HHMI
Agentic AI Security Engineer
Janelia Research Campus
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Mid level
- Stated salary
- $149,084 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 23 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Primary Work Address: 19700 Helix Drive, Ashburn, VA, 20147
Current HHMI Employees, click here to apply via your Workday account.
AI@HHMI at Janelia integrates AI agents across the research process. These tools write and execute code, optimize experimental and model parameters, and drive instruments.
Letting AI agents act on shared research infrastructure requires serious safety engineering. The relevant failure mode is usually not a malicious attacker but a capable, misdirected tool running with legitimate user permissions at machine speed: hallucinated commands, instructions hijacked by retrieved content, runaway loops, sandbox escapes. We are hiring the engineer who owns this problem.
The role
You will research, develop, deploy, operate, and analyze the safety stack for agentic AI at Janelia:
- Sandboxing. Hardened, reproducible execution environments for agent code (kernel- and VM-level isolation, network egress control) on our OpenShift platform and HPC cluster, validated by adversarial testing.
- Guardrails. Policy enforcement on agent inputs, outputs, and tool calls; judge models; human approval gates; independent safeguard services that sessions can be routed through, individually or chained.
- Observability. Attributable audit logging, full-trace capture, real-time monitoring, and post-incident analysis of agent sessions.
You will join early enough to make the foundational architecture decisions, and you will operate what you design. We expect and support open-sourcing and publishing this work.
The environment
A large NVIDIA GPU cluster (B300/H200/H100 class) running self-hosted open-weight models and frontier commercial models; collaborations with industry (Anthropic and Google); scientists across biology, physics, and ML as your users; the long-term stability of a philanthropy-funded research institute.
What we look for
- Hands-on experience operating LLM agents and dealing with their failures, or deep sandbox/container-security expertise with clear ability to move into the agentic domain.
- Linux and Kubernetes/OpenShift isolation depth, including a precise understanding of the difference between containerization and sandboxing.
- Working knowledge of agent architectures: tool-calling protocols (e.g., MCP), approval gates, judge models, guardrail frameworks, and the limits of each.
- Evidence over certifications: open-source contributions, publications or technical writing, disclosed findings, or production systems you can discuss in depth.
- Minimum 5 years in security, systems/SRE, or ML systems engineering.
To apply: include a link to something you have built, broken, or written.
Physical Requirements
Remaining in a normal seated or standing position for extended periods of time; reaching and grasping by extending hand(s) or arm(s); dexterity to manipulate objects with fingers, for example using a keyboard; communication skills using the spoken word; ability to see and hear within normal parameters; ability to move about workspace. The position requires mobility, including the ability to move materials weighing up to several pounds (such as a laptop computer or tablet).
Persons with disabilities may be able to perform the essential duties of this position with reasonable accommodation. Requests for reasonable accommodation will be evaluated on an individual basis.
Please Note:
This job description sets forth the job’s principal duties, responsibilities, and requirements; it should not be construed as an exhaustive statement, however. Unless they begin with the word “may,” the Essential Duties and Responsibilities described above are “essential functions” of the job, as defined by the Americans with Disabilities Act.
#LI-BG1
Hiring Pay Range
Agentic AI Security Engineer: $149,084.80 - $186,356.00
Agentic AI Security Senior Engineer: $181,143.20 - $226,429.00
Agentic AI Security Principal Engineer: $210,803.20 - $263,504.00
Pay Type:
Salary
The posted range reflects HHMI’s good faith estimate of the anticipated hiring salary range for this role at the time of posting. Actual hiring compensation is determined by a candidate’s qualifications, experience, and internal equity.
Compensation and Benefits
Our employees are compensated from a total rewards perspective in many ways for their contributions to our mission, including competitive pay, exceptional health benefits, retirement plans, time off, and a range of recognition and wellness programs. Visit our Benefits at HHMI site to learn more.
HHMI is an Equal Opportunity Employer
We use E-Verify to confirm the identity and employment eligibility of all new hires.
Similar jobs
- AI Security Engineer, AWS Security - AISecAmazon · Austin, Texas, USAFirst seen today
- Application Security EngineerAmazon · Arlington, Virginia, USAFirst seen today
- Information Systems Security Engineer (Active DOD Secret Clearance required)CompQsoft Inc. - ACTIVE · KITTERY, MEFirst seen today
- Software Product Security Engineer - HP IQHp · San Francisco, California, United States of AmericaFirst seen today
- Systems Security Engineer I – Anti-Tamper / Program Protection (On-site)Globalhr · US-AZ-TUCSON-801 ~ 1151 E Hermans Rd ~ BLDG 801 (External Site)First seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job