Apollo Research Logo

Apollo Research

AI Security Researcher

Posted 6 Days Ago
Be an Early Applicant
In-Office
San Francisco, CA, USA
144K-280K Annually
Senior level
In-Office
San Francisco, CA, USA
144K-280K Annually
Senior level
Secure Apollo’s internal software, infrastructure, and AI-agent environments through threat modeling, red teaming, attack-trajectory development, adversary tracking, and detection engineering. Own security findings through remediation by designing durable controls, automated tests, CI/CD integrations, and monitoring. Collaborate closely with engineers and research teams to address novel AI-agent and insider-risk threats while documenting threat models and failure modes clearly.
The summary above was generated by AI
THE OPPORTUNITY

Apollo Research works with most frontier AI companies (OpenAI, Anthropic, Google, Meta, Thinking Machines and others) to test their models before deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprise. 

Security exists at Apollo to safeguard the trust frontier labs place in us and to enable that research. Our own team uses AI agents extensively across its work, which makes Apollo both a target and a testbed. We’re hiring AI Security Researchers to join the Infra & Security Team. 

In this role, you will identify, research and remediate both conventional threats and the novel risks introduced by AI agents that can affect Apollo and our mission. You will redefine and work on a new class of insider risk that didn’t exist before. 

RESPONSIBILITIES

  • Hold responsibility for the security of Apollo’s internal surfaces. Red-team internal software, infrastructure, and AI agent access controls/monitoring. Build realistic attack trajectories.

  • Design solutions for novel or emerging threats in the AI security space, where no existing playbook applies. Set the standard for our security posture in these areas.

  • Track adversary tactics, techniques, and campaigns relevant to Apollo's threat landscape, and translate that intelligence into tuned, high-signal detections.

  • Own each finding through to a deployed fix. Build and roll out durable controls: checks, tests, defaults, detections. Socialise them, work with engineers to implement, and hold remediation to a high bar.

KEY REQUIREMENTS

    Must haves
  • 5+ years in security roles in a hands-on technical capacity (not purely GRC/compliance). You'd need to be able to think structurally about threat modelling and failure modes. You need to be able to read code, understand infrastructure, and evaluate technical controls.

  • Direct experience with offensive security. Threat modelling, red teaming, etc. Knowledge of application or cloud. Ideally you owned or significantly contributed to the security posture of an organisation or product that handles sensitive customer data. 

  • Engineering mindset. You treat security as an engineering problem. You can translate your findings into fixes and controls, such as paved roads, custom detection rules, adversarial test suites, CI/CD integrations. You prioritize automation and systems-level thinking to scale security, and you are comfortable leveraging AI to accelerate development.

  • Startup pace. You are excited about a fast-moving environment, comfortable with ambiguity and changing priorities, and willing to grind when it matters.

  • Strong written communication. This role produces a lot of artifacts (threat models, reports, failure mode documentation) and they need to be clear and precise.

  • Nice to haves
  • Experience with AI/ML systems security or LLM security. 

  • Detection engineering, SOC, or incident analysis experience. 

  • Familiarity with insider threat programs or insider risk frameworks. 

  • Explicitly not required
  • Formal AI safety research background. We need security practitioners who can learn the AI safety context, not AI safety researchers who need to learn security.

REPRESENTATIVE PROJECTS

  • Red-team Apollo's agent sandboxes used for evals: Test whether an agent can escape isolation, exfiltrate data, detect it's being evaluated, or otherwise undermine the validity of eval results. Your findings will harden the sandbox infrastructure the research team depends on to trust its own eval results.

  • Comprehensive coding agent threat model: Map every way a coding agent with internal access: credentials, code, network, execution ability,  could attack Apollo, benchmarked against what a human insider with the same access could do.

BENEFITS

  • This role offers market competitive salary, equity, and competitive benefits.

  • Salary: San Francisco: $214,000 – $280,000; London: £144,000 – £189,000. We will be looking to meaningfully raise salaries soon.  

  • Our engineers effectively have an unlimited token budget. If a better result costs more compute, use it.

  • Flexible work hours and schedule

  • Unlimited vacation

  • Unlimited sick leave

  • Up to 6 months of paid parental leave

  • Comprehensive health, dental and vision insurance

  • Retirement savings with competitive employer matching (e.g. 401(k) for US employees)

  • Lunch, dinner, and snacks are provided for all employees on workdays

  • Paid work trips, including staff retreats, business trips, and relevant conferences

  • A yearly $1,000 (USD) professional development budget

  • Relocation support and visa fees (if applicable)

LOGISTICS

  • Time Allocation: Full-time

  • Location: This is an in-person role working out of our London or San Francisco office. We offer flexible working hours and some wfh arrangements.

  • Visa sponsorship: We sponsor visas in both the UK and US. Sponsorship isn't guaranteed for every role or candidate, but if we make you an offer, we'll work with you to find the right visa route.

ABOUT THE TEAM

The Infra and Security team is currently led by Rusheb Shah and consists of Glen Rodgers and Steven Lee. You will work closely with Security Engineers we’re hiring for as well as technical staff from the Scheming Research and Product team. You can find our full team here.

ABOUT APOLLO RESEARCH

The rapid rise in AI capabilities offers tremendous opportunities, but also presents significant risks. At Apollo Research, we're primarily concerned with risks from Loss of Control, i.e. risks coming from the model itself rather than e.g. humans misusing the AI. We're particularly concerned with deceptive alignment / scheming, a phenomenon where a model appears to be aligned but is, in fact, misaligned and capable of evading human oversight. 

We work on the science of scheming, detection of scheming (e.g. building evaluations), and scheming mitigations (e.g. anti-scheming). We also work on control and monitoring research (see our scalable monitoring agenda). We work closely with many frontier AI companies, such as OpenAI, Anthropic, Google, Meta, Thinking Machines and others, e.g. to test their models and collaborate on the science of scheming. At Apollo, we aim for a culture that emphasizes truth-seeking, being goal-oriented, giving and receiving constructive feedback, and being friendly and helpful. If you're interested in more details about what it's like working at Apollo, you can find more information here.

We also build a coding agent security product called Watcher that secures agent deployments in companies. Our goal is to reduce the probability of catastrophic incidents by securing coding agents, learning about their real-world risks, and publishing our research on how to build these control systems most effectively.

Equality Statement: Apollo Research is an Equal Opportunity Employer. We value diversity and are committed to providing equal opportunities to all, regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex, or sexual orientation.

HOW TO APPLY

Please complete the application form with your CV. The provision of a cover letter is neither required nor encouraged. Please also feel free to share links to relevant work samples.

About the interview process: Our multi-stage process includes a screening interview, a take-home test (approx. 2-3 hours), 3 technical interviews, and a final interview with Marius (CEO). There are no leetcode-style general coding interviews. You may use AI tools on the take-home; we judge the result the way we'd judge any contributor's work, so you are responsible for the quality of everything you submit.

Your Privacy and Fairness in Our Recruitment Process: We are committed to protecting your data, ensuring fairness, and adhering to workplace fairness principles in our recruitment process. To enhance hiring efficiency, we use AI-powered tools to assist with tasks such as resume screening. These tools are designed and deployed in compliance with internationally recognized AI governance frameworks. Your personal data is handled securely and transparently. All resumes are screened by a human and final hiring decisions are made by our team. If you have questions about how your data is processed or wish to report concerns about fairness, please contact us at [email protected].

Similar Jobs

4 Minutes Ago
Remote or Hybrid
US
185K-210K Annually
Senior level
185K-210K Annually
Senior level
Artificial Intelligence • Machine Learning
Own and modernize Domino's Tempest scale-testing platform; build repeatable automated validation, sizing guidance, and cloud-scale test automation; partner with platform teams to enable multi-cloud scale testing and improve test reliability and reporting.
Top Skills: Ci SystemsCloud PlatformsCloud-Native ToolingEnd-To-End FrameworksKubernetesMulti-CloudPerformance/Load Testing FrameworksPythonTempest
6 Minutes Ago
Easy Apply
In-Office or Remote
Easy Apply
Internship
Internship
Machine Learning • Security • Software • Analytics • Defense
Summer 2027 internship opportunities are available across sensors, intelligence, cyber, analytics and command-and-control, systems, operations, and corporate functions. Interns should be enrolled in a BS, MS, or PhD program, demonstrate strong academics and research interest, and be able to obtain a security clearance. The program offers competitive pay, housing at the Massachusetts site, alternate-site bonuses, flexible hours, and summer activities. Roles support advanced defense, intelligence, cybersecurity, sensing, communications, electronic warfare, and artificial intelligence research.
Top Skills: AnalyticsArtificial IntelligenceCommand And Control (C2)CommunicationsCybersecurityElectronic WarfareRadarSensorsSonar
An Hour Ago
Remote or Hybrid
116K-192K Annually
Mid level
116K-192K Annually
Mid level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Oversee enterprise Moveworks implementations from planning through launch, ensuring on-time, on-budget delivery. Manage governance, scope, timelines, budgets, risks, resources, reporting, and change management. Lead customers, partners, and cross-functional teams in designing and deploying agentic workflows, resolving complex issues, and driving adoption. Serve as the primary customer contact, mentor team members, communicate insights to Product, and coordinate transition to Customer Success.
Top Skills: Artificial IntelligenceLarge Language Models (Llms)MoveworksSaaSServicenow

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account