Staff Threat Detection
1 week ago
About The AI Security Institute
The AI Security Institute is the world's largest and best-funded team dedicated to understanding advanced AI risks and translating that knowledge into action. We're in the heart of the UK government with direct lines to No. 10 (the Prime Minister's office), and we work with frontier developers and governments globally.
We're here because governments are critical for advanced AI going well, and UK AISI is uniquely positioned to mobilise them. With our resources, unique agility and international influence, this is the best place to shape both AI development and government action.
About The Team
Security Engineering at the AI Security Institute (AISI) exists to help our researchers move fast, safely. We are founding the Security Engineering team in a largely greenfield cloud environment, we treat security as a measurable, researcher centric product.
Secure by design platforms, automated governance, and intelligence led detection that protects our people, partners, models, and data. We work shoulder to shoulder with research units and core technology teams, and we optimise for enablement over gatekeeping, proportionate controls, low ego, and high ownership.
What You Might Work On
- Help design and ship paved roads and secure defaults across our platform so researchers can build quickly and safely
- Build provenance and integrity into the software supply chain (signing, attestation, artefact verification, reproducibility)
- Support strengthened identity, segmentation, secrets, and key management to create a defensible foundation for evaluations at scale
- Develop automated, evidence driven assurance mapped to relevant standards, reducing audit toil and improving signal
- Create detections and response playbooks tailored to model evaluations and research workflows, and run exercises to validate them
- Threat model new evaluation pipelines with research and core technology teams, fixing classes of issues at the platform layer
- Assess third party services and hardware/software supply chains; introduce lightweight controls that raise the bar
- Contribute to open standards and open source, and share lessons with the broader community where appropriate
If you want to build security that accelerates frontier scale AI safety research, and see your work land in production quickly, this is a good place to do it
Role Summary
Build and maintain a modern, mission-aware detection engineering practice. You'll own AISI's threat model, define detections that reflect AISI-specific risks, and collaborate with DSIT's SOC to extend coverage and context. You'll focus on signal quality, not alert volume. You will extend coverage to AI/ML surfaces, instrumenting the model lifecycle and AI platforms so threats to model weights, data pipelines, GPU estates, and inference endpoints are visible, correlated, and actionable.
Responsibilities
- Define and evolve AISI's threat model, working with platform, research, and policy teams
- Write detection rules, correlation logic, and hunt queries tailored to AISI's risk surface
- Ensure relevant signals are logged, routed, and contextualised appropriately
- Maintain detection playbooks, triage documentation, and escalation workflows
- Act as a liaison between AISI engineering and DSIT's central SOC
- Evaluate detection gaps and propose new signal sources or telemetry improvements
- Extend the threat model to AI/ML: data/feature pipelines, training/finetuning, evaluations/release gates, registries, GPUs, and inference services
- Develop detections for AI-specific risks: model weight custody/exfil (e.g., anomalous KMS decrypts, S3 access), registry tampering, dataset poisoning, training pipeline/image compromise, GPU abuse/cryptomining, and inference abuse (prompt injection/data exfil patterns, anomalous RAG connector access)
- Integrate AI platform telemetry (e.g., SageMaker/Bedrock logs, model registry events, provenance/attestation)
- Define hunts and correlations that tie AI safety/evaluation signals (red-team hits, eval regressions, release gate overrides) to security events and insider/outsider activity
- Author and rehearse AI-focused incident playbooks (weights leak, compromised model artefacts, inference abuse campaigns) with DSIT SOC
Profile Requirements
- Strong understanding of detection-as-code, MITRE ATT&CK, log pipelines, and cloud signal sources
- Able to navigate outsourced SOC relationships while owning internal threat understanding
- Familiarity with AWS CloudTrail, GuardDuty, KMS, S3 access logs, EKS/ECS audit, custom log ingestion; exposure to SageMaker/Bedrock or equivalent a plus
- Curious, methodical, and proactive mindset
- Practical grasp of AI/ML attack surfaces and telemetry needs (model registries, weights custody, GPU/accelerator fleets, inference gateways, vector stores)
- Familiarity with AI threat frameworks (e.g., MITRE ATLAS, OWASP Top 10 for LLMs) desirable
Key Competencies
- Detection engineering mindset focused on signal quality and measurable coverage
- Familiarity with MITRE ATT&CK and detection pipelines
- Understanding of cloud-native telemetry and logging gaps
- Ability to collaborate with outsourced SOCs
- Instrumenting and detecting threats across AI/ML workloads (weights, datasets, training/inference) and correlating safety and security signals
Salary & Benefits
We are hiring individuals at all ranges of seniority and experience within this research unit, and this advert allows you to apply for any of the roles within this range. Your dedicated talent partner will work with you as you move through our assessment process to explain our internal benchmarking process. The full range of salaries are available below, salaries comprise of a base salary, technical allowance plus
additional benefits
as detailed on this page.
- Level 3 - Total Package £65,000 - £75,000 inclusive of a base salary £35,720 plus additional technical talent allowance of between £29,280 - £39,280
- Level 4 - Total Package £85,000 - £95,000 inclusive of a base salary £42,495 plus additional technical talent allowance of between £42,505 - £52,505
- Level 5 - Total Package £105,000 - £115,000 inclusive of a base salary £55,805 plus additional technical talent allowance of between £49,195 - £59,195
- Level 6 - Total Package £125,000 - £135,000 inclusive of a base salary £68,770 plus additional technical talent allowance of between £56,230 - £66,230
- Level 7 - Total Package £145,000 inclusive of a base salary £68,770 plus additional technical talent allowance of £76,230
This role sits outside of the DDaT pay framework given the scope of this role requires in depth technical expertise in frontier AI safety, robustness and advanced AI architectures.
Government Digital and Data Profession Capability Framework - Government Digital and Data Profession Capability Framework
There are a range of pension options available which can be found through the Civil Service website.
Additional Information
Internal Fraud Database
The Internal Fraud function of the Fraud, Error, Debt and Grants Function at the Cabinet Office processes details of civil servants who have been dismissed for committing internal fraud, or who would have been dismissed had they not resigned. The Cabinet Office receives the details from participating government organisations of civil servants who have been dismissed, or who would have been dismissed had they not resigned, for internal fraud. In instances such as this, civil servants are then banned for 5 years from further employment in the civil service. The Cabinet Office then processes this data and discloses a limited dataset back to DLUHC as a participating government organisations. DLUHC then carry out the pre employment checks so as to detect instances where known fraudsters are attempting to reapply for roles in the civil service. In this way, the policy is ensured and the repetition of internal fraud is prevented. For more information please see - Internal Fraud Register.
Security
Successful candidates must undergo a criminal record check and get baseline personnel security standard (BPSS) clearance before they can be appointed. Additionally, there is a strong preference for eligibility for counter-terrorist check (CTC) clearance. Some roles may require higher levels of clearance, and we will state this by exception in the job advertisement. See our vetting charter here.
Nationality requirements
We may be able to offer roles to applicant from
any nationality or background
. As such we encourage you to apply even if you do not meet the standard nationality requirements (opens in a new window).
Working for the Civil Service
The Civil Service Code (opens in a new window) sets out the standards of behaviour expected of civil servants. We recruit by merit on the basis of fair and open competition, as outlined in the Civil Service Commission's recruitment principles (opens in a new window). The Civil Service embraces diversity and promotes equal opportunities. As such, we run a Disability Confident Scheme (DCS) for candidates with disabilities who meet the minimum selection criteria. The Civil Service also offers a Redeployment Interview Scheme to civil servants who are at risk of redundancy, and who meet the minimum requirements for the advertised vacancy.
Diversity and Inclusion
The Civil Service is committed to attract, retain and invest in talent wherever it is found. To learn more please see the Civil Service People Plan (opens in a new window) and the Civil Service Diversity and Inclusion Strategy (opens in a new window).
-
Staff Threat Detection Engineer
1 week ago
London, Greater London, United Kingdom Reinsurance Group of America, Incorporated Full time £60,000 - £120,000 per yearYou desire impactful work.You'reRGA readyRGA is a purpose-driven organization working to solve today's challenges through innovation and collaboration. A Fortune 500 Company and listed among itsWorld's Most Admired Companies, we're the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of...
-
Senior Threat Detection Specialist
4 days ago
London, Greater London, United Kingdom QBE Europe Full time £60,000 - £150,000 per yearPrimary DetailsTime Type: Full timeWorker Type: EmployeeSenior Threat Detection SpecialistLocation:LondonHappy to talk flexible workingThe OpportunityAs we focus on transformation across the organisation, we're also investing in our cyber security capabilities to keep our people, data, and customers safe. That's why we're building a newDetection...
-
London, Greater London, United Kingdom Meta Full time £60,000 - £120,000 per yearMeta Security is looking for a threat intelligence investigator with extensive experience in investigating cyber threats with an intelligence-driven approach. You will be proactively responding to a broad set of security threats, as well as tracking actor groups with an interest or capability to target Meta and its employees. You will also be identifying the...
-
Senior Threat Detection Engineer
2 weeks ago
London, Greater London, United Kingdom Reinsurance Group of America, Incorporated Full time £60,000 - £100,000 per yearYou desire impactful work.You'reRGA readyRGA is a purpose-driven organization working to solve today's challenges through innovation and collaboration. A Fortune 500 Company and listed among itsWorld's Most Admired Companies, we're the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of...
-
Insider Threat
6 days ago
London, Greater London, United Kingdom Axiom Software Solutions Limited Full time £60,000 - £120,000 per yearJob Titlle: Insider Threat & Data Loss Prevention (DLP) SpecialistLocation: Remote - Europe /UK Role Overview:We are looking for a DLP & Insider Threat Specialist to help our client assess, design, and implement a comprehensive insider threat and data loss prevention capability. The client's current monitoring and controls in this area are minimal, and the...
-
Cyber Security Detection Engineer
4 days ago
London, Greater London, United Kingdom American Express Global Business Travel Full time £90,000 - £120,000 per yearAmex GBT is a place where colleagues find inspiration in travel as a force for good and – through their work – can make an impact on our industry. We're here to help our colleagues achieve success and offer an inclusive and collaborative culture where your voice is valued. The Senior Cyber Security Detection Engineer is a critical role responsible for...
-
London, Greater London, United Kingdom TikTok Full time £60,000 - £120,000 per yearSecuritySecurity Operations Analyst – Detection Engineering & Threat HuntingLocation:LondonEmployment Type:RegularJob Code:A174654ResponsibilitiesAbout the team:TikTok's IT security team is responsible for enterprise IT global cyber security, server security, endpoint security, application security construction, and protection work. They work to improve...
-
Threat Analyst, EMEA
2 weeks ago
London, Greater London, United Kingdom BioCatch Full time £40,000 - £80,000 per yearBioCatch is the leader in Behavioral Biometrics, a technology that leverages machine learning to analyze an online user's physical and cognitive digital behavior to protect individuals online.BioCatch's mission is to unlock the power of behavior and deliver actionable insights to create a digital world where identity, trust, and ease coexist.Today, 32 of the...
-
Security Engineer: Detection and Response
2 weeks ago
London, Greater London, United Kingdom Anthropic Full time £255,000 - £325,000 per yearAbout AnthropicAnthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.At Anthropic, we are...
-
Security Engineer: Detection and Response
6 days ago
London, Greater London, United Kingdom Anthropic Full time £255,000 - £325,000 per yearAbout AnthropicAnthropic's mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. At Anthropic, we are...