Back to sponsored jobs

Visa sponsorship advertised

AI Security Researcher - Sponsorship Available

London & San FranciscoInfrastructure & SecurityFull-time
Employer locked

Role overview

THE OPPORTUNITY the hiring employer works with most frontier AI companies (OpenAI, Anthropic, Google, Meta, Thinking Machines and others) to test their models before deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprise.  Security exists at Apollo to safeguard the trust frontier labs place in us and to enable that research. Our own team uses AI agents extensively across its work, which makes Apollo both a target and a testbed. We’re hiring AI Security Researchers to join the Infra & Security Team.  In this role, you will identify, research and remediate both conventional threats and the novel risks introduced by AI agents that can affect Apollo and our mission. You will redefine and work on a new class of insider risk that didn’t exist before.  RESPONSIBILITIES Hold responsibility for the security of Apollo’s internal surfaces. Red-team internal software, infrastructure, and AI agent access controls/monitoring. Build realistic attack trajectories. Design solutions for novel or emerging threats in the AI security space, where no existing playbook applies. Set the standard for our security posture in these areas. Track adversary tactics, techniques, and campaigns relevant to Apollo's threat landscape, and translate that intelligence into tuned, high-signal detections. Own each finding through to a deployed fix. Build and roll out durable controls: checks, tests, defaults, detections. Socialise them, work with engineers to implement, and hold remediation to a high bar. KEY REQUIREMENTS Must haves 5+ years in security roles in a hands-on technical capacity (not purely GRC/compliance). You'd need to be able to think structurally about threat modelling and failure modes. You need to be able to read code, understand infrastructure, and evaluate technical controls. Direct experience with offensive security. Threat modelling, red teaming, etc. Knowledge of application or cloud. Ideally you owned or significantly contributed to the security posture of an organisation or product that handles sensitive customer data. Engineering mindset. You treat security as an engineering problem. You can translate your findings into fixes and controls, such as paved roads, custom detection rules, adversarial test suites, CI/CD integrations. You prioritize automation and systems-level thinking to scale security, and you are comfortable leveraging AI to accelerate development. Startup pace. You are excited about a fast-moving environment, comfortable with ambiguity and changing priorities, and willing to grind when it matters. Strong written communication. This role produces a lot of artifacts (threat models, reports, failure mode documentation) and they need to be clear and precise. Nice to haves Experience with AI/ML systems security or LLM security. Detection engineering, SOC, or incident analysis experience. Familiarity with insider threat programs or insider risk frameworks. Explicitly not required Formal AI safety research background. We need security practitioners who can learn the AI safety context, not AI safety researchers who need to learn security. We want to emphasize that people who feel they don’t fulfill all of these characteristics but think they would be a good fit for the position, nonetheless, are strongly encouraged to apply. REPRESENTATIVE PROJECTS Red-team Apollo's agent sandboxes used for evals: Test whether an agent can escape isolation, exfiltrate data, detect it's being evaluated, or otherwise undermine the validity of eval results. Your findings will harden the sandbox infrastructure the research team depends on to trust its own eval results. Comprehensive coding agent threat model : Map every way a coding agent with internal access: credentials, code, network, execution ability, could attack Apollo, benchmarked against what a human insider with the same access could do. As well as the representative projects from the Security Engineer role BENEFITS This role offers market competitive salary, equity, and competitive benefits. Salary: San Francisco : $214,000 – $280,000; London : £144,000 – £189,000. We will be looking to meaningfully raise salaries soon. Our engineers effectively have an unlimited token budget. If a better result costs more compute, use it. Flexible work hours and schedule Unlimited vacation Unlimited sick leave Up to 6 months of paid parental leave Comprehensive health, dental and vision insurance Retirement savings with competitive employer matching (e.g. 401(k) for US employees) Lunch, dinner, and snacks are provided for all employees on workdays Paid work trips, including staff retreats, business trips, and relevant conferences A yearly $1,000 (USD) professional development budget Relocation support and visa fees (if applicable) LOGISTICS Time Allocation: Full-time Location: This is an in-person role working out of our London or San Francisco office. We offer flexible working hours and some wfh arrangements. Visa sponsorship: We sponsor visas in both the UK and US. Sponsorship isn't guaranteed for every role or candidate, but if we make you an offer, we'll work with you to find the right visa route. ABOUT THE TEAM The Infra and Security team is currently led by Rusheb Shah and consists of Glen Rodgers and Steven Lee. You will work closely with Security Engineers we’re hiring for as well as technical staff from the Scheming Research and Product team. You can find our full team here. ABOUT the hiring employer The rapid rise in AI capabilities offers tremendous opportunities, but also presents significant risks. , we're primarily concerned with risks from Loss of Control, i.e. risks coming from the model itself rather than e.g. humans misusing the AI. We're particularly concerned with deceptive alignment / scheming, a phenomenon where a model appears to be aligned but is, in fact, misaligned and capable of evading human oversight.  We work on the science of scheming, detection of scheming (e.g. building evaluations), and scheming mitigations (e.g. anti-scheming). We also work on control and monitoring research (see our scalable monitoring agenda). We work closely with many frontier AI companies, such as OpenAI, Anthropic, Google, Meta, Thinking Machines and others, e.g. to test their models and collaborate on the science of scheming. At Apollo, we aim for a culture that emphasizes truth-seeking, being goal-oriented, giving and receiving constructive feedback, and being friendly and helpful. If you're interested in more details about what it's like working at Apollo, you can find more information here. We also build a coding agent security product called Watcher that secures agent deployments in companies. Our goal is to reduce the probability of catastrophic incidents by securing coding agents, learning about their real-world risks, and publishing our research on how to build these control systems most effectively. Equality Statement: the hiring employer is an Equal Opportunity Employer. We value diversity and are committed to providing equal opportunities to all, regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, or sexual orientation. HOW TO APPLY Please complete the application form with your CV. The provision of a cover letter is neither required nor encouraged. Please also feel free to share links to relevant work samples. About the interview process: Our multi-stage process includes a screening interview, a take-home test (approx. 2-3 hours), 3 technical interviews, and a final interview with Marius (CEO). There are no leetcode-style general coding interviews. You may use AI tools on the take-home; we judge the result the way we'd judge any contributor's work, so you are responsible for the quality of everything you submit. Your Privacy and Fairness in Our Recruitment Process: We are committed to protecting your data, ensuring fairness, and adhering to workplace fairness principles in our recruitment process. To enhance hiring efficiency, we use AI-powered tools to assist with tasks such as resume screening. These tools are designed and deployed in compliance with internationally recognized AI governance frameworks. Your personal data is handled securely and transparently. All resumes are screened by a human and final hiring decisions are made by our team. If you have questions about how your data is processed or wish to report concerns about fairness, please contact us at [employer contact hidden].

Key details to check

  • The advertised location is London & San Francisco.
  • The salary was not clearly stated in the data we received, so confirm it before applying.
  • The role is listed as Full-time.

Tailor your application to the duties shown in the vacancy. Use specific examples of relevant experience, qualifications and measurable results rather than sending the same CV to every employer.

Sponsorship information

This vacancy advertised visa sponsorship when SLC last reviewed it. Check the statement below, then compare the role, salary and requirements with the visa route you need.

“Visa sponsorship: We sponsor visas in both the UK and US.”
Evidence checked 3 Oct 2026

Vacancy wording can change or a role can close. Confirm the sponsorship statement and your own eligibility on the employer’s application page before applying.

Search the UK sponsor register

Frequently asked questions

Does this AI Security Researcher job offer visa sponsorship?

The vacancy advertised visa sponsorship when SLC reviewed it on 3 Oct 2026. Sponsorship is never automatic: the employer must still decide that the candidate, role, salary and visa route meet its requirements.

Where is this AI Security Researcher role based?

The vacancy is listed in London & San Francisco. Check the original application page for the exact workplace, remote-working arrangements and any relocation requirements.

What should I check before applying for this sponsored job?

Compare your experience with the duties, check the salary and working hours, confirm the employer is still accepting applications, and make sure the role can fit the visa route you need. A sponsorship statement in an advert does not guarantee an offer or a visa.

How do I apply for this AI Security Researcher vacancy?

Select Apply for this job to unlock the hiring employer and its direct application page. A 99p pass provides access to all current SLC job links for 24 hours and does not renew automatically.