About the AI Security Institute
The AI Security Institute is the world's largest and best-funded team dedicated to understanding advanced AI risks and translating that knowledge into action. We’re in the heart of the UK government with direct lines to No. 10 (the Prime Minister's office), and we work with frontier developers and governments globally.
We’re here because governments are critical for advanced AI going well, and UK AISI is uniquely positioned to mobilise them. With our resources, unique agility and international influence, this is the best place to shape both AI development and government action.
The deadline for applying to this role is 11th October 2026, end of day, anywhere on Earth.
About the team
AI capabilities in cybersecurity and autonomy are advancing faster than at any point in history. Frontier models can now work through multi-step network intrusions, discover and exploit software vulnerabilities, and carry out long-horizon technical tasks with increasing independence. These are extraordinary tools for scientific and economic progress, but also have the potential for serious harm if misused or deployed without adequate oversight, as seen in the recent cybersecurity incidents.
The team evaluates the capability of both frontier and open-weight AI models in cybersecurity, autonomy and AI R&D, ensuring the UK government and its partners have an accurate view of risks and capabilities. We use realistic cyber ranges and a large CTF suite for our evaluations, run pre-deployment testing of frontier models, and collaborate with our partners across UK government, frontier labs, and NCSC.
Role Description
We are looking for exceptional cybersecurity experts at all experience levels, from junior through to senior or staff, who want to work at the forefront of frontier AI security.
In this role, you’ll work with cutting-edge technologies on research problems with real-world impact, and receive mentorship and coaching from your manager and the technical leads on your team.
Your day-to-day work might include building state-of-the-art evaluations (e.g., cyber ranges), running pre-deployment testing exercises (e.g., Claude Mythos Preview), validating novel model behaviours (e.g., models cheating in evaluations), and answering timely research questions (e.g., the capabilities of open-weight models). You would be working alongside engineers and researchers who care deeply about the impact of their work, take pride in their craft, and have a high level of autonomy.
If that sounds exciting to you, we'd love for you to apply!
Core Responsibilities
- Evaluation Design & Development (60%)
- Design cyber ranges and CTF-style challenges for automatically grading AI system performance on cybersecurity tasks
- Build agentic scaffolding to evaluate frontier models, equipping them with tools such as network packet capture utilities, penetration testing frameworks, and reverse engineering/disassembly tools
- Design metrics and interpret results of cyber capability evaluations
- Infrastructure engineering (30%)
- Work alongside other engineers to ensure evaluation environments are robust and scalable
- Research & Communication (10%)
- Write reports, research papers and blog posts to share findings with stakeholders
- Keep up-to-date with related research taking place in other organisations
- Contribute to AISI's broader understanding of AI cyber risks
Example projects
- Onboard and integrate new cyber ranges into our evaluation pipeline
- Conduct agent research to improve the cyber capabilities of our agents
- Improve grading and scoring methodologies for automated evaluation tasks
- Integrate defensive telemetry and simulated users into ranges to increase their realism
- Collaborate with government partners on joint research publications
Impact
Your work will directly shape the UK government's understanding of AI cyber capabilities, inform safety standards for frontier AI systems, and contribute to the global effort to develop rigorous evaluation methodologies. The evaluations you build will help determine how advanced AI systems are assessed before deployment.
Who we're looking for
We're flexible on the exact profile and expect successful candidates will meet many (but not necessarily all) of the criteria below:
Essential
- Strong Python skills with experience writing scripts for automation or security tooling
- Proven experience in at least one of the following areas of cybersecurity red-teaming:
- Penetration testing
- Cyber range design
- Competing in or designing CTFs
- Developing automated security testing tools
- Bug bounties, vulnerability research, or exploit discovery and patching
- Strong interest in helping improve the safety of AI systems
Desirable
- Familiarity with virtualisation technologies such as Proxmox VE and infrastructure-as-code approaches to enable reproducible test environments to be rapidly spun up for testing
- Ability to communicate the outcomes of cybersecurity research to a range of technical and non-technical audiences
- Familiarity with cybersecurity tools such as network packet capture utilities, penetration testing frameworks, and reverse engineering/disassembly tools
- Active in the cybersecurity community with a track record of keeping up to date with new research
- Previous experience building or measuring the impact of automation tools on cyber red-teaming workflows
Motivated candidates are encouraged to apply even if you don't meet all the above criteria.
What We Offer
Impact you couldn't have anywhere else
- Incredibly talented, mission-driven and supportive colleagues.
- Direct influence on how frontier AI is governed and deployed globally.
- Work with the Prime Minister’s AI Advisor and leading AI companies.
- Opportunity to shape the first & best-resourced public-interest research team focused on AI security.
Resources & access
- Pre-release access to multiple frontier models and ample compute.
- Extensive operational support so you can focus on research and ship quickly.
- Work with experts across national security, policy, AI research and adjacent sciences.
Growth & autonomy
- If you’re talented and driven, you’ll own important problems early.
- 5 days off and annual stipends for learning and development, and funding for conferences and external collaborations.
- Freedom to pursue research bets without product pressure.
- Opportunities to publish and collaborate externally.
Life & family*
- Modern central London office, or where applicable, option to work in similar government offices in Birmingham, Cardiff, Darlington, Edinburgh, Salford or Bristol.
- Hybrid working, flexibility for occasional remote work abroad and stipends for work-from-home equipment.
- At least 25 days’ annual leave, 8 public holidays, extra team-wide breaks and 3 days off for volunteering.
- Generous paid parental leave (36 weeks of UK statutory leave shared between parents + 3 extra paid weeks + option for additional unpaid time).