Founding AI Engineer
Founding AI Engineer role building runtime classification stacks, policy engines, and evidence pipelines for agentic AI safety. Work with adversarial attack detection and multi-modal controls for LLMs and agents, securing high-consequence deployments for startups and government. London-based startup in cybersecurity infrastructure for autonomy.
Free Tailor for ATS: 10/10 runs left
Job Title
Founding AI Engineer
Company Description
Refractal is a London-based startup building security infrastructure for autonomy, recognized by MIT’s CSAIL Alliances and selected for Google’s Gemini Cybersecurity Startup Forum.
Job Description
As a Founding AI Engineer at Refractal, you will build the critical safety layer for agentic systems. You'll own the development of runtime classification stacks, policy engines, and evidence pipelines that secure high-consequence AI deployments for leading startups and government entities. This is a rare opportunity to define a new category in cybersecurity.
Location
London, UK
Why this role is remarkable
Join a powerhouse founding team with technical pedigree from MIT, NASA, Microsoft, and the NSA building at the frontier of AI security.
Work on real-world, high-consequence deployments for a European government and top-tier startups rather than purely synthetic research environments.
Direct path to Head of Engineering with significant founding equity and influence over the product roadmap and research agenda.
What You Will Do
Develop the runtime classification stack that authorizes agent actions in real-time, ensuring safety and compliance before execution.
Build high-performance evidence pipelines to record AI verdicts and rationale, providing transparent governance for autonomous systems.
Collaborate with security researchers to translate novel adversarial attacks into robust, production-ready detections and multi-modal controls.
The ideal candidate
0–3 years of experience in AI/ML systems with a strong foundation in computer science, machine learning, or cybersecurity.
A proven builder with a portfolio of production-grade systems, research at top labs, or significant open-source contributions.
Rigorous understanding of how adversaries exploit LLMs and agents, including prompt injection, goal hijacking, and data exfiltration.