudication: Serve as security adjudicator for flagged trajectories. When monitors flag ambiguous agent behavior, determine whether it represents a genuine attack, a benign‑but‑unusual workflow, or needs deeper investigation.
- Red‑teaming Watcher: Red‑team and improve Watcher's monitors and policies, document findings, and feed them into product improvement.
Security expertise for product (25%)
- Failure mode prioritization and CISO perspective: Understand which failure modes are the biggest problems and prioritise systematically what is most useful to solve for security buyers.
- Customer engagement and landscape awareness: Join customer/prospect calls to understand security needs firsthand and map them onto the threat models and library of failure modes.
- Customer‑facing security artifacts: Own security questionnaire responses, product security whitepapers, and support for customer pen‑tests.
Improving security posture for product (25%)
- Attack surface, infrastructure, and isolation: Own AppSec standards for the product engineering team. Reduce attack surface for all product‑related deployments.
- Data handling and multi‑tenancy: Define security requirements for tenant isolation, encryption at rest/in transit, access controls, and data retention policies for customer coding agent transcripts.
- Product threat model and incident response: Co‑own the product‑specific threat model with the product team lead and keep it up to date.
Development tasks:
- Develop a comprehensive coding agent threat model.
- Improve our database of failure modes.
- Prioritize failure modes that Watcher should cover.
- Design a security roadmap for keeping customer data for Watcher secure.
Must‑haves:
- 5+ years in security roles in a hands‑on technical capacity.
- Engineering mindset – treat security as an engineering problem.
- Direct experience with application, cloud or product security.
- Strong understanding of enterprise security buyer concerns.
- Comfortable working in a small, fast‑moving team.
- Strong written communication.
Strong nice‑to‑haves:
- Experience with AI/ML systems security, LLM security, or AI control research.
- Detection engineering, SOC, or incident analysis experience.
- Familiarity with insider threat programs or frameworks.
- Red‑teaming or offensive security background.
Benefits:
- Market competitive salary, equity, and competitive benefits.
- Flexible work hours and schedule.
- Unlimited vacation and sick leave.
- Comprehensive health, dental and vision insurance.
- Retirement savings with competitive employer matching.
- Paid work trips, including staff retreats, business trips, and relevant conferences.
- A yearly $1,000 (USD) professional development budget.
- Relocation support and visa fees (if applicable).
Time Allocation: Full‑time
Location: In‑person role working out of London or San Francisco office. Flexible working hours and some WFH arrangements.
Visa Sponsorship: We sponsor visas in both the UK and US.
Equality Statement: Apollo Research is an Equal Opportunity Employer. We value diversity and are committed to providing equal opportunities to all.
AI Security & Control Engineer in London employer: Apolloresearch
Apollo Research is an exceptional employer, offering a dynamic work environment in either London or San Francisco, where you can contribute to groundbreaking AGI safety research. With flexible working hours, unlimited vacation, and a strong emphasis on employee growth through professional development budgets, we foster a culture of collaboration and innovation. Our commitment to diversity and inclusion ensures that every team member feels valued and empowered to make a meaningful impact.
StudySmarter Expert Advice🤫
We think this is how you could land AI Security & Control Engineer in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Apolloresearch, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Apolloresearch
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Apolloresearch. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace AI Security & Control Engineer in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Apolloresearch insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Apolloresearch that you’re committed to staying ahead in the game.
How to prepare for a job interview at Apolloresearch
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Apolloresearch to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Apolloresearch.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.