> Markdown version of [/jobs/ext/3026572-ai-security-engineer-agentic-systems](https://www.wearedevelopers.com/jobs/ext/3026572-ai-security-engineer-agentic-systems). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Security Engineer (Agentic Systems) - **Company:** ClearRoute - **Location:** London, UK - **Salary:** £62,207.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Microsoft Azure, Cloud Computing Security, Continuous Integration, Open Source Technology, Open Web Application Security, Strategies of Testing, Large Language Models, Multi-Agent Systems, Virtual Agents, Terraform - **Published:** September 22, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5893291794 ## About the Role Must Have: * Hands-on experience red-teaming or adversarially testing LLM or agentic AI systems, including prompt injection, jailbreaking and tool-misuse scenarios * Practical understanding of how to test non-deterministic systems and how to detect, quantify and mitigate hallucination * Working knowledge of agentic-AI-specific risk frameworks and taxonomies, such as OWASP's agent risk categories and MITRE ATLAS * Experience with the OWASP Top 10 for LLM Applications, including prompt injection and system-prompt-leakage risk categories * Experience designing or applying an AI governance framework (for example NIST's AI Risk Management Framework) to translate identified risks into organisational controls * Ability to operate across accounts and teams, building test strategy and tooling recommendations that generalise beyond a single application * Threat modelling and security review experience * Strong communication skills, able to explain agentic AI risk clearly to technical and non-technical stakeholders, including on what should and shouldn't be released to clients * Comfortable being hands-on first - implementing and running agentic security tests directly - then mentoring and training other security engineers to take the practice on themselves Nice to Have: * Familiarity with agent-hijacking or agent-specific evaluation tooling (for example open-source agent-security benchmarks) * Awareness of emerging AI regulation relevant to security testing, such as the EU AI Act's adversarial and robustness-testing requirements * Experience with multi-agent or agent-mesh systems and the trust/authentication issues between agents * Cloud security background (Azure preferred) and Terraform and CI/CD * Experience in a regulated sector (for example financial services) ## Description This role sits apart from our traditional cloud security engineering positions: it is centred on AI and agentic systems rather than infrastructure alone. You will test and secure AI use cases across an account, not a single application or user set, building a broad, first-hand picture of how ClearRoute should approach testing, risk and governance for agentic AI. You will work across teams rather than within one delivery stream, owning the question of what "good" looks like for agentic security testing across the account, and helping ClearRoute build a repeatable, defensible approach that other engagements can adopt. The role is deliberately hands-on in its first phase: you will implement and run the testing yourself, so you understand the detail before asking anyone else to follow it. As that practice matures, the role shifts toward governance across the account, training and upskilling existing security engineers to implement and automate the strategy themselves, so agentic security testing becomes something the wider team can run, not something that depends on one person. Key Responsibilities Agentic Red Teaming & Adversarial Testing: * Design and run red-team exercises against AI agents and agentic workflows, probing for prompt injection (direct and indirect), tool-call and argument manipulation, agent hijacking, memory/context poisoning, and privilege or credential escalation. * Build repeatable evaluation approaches for non-deterministic systems, including how to test, measure and report against outputs that vary run to run. * Define and own an approach for detecting, measuring and mitigating hallucinations in agent and LLM outputs, distinct from traditional functional-testing methods. Agentic Governance & Risk: * Own agentic AI risk identification and governance across an account, not a single application: build the risk view, the test strategy and the tooling recommendations that other teams can reuse. * Map findings and controls to recognised external frameworks (for example OWASP's agent-specific risk taxonomy, NIST's AI Risk Management Framework Govern function, and MITRE ATLAS) so ClearRoute's approach is defensible and auditable, * Distinguish and design controls for internal versus external (client-facing) views of agent behaviour, including how outputs are reviewed, sanitised or gated before release. * Define rollback and incident-response procedures for agentic systems, so a compromised or misbehaving agent can be safely withdrawn or reverted. * Track emerging regulatory expectations relevant to AI testing (for example EU AI Act provisions on adversarial and robustness testing) and translate them into practical test and governance requirements. Cross-Team & Organisational Scope: * Work across delivery teams and accounts, acting as the connective view on agentic security testing rather than being embedded in a single application or team * Recommend and help select tooling for agentic security testing and monitoring, and advise delivery teams on how to embed it into their workflow * Represent ClearRoute's agentic security posture with internal stakeholders and, where relevant, clients * Train and upskill existing security engineers over time so agentic testing and automation becomes a capability the wider team owns, not a single specialist ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Guiding Agentic AI with Vue](https://www.wearedevelopers.com/videos/2033-guiding-agentic-ai-with-vue) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Building Agents Securely at Scale - Alfonso Graziano](https://www.wearedevelopers.com/videos/1862-building-agents-securely-at-scale-alfonso-graziano) - [How to Stop Your Agents From Going Rogue - Arnav Gupta](https://www.wearedevelopers.com/videos/2152-how-to-stop-your-agents-from-going-rogue-arnav-gupta) - [Agentic AI - From Theory to Practice: Developing Multi-Agent AI Systems on Azure](https://www.wearedevelopers.com/videos/1532-agentic-ai-from-theory-to-practice-developing-multi-agent-ai-systems-on-azure) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 210: AI Agents Are Go! Is MCP Dead? LLMs Crack Anonymity](https://www.wearedevelopers.com/magazine/709-dev-digest-210-ai-agents-are-go-is-mcp-dead-llms-crack-anonymity) - [From Prototype to Production: Build AI Agents with This Free 4-Course Learning Path](https://www.wearedevelopers.com/magazine/655-from-prototype-to-production-build-ai-agents-with-this-free-4-course-learning-path) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)