About the role
You keep documents, websites and tools from silently taking control of a person's agent. Prompt injection and confused-deputy problems are the defining security issue of agent systems: an agent that reads a web page has just taken instructions from a stranger, and the boundary between data and command is where this either holds or does not. This role is the one holding that line, and it is a research problem as much as an engineering one.
The work
Review application code, connectors and tool execution for authorization failures, injection, secret leakage and unsafe external actions. Build enforceable controls outside model prompts. Work with engineers on secure defaults, egress restrictions and tests that reproduce actual failure modes.
What good looks like
In your first 90 days, secure one complete workflow and add regression tests for its highest-risk attacks.
Evidence we look for
Bring practical application security and strong coding skills. Experience with agent systems is valuable, but disciplined threat modeling and remediation are essential.
What we need to see
- Practical application security with strong coding skills
- Disciplined threat modelling and remediation you can walk through end to end
- You treat all external content as hostile input by default
- You can fix what you find rather than only reporting it
Nice to have
- Agent or LLM security specifically, including injection research
- Browser or sandbox security
- A track record of responsible disclosure
The exercise
Review a malicious document that asks the agent to send private files elsewhere and show where enforcement must happen.
Where and how we work
In the office together five days a week, in any of these cities. Remote-friendly around your family, arranged one person at a time.