Guardrails. Policy enforcement on agent inputs, outputs,
and tool calls; judge models; human approval gates; independent
safeguard services that sessions can be routed through,
individually or chained.
Observability. Attributable audit logging, full-trace
capture, real-time monitoring, and post-incident analysis of agent
sessions.
You will join early enough to make the foundational architecture
decisions, and you will operate what you design. We expect and
support open-sourcing and publishing this work.
The environment
A large NVIDIA GPU cluster (B300/H200/H100 class) running
self-hosted open-weight models and frontier commercial models;
collaborations with industry (Anthropic and Google); scientists
across biology, physics, and ML as your users; the long-term
stability of a philanthropy-funded research institute.
What we look for
- Hands-on experience operating LLM agents and dealing with their
failures, or deep sandbox/container-security expertise with clear
ability to move into the agentic domain.
- Linux and Kubernetes/OpenShift isolation depth, including a
precise understanding of the difference between containerization
and sandboxing.
- Working knowledge of agent architectures: tool-calling
protocols (e.g., MCP), approval gates, judge models, guardrail
frameworks, and the limits of each.
- Evidence over certifications: open-source contributions,
publications or technical writing, disclosed findings, or
production systems you can discuss in depth.
- Minimum 5 years in security, systems/SRE, or ML systems
engineering.
To apply: include a link to something you have built,
broken, or written.
Physical Requirements
Remaining in a normal seated or standing position for extended
periods of time; reaching and grasping by extending hand(s) or
arm(s); dexterity to manipulate objects with fingers, for example
using a keyboard; communication skills using the spoken word;
ability to see and hear within normal parameters; ability to move
about workspace. The position requires mobility, including the
ability to move materials weighing up to several pounds (such as a
laptop computer or tablet).
Persons with disabilities may be able to perform the essential
duties of this position with reasonable accommodation. Requests for
reasonable accommodation will be evaluated on an individual
basis.
Please Note:
This job description sets forth the job’s principal duties,
responsibilities, and requirements; it should not be construed as
an exhaustive statement, however. Unless they begin with the word
“may,” the Essential Duties and Responsibilities described above
are “essential functions” of the job, as defined by the Americans
with Disabilities Act.
Hiring Pay Range
Agentic AI Security Engineer: $149,084.80 - $186,356.00
Agentic AI Security Senior Engineer: $181,143.20 -
$226,429.00
Agentic AI Security Principal Engineer: $210,803.20 -
$263,504.00
Pay Type:
Salary
The posted range reflects HHMI’s good faith estimate of the
anticipated hiring salary range for this role at the time of
posting. Actual hiring compensation is determined by a candidate’s
qualifications, experience, and internal equity.
Compensation and Benefits
Our employees are compensated from a total rewards perspective in
many ways for their contributions to our mission, including
competitive pay, exceptional health benefits, retirement plans,
time off, and a range of recognition and wellness programs. Visit
our
Benefits at
HHMI site to learn more.
HHMI is an Equal Opportunity
Employer
We use
E-Verify to confirm the identity and employment
eligibility of all new hires.