# Security Engineer (AI Red Team)

[Refractal](https://gurify.com/jobs?q=Refractal) · London · Posted yesterday

[AI & ML](https://gurify.com/jobs/ai-ml)

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/refractal/48843164-d3d5-4fa6-8b36-decb75932a08)

## Job description

### ABOUT REFRACTAL

Refractal is an AI security company building the infrastructure organisations need to defend against autonomous AI threats. 2026 has shown that generally capable intelligence is here. The challenge now is modernising security to stop AI-enabled threats, whether they come from internal agents going rogue or from attackers using AI to become more dangerous.

Refractal was founded on cybersecurity and AI expertise from MIT, Microsoft, NASA and the U.S. Navy. Our product lets organisations detect AI-enabled threats at low cost without sacrificing detection quality. We take a practical approach to AI risk, combining proven cybersecurity methods with frontier AI security research.

Today, we work with governments and organisations that can't afford to get security wrong. We're backed by leading deep-tech and cybersecurity investors and are growing the team to deliver on this mission.

### THE ROLE

You'll test how deployed AI systems and agents fail under adversarial pressure. You'll run authorised, controlled security assessments, show what each finding means in practice, and work with our engineering and research teams to turn findings into stronger defences and repeatable tests.

### WHAT YOU'LL DO

- Design and execute assessments of AI applications and agents, grounded in realistic attacker goals and clearly defined test scope.

- Test realistic threats such as indirect prompt injection, misuse of connected tools, sensitive data exposure and attempts to cross permission boundaries.

- Build reproducible test cases and small testing tools that demonstrate security impact and distinguish reliable failures from one-off outputs.

- Analyse how model behaviour, application design, identity and permissions combine to create vulnerabilities.

- Document findings, recommend practical mitigations and retest fixes with the engineers responsible for the affected systems.

### SUCCESS IN YOUR FIRST SIX MONTHS

- You've established a repeatable assessment approach that connects realistic adversaries, test scenarios and security outcomes.

- You've produced actionable findings with reproducible evidence and helped validate the resulting fixes.

- You've built a growing set of regression tests that captures recurring failure modes and checks whether fixes hold.

### ABOUT YOU: ESSENTIAL

- Hands-on experience in offensive security, application security testing or adversarial testing of AI systems.

- A solid understanding of web applications, APIs, authentication, authorisation and common security failure modes.

- An understanding of how AI applications use prompts, retrieved information, memory and connected tools, and where trust boundaries arise.

- The ability to write code that automates testing, reproduces findings and inspects application behaviour.

- Good judgement around test scope and sensitive data, and the ability to explain technical findings in terms of practical impact.

### NICE TO HAVE

- Experience assessing LLM applications, agent workflows or systems that retrieve external content.

- Experience building security evaluation suites or testing proposed mitigations systematically.

- Experience combining application testing with cloud, identity or infrastructure security assessment.

### OUR VALUES

Radical transparency. We believe the best work happens when everyone feels able to give and receive honest, constructive feedback.

Public service. We see AI security as a form of public service. Getting the AI transition right means putting the right infrastructure in place to manage the threats that come with it, and our work helps protect the institutions and services society depends on.

Fail fast. We test ideas early, seek feedback and learn quickly. We experiment rapidly and change course when something isn't working, without compromising on security.

Pragmatism, not dogmatism. We choose approaches based on how well they solve the problem. That means combining established cybersecurity methods with frontier AI research, questioning our assumptions, and changing our minds when the evidence changes.

### COMPENSATION AND BENEFITS

- Salary: £65,000–£125,000

- Competitive equity to share in Refractal's growth

- Pension contribution

- Private medical and dental cover

- Visa and relocation support

**Live in Refractal’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- AN [Senior Data Engineer - AI](https://gurify.com/job/senior-data-engineer-ai-at-anaplan-df499d9e9edc) Anaplan · London, United Kingdom · last week
- BJ [Backend Engineer, AI (Agent Systems)](https://gurify.com/job/backend-engineer-ai-agent-systems-at-bjak-71cec5b08766) Bjak · United Kingdom · last week
- IN [Senior Data Engineer](https://gurify.com/job/senior-data-engineer-at-indiciumai-4746b4ab9596) Indiciumai · London · 2 weeks ago
- AR [AI Research Engineer (Multi-Modal Reinforcement Learning)](https://gurify.com/job/ai-research-engineer-multi-modal-reinforcement-learning-8cbff2f521d7) United Kindom, United Kingdom · 3 weeks ago
- BJ [UX Designer, AI App](https://gurify.com/job/ux-designer-ai-app-at-bjak-361f1dacb6de) Bjak · United Kingdom · last week
- WA [Lead Technical Program Manager, AI Platform](https://gurify.com/job/lead-technical-program-manager-ai-platform-at-wayve-f8cd256aad1e) Wayve · London, United Kingdom · 4 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer (AI Red Team)","description":"\u003Ch3\u003EABOUT REFRACTAL\u003C/h3\u003E\u003Cp\u003ERefractal is an AI security company building the infrastructure organisations need to defend against autonomous AI threats. 2026 has shown that generally capable intelligence is here. The challenge now is modernising security to stop AI-enabled threats, whether they come from internal agents going rogue or from attackers using AI to become more dangerous.\u003C/p\u003E\u003Cp\u003ERefractal was founded on cybersecurity and AI expertise from MIT, Microsoft, NASA and the U.S. Navy. Our product lets organisations detect AI-enabled threats at low cost without sacrificing detection quality. We take a practical approach to AI risk, combining proven cybersecurity methods with frontier AI security research.\u003C/p\u003E\u003Cp\u003EToday, we work with governments and organisations that can\u0026#39;t afford to get security wrong. We\u0026#39;re backed by leading deep-tech and cybersecurity investors and are growing the team to deliver on this mission.\u003C/p\u003E\u003Ch3\u003ETHE ROLE\u003C/h3\u003E\u003Cp\u003EYou\u0026#39;ll test how deployed AI systems and agents fail under adversarial pressure. You\u0026#39;ll run authorised, controlled security assessments, show what each finding means in practice, and work with our engineering and research teams to turn findings into stronger defences and repeatable tests.\u003C/p\u003E\u003Ch3\u003EWHAT YOU\u0026#39;LL DO\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDesign and execute assessments of AI applications and agents, grounded in realistic attacker goals and clearly defined test scope.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETest realistic threats such as indirect prompt injection, misuse of connected tools, sensitive data exposure and attempts to cross permission boundaries.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EBuild reproducible test cases and small testing tools that demonstrate security impact and distinguish reliable failures from one-off outputs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnalyse how model behaviour, application design, identity and permissions combine to create vulnerabilities.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDocument findings, recommend practical mitigations and retest fixes with the engineers responsible for the affected systems.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ESUCCESS IN YOUR FIRST SIX MONTHS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve established a repeatable assessment approach that connects realistic adversaries, test scenarios and security outcomes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve produced actionable findings with reproducible evidence and helped validate the resulting fixes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EYou\u0026#39;ve built a growing set of regression tests that captures recurring failure modes and checks whether fixes hold.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EABOUT YOU: ESSENTIAL\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience in offensive security, application security testing or adversarial testing of AI systems.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EA solid understanding of web applications, APIs, authentication, authorisation and common security failure modes.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAn understanding of how AI applications use prompts, retrieved information, memory and connected tools, and where trust boundaries arise.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EThe ability to write code that automates testing, reproduces findings and inspects application behaviour.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EGood judgement around test scope and sensitive data, and the ability to explain technical findings in terms of practical impact.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ENICE TO HAVE\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EExperience assessing LLM applications, agent workflows or systems that retrieve external content.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience building security evaluation suites or testing proposed mitigations systematically.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience combining application testing with cloud, identity or infrastructure security assessment.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EOUR VALUES\u003C/h3\u003E\u003Cp\u003ERadical transparency. We believe the best work happens when everyone feels able to give and receive honest, constructive feedback.\u003C/p\u003E\u003Cp\u003EPublic service. We see AI security as a form of public service. Getting the AI transition right means putting the right infrastructure in place to manage the threats that come with it, and our work helps protect the institutions and services society depends on.\u003C/p\u003E\u003Cp\u003EFail fast. We test ideas early, seek feedback and learn quickly. We experiment rapidly and change course when something isn\u0026#39;t working, without compromising on security.\u003C/p\u003E\u003Cp\u003EPragmatism, not dogmatism. We choose approaches based on how well they solve the problem. That means combining established cybersecurity methods with frontier AI research, questioning our assumptions, and changing our minds when the evidence changes.\u003C/p\u003E\u003Ch3\u003ECOMPENSATION AND BENEFITS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003ESalary: \u0026#163;65,000\u2013\u0026#163;125,000\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECompetitive equity to share in Refractal\u0026#39;s growth\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPension contribution\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPrivate medical and dental cover\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EVisa and relocation support\u003C/li\u003E\u003C/ul\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-ai-red-team-at-refractal-e96c4be934e3"},"url":"https://gurify.com/job/security-engineer-ai-red-team-at-refractal-e96c4be934e3","datePosted":"2026-10-08","validThrough":"2026-11-23T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Refractal","sameAs":"https://jobs.ashbyhq.com/refractal"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"GB","addressLocality":"London"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"United Kingdom","item":"https://gurify.com/jobs/united-kingdom"},{"@type":"ListItem","position":3,"name":"Security Engineer (AI Red Team)","item":"https://gurify.com/job/security-engineer-ai-red-team-at-refractal-e96c4be934e3"}]}
```
