×
Register Here to Apply for Jobs or Post Jobs. X

AI Security Researcher

Job in San Francisco, San Francisco County, California, 94102, USA
Listing for: Apollo Research
Full Time position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, AI Engineer (Applied/Software), Security Management & Operations, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 214000 - 280000 USD Yearly USD 214000.00 280000.00 YEAR
Job Description & How to Apply Below

AI Security Researcher

Apollo Research works with most frontier AI companies to test their models before deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprise.

Security exists at Apollo to safeguard the trust frontier labs place in us and to enable that research. Our own team uses AI agents extensively across its work, which makes Apollo both a target and a testbed. We're hiring AI Security Researchers to join the Infra & Security Team.

In this role, you will identify, research and remediate both conventional threats and the novel risks introduced by AI agents that can affect Apollo and our mission. You will redefine and work on a new class of insider risk that didn't exist before.

Responsibilities

  • Hold responsibility for the security of Apollo's internal surfaces. Red-team internal software, infrastructure, and AI agent access controls/monitoring. Build realistic attack trajectories.
  • Design solutions for novel or emerging threats in the AI security space, where no existing playbook applies. Set the standard for our security posture in these areas.
  • Track adversary tactics, techniques, and campaigns relevant to Apollo's threat landscape, and translate that intelligence into tuned, high-signal detections.
  • Own each finding through to a deployed fix. Build and roll out durable controls: checks, tests, defaults, detections. Socialise them, work with engineers to implement, and hold remediation to a high bar.

Key Requirements

Must Haves
  • 5+ years in security roles in a hands-on technical capacity (not purely GRC/compliance). You'd need to be able to think structurally about threat modelling and failure modes. You need to be able to read code, understand infrastructure, and evaluate technical controls.

  • Direct experience with offensive security. Threat modelling, red teaming, etc. Knowledge of application or cloud. Ideally you owned or significantly contributed to the security posture of an organisation or product that handles sensitive customer data.

  • Engineering mindset. You treat security as an engineering problem. You can translate your findings into fixes and controls, such as paved roads, custom detection rules, adversarial test suites, CI/CD integrations. You prioritize automation and systems-level thinking to scale security, and you are comfortable leveraging AI to accelerate development.

  • Startup pace. You are excited about a fast-moving environment, comfortable with ambiguity and changing priorities, and willing to grind when it matters.

  • Strong written communication. This role produces a lot of artifacts (threat models, reports, failure mode documentation) and they need to be clear and precise.

Nice to Haves
  • Experience with AI/ML systems security or LLM security.

  • Detection engineering, SOC, or incident analysis experience.

  • Familiarity with insider threat programs or insider risk frameworks.

Explicitly Not Required
  • Formal AI safety research background. We need security practitioners who can learn the AI safety context, not AI safety researchers who need to learn security.

Representative Projects

  • Red-team Apollo's agent sandboxes used for evals:
    Test whether an agent can escape isolation, exfiltrate data, detect it's being evaluated, or otherwise undermine the validity of eval results. Your findings will harden the sandbox infrastructure the research team depends on to trust its own eval results.

  • Comprehensive coding agent threat model:
    Map every way a coding agent with internal access: credentials, code, network, execution ability, could attack Apollo, benchmarked against what a human insider with the same access could do.

Benefits

  • This role offers market competitive salary, equity, and competitive benefits.

  • Salary:
    San Francisco: $214,000 – $280,000;
    London: £144,000 – £188,000

  • Our engineers effectively have an unlimited token budget. If a better result costs more compute, use it.

  • Flexible work hours and schedule

  • Unlimited vacation

  • Unlimited sick leave

  • Up to 6 months of paid parental leave

  • Comprehensive health, dental and vision…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary