Back to jobs
Refractal

Refractal

Security Engineer (AI Red Team)

London On-site 2-5 yrs exp Software Development 9 employees£65k – £125k / year
Offensive SecurityApplication Security TestingAI Red TeamingWeb Application SecurityAPI Security

Requirements

Candidates need hands-on experience in offensive security, application security testing, or adversarial AI testing, along with a solid understanding of web applications, APIs, authentication, authorization, and AI application trust boundaries. They must be able to code to automate tests and reproduce findings, exercise sound judgment around scope and sensitive data, and explain technical risks in terms of practical impact.

Job Description

About Refractal

Refractal is an AI security company building the infrastructure organisations need to defend against autonomous AI threats. 2026 has shown that generally capable intelligence is here. The challenge now is modernising security to stop AI-enabled threats, whether they come from internal agents going rogue or from attackers using AI to become more dangerous.

Refractal was founded on cybersecurity and AI expertise from MIT, Microsoft, NASA and the U.S. Navy. Our product lets organisations detect AI-enabled threats at low cost without sacrificing detection quality. We take a practical approach to AI risk, combining proven cybersecurity methods with frontier AI security research.

Today, we work with governments and organisations that can't afford to get security wrong. We're backed by leading deep-tech and cybersecurity investors and are growing the team to deliver on this mission.


The role

You'll test how deployed AI systems and agents fail under adversarial pressure. You'll run authorised, controlled security assessments, show what each finding means in practice, and work with our engineering and research teams to turn findings into stronger defences and repeatable tests.


What you'll do

  • Design and execute assessments of AI applications and agents, grounded in realistic attacker goals and clearly defined test scope.
  • Test realistic threats such as indirect prompt injection, misuse of connected tools, sensitive data exposure and attempts to cross permission boundaries.
  • Build reproducible test cases and small testing tools that demonstrate security impact and distinguish reliable failures from one-off outputs.
  • Analyse how model behaviour, application design, identity and permissions combine to create vulnerabilities.
  • Document findings, recommend practical mitigations and retest fixes with the engineers responsible for the affected systems.


Success in your first six months

  • You've established a repeatable assessment approach that connects realistic adversaries, test scenarios and security outcomes.
  • You've produced actionable findings with reproducible evidence and helped validate the resulting fixes.
  • You've built a growing set of regression tests that captures recurring failure modes and checks whether fixes hold.


About you: essential

  • Hands-on experience in offensive security, application security testing or adversarial testing of AI systems.
  • A solid understanding of web applications, APIs, authentication, authorisation and common security failure modes.
  • An understanding of how AI applications use prompts, retrieved information, memory and connected tools, and where trust boundaries arise.
  • The ability to write code that automates testing, reproduces findings and inspects application behaviour.
  • Good judgement around test scope and sensitive data, and the ability to explain technical findings in terms of practical impact.


Nice to have

  • Experience assessing LLM applications, agent workflows or systems that retrieve external content.
  • Experience building security evaluation suites or testing proposed mitigations systematically.
  • Experience combining application testing with cloud, identity or infrastructure security assessment.


Our values

Radical transparency. We believe the best work happens when everyone feels able to give and receive honest, constructive feedback.

Public service. We see AI security as a form of public service. Getting the AI transition right means putting the right infrastructure in place to manage the threats that come with it, and our work helps protect the institutions and services society depends on.

Fail fast. We test ideas early, seek feedback and learn quickly. We experiment rapidly and change course when something isn't working, without compromising on security.

Pragmatism, not dogmatism. We choose approaches based on how well they solve the problem. That means combining established cybersecurity methods with frontier AI research, questioning our assumptions, and changing our minds when the evidence changes.


Compensation and benefits

  • Salary: £65,000–£125,000
  • Competitive equity to share in Refractal's growth
  • Pension contribution
  • Private medical and dental cover
  • Visa and relocation support

Skills

Offensive SecurityApplication Security TestingAI Red TeamingWeb Application SecurityAPI SecurityAuthenticationAuthorizationPrompt Injection TestingAgent Security AssessmentSecurity Test AutomationPython or Other ProgrammingVulnerability AnalysisThreat ModelingCloud SecurityIdentity and Infrastructure SecuritySecurity Findings Documentation

About Refractal

AI agents can access sensitive data, use tools and act across enterprise systems, but security teams lack visibility and control. Refractal discovers AI activity, detects cross-layer attacks and enforces policy across models, tools, data and modalities.