Research how AI agents and LLM-powered systems fail, and what companies should do about it. Threat research, risk analysis, and clear guidance, not hands-on engineering.
Apply for this roleAbout the role
Companies are putting AI agents in front of customers, wiring them to CRMs and inboxes, and giving them tools. Most leaders have no clear picture of what can go wrong. You'll study how these systems fail, track new attacks and incidents, and turn that into practical guidance: risk assessments, security checklists, policies, and public research under the Belsoft name. You'll work alongside our security and AI engineers, who test and build. Your job is to know what to look for, why it matters, and how to explain it to people who make decisions.
What you'll do
- Research AI security threats: prompt injection, data leakage, agent and tool abuse, supply-chain risk, and new attack techniques
- Track incidents, vulnerability disclosures, papers, and standards, and tell the team what matters for our clients
- Assess AI deployments at the design level: what an agent can access, where trust boundaries sit, and what could go wrong
- Write risk assessments, security checklists, and AI usage and governance policies for client teams
- Map clients' AI use against frameworks such as the OWASP Top 10 for LLM applications, NIST AI RMF, and the EU AI Act
- Brief our engineers on what to test, and turn findings into requirements for checks in our tooling, including DeployReady
- Publish research: reports, articles, and talks that explain AI risk clearly and build trust in Belsoft
What you bring
- Experience in security research, threat intelligence, risk analysis, or a related analytical field
- A solid understanding of how LLMs, AI agents, and tool-connected systems work, and where they break
- Familiarity with security fundamentals and frameworks such as OWASP, NIST, or ISO 27001
- Excellent writing: able to turn complex technical risk into clear, accurate guidance for non-technical leaders
- Rigorous and curious, with careful judgement about evidence, severity, and what to claim
- You do not need to be a hands-on engineer, but you can read technical material and work closely with engineers
Nice to have
- Published research, advisories, conference talks, or a strong public writing record
- Experience in compliance, governance, or risk for AI or data-heavy systems
- Background in machine learning, academia, or policy research
- Some scripting ability for analysis, or familiarity with security testing concepts
Apply
Sound like you?
Five minutes. No cover-letter theatre — just tell us what you've done and why this role.
