Agentic AI Security Engineer
Job Description
Howard Hughes Medical Institute (HHMI) Janelia is hiring an Agentic AI Security Engineer to help shape the safety stack for AI agents used throughout the research process. The role is based in Ashburn, VA (onsite) and offers competitive annual pay along with exceptional health benefits, retirement plans, time off, and a range of recognition and wellness programs.
HHMI Janelia builds and runs AI agents that can write and execute code, optimize experimental and model parameters, and drive instruments. You will work in a long-term, philanthropy-funded research environment backed by a large NVIDIA GPU cluster (B300/H200/H100 class), combining self-hosted open-weight models with frontier commercial models, and collaborating with industry partners (including Anthropic and Google).
What you’ll do
You will research, develop, deploy, operate, and analyze safety controls for agentic AI across the full research workflow. The focus is preventing failure modes caused by capable, misdirected tools running with legitimate user permissions at machine speed, such as hallucinated commands, instructions hijacked by retrieved content, runaway loops, and sandbox escapes. Work includes designing foundational architecture and operating the systems you build.
- Sandboxing: Own hardened, reproducible execution environments for agent code, including kernel- and VM-level isolation and network egress control, running on the OpenShift platform and an HPC cluster, validated using adversarial testing.
- Guardrails: Own policy enforcement across agent inputs, agent outputs, and tool calls, including judge models, human approval gates, and independent safeguard services that sessions can be routed through individually or chained.
- Observability: Own attributable audit logging, full-trace capture, real-time monitoring, and post-incident analysis for agent sessions.
- Architecture ownership: Join early enough to influence foundational architecture decisions, then operate what you design.
- Knowledge sharing: Support open-sourcing and publishing the work.
What you bring
- Hands-on experience operating LLM agents and handling their failures, or deep sandbox/container-security expertise with the ability to move into the agentic domain.
- Depth in Linux and Kubernetes/OpenShift isolation, with a precise understanding of the difference between containerization and sandboxing.
- Working knowledge of agent architectures, including tool-calling protocols (for example MCP), approval gates, judge models, guardrail frameworks, and the limitations of each.
- Evidence over certifications, such as open-source contributions, publications or technical writing, disclosed findings, or production systems you can discuss in depth.
- Minimum 5 years in security, systems/SRE, or ML systems engineering.
Environment and tools
Work is conducted on OpenShift and an HPC cluster with a large NVIDIA GPU cluster, using Linux and Kubernetes. Agent safety work may involve open-weight models, frontier commercial models, and technologies such as MCP.
- OpenShift, HPC cluster, Linux, Kubernetes
- Open-weight models and frontier commercial models
- NVIDIA GPU cluster: B300, H200, H100
- MCP
Apply
To apply, include a link to something you have built, broken, or written.
Compensation and additional information
- Hiring Pay Range: USD 149,084 - 186,356 per year (annual)
- Pay range reflects HHMI’s good faith estimate; actual compensation depends on qualifications, experience, and internal equity.
- Equal opportunity employer: HHMI uses E-Verify to confirm identity and employment eligibility for new hires.
Physical requirements
- Remaining seated or standing for extended periods
- Reaching and grasping by extending hand(s) or arm(s)
- Dexterity to manipulate objects with fingers, such as using a keyboard
- Communication skills using the spoken word
- Ability to see and hear within normal parameters
- Ability to move about the workspace, including moving materials up to several pounds (for example a laptop computer or tablet)
- Reasonable accommodations may be possible for qualified individuals with disabilities, evaluated on an individual basis
Please note: This job description outlines principal duties, responsibilities, and requirements and is not exhaustive. Unless specified with “may,” essential duties and responsibilities are considered essential functions under the Americans with Disabilities Act.
Hiring status: This role requires onsite presence in Ashburn, VA.