Rodeo
Get started

SanaInfotech

AI Security Engineer — AgentLatch

England
Posted about 19 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Location: [Hybrid] · Type: [Full-time / Contract] · Level: [Mid / Senior]

About AgentLatch

AI agents now run shell commands, write files, call APIs and act for users, often with little human oversight. AgentLatch is an open-source, local-first security scanner that finds risky patterns in AI-agent projects before they're deployed.

It analyzes Python agent code, prompts, tool definitions and agent manifests, and maps findings to the OWASP Top 10 for Agentic Applications 2026. It runs as a CLI, a pre-commit hook and a GitHub Action on the GitHub Marketplace, and reports in terminal, JSON and SARIF formats.

We're an early-stage project with a clear principle: the code we scan is untrusted. Scans stay local, nothing is uploaded, and we never overstate what a clean scan means.

The role

You'll design and build the detection rules at the core of AgentLatch. You'll study how agents built with LangChain, LangGraph, CrewAI, AutoGen, the OpenAI Agents SDK and MCP actually fail. You'll turn those failure modes into precise, low-noise static checks and test them against real open-source agent projects.

Your first major goal is closing our coverage gaps in the OWASP Agentic Top 10:

  • ASI06 Memory & Context Poisoning
  • ASI07 Insecure Inter-Agent Communication
  • ASI10 Rogue Agents

deepening our early checks for ASI08 Cascading Failures and ASI09 Human-Agent Trust Exploitation

What you'll do

  • Build detection rules with Python AST analysis and data-flow (taint) tracking. Examples: untrusted web content flowing into agent memory or vector stores, MCP and agent-to-agent connections without authentication, agents running without approval or iteration limits.
  • Extend our taint analysis to work across files and modules, and keep it fast on large codebases (thousands of files).
  • Research agent attack techniques, including indirect prompt injection, tool poisoning, memory poisoning, MCP descriptor spoofing and privilege escalation through tools. Turn them into checks and test cases.
  • Measure and reduce false positives by benchmarking rules against popular open-source agent frameworks and real-world projects.
  • Add coverage for new frameworks and file types: MCP config files, TypeScript/JavaScript agents and agent workflow definitions.
  • Write clear documentation for every rule: what it detects, how it maps to OWASP, and its known blind spots.
  • Work in the open: review contributions, triage reported issues and vulnerabilities, and help shape the roadmap.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

What you'll bring

Required

  • 3+ years in application security, security engineering or security research [adjust for level]
  • Strong Python, including comfort with the ast module or other parsers and static analysis
  • Hands-on experience building with LLM agent frameworks (LangChain/LangGraph, CrewAI, AutoGen, OpenAI Agents SDK or similar)
  • A solid grasp of LLM-specific threats: direct and indirect prompt injection, excessive agency, tool misuse, insecure output handling
  • Familiarity with the OWASP Top 10 for LLM Applications and/or Agentic Applications
  • A track record of building detections with high signal and low noise, and the judgment to say when a check isn't reliable enough to ship
  • Clear technical writing

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Nice to have

  • Experience building or extending SAST tools (Semgrep, CodeQL, Bandit or similar), or writing data-flow and taint analysis
  • Knowledge of the Model Context Protocol (MCP) and agent-to-agent (A2A) protocols
  • Experience with SARIF, GitHub code scanning, GitHub Actions or pre-commit tooling
  • Published security research, CVEs, CTF experience or open-source security contributions
  • TypeScript/JavaScript static analysis experience
  • AI red-teaming experience with tools like garak or promptfoo

How we work

  • Local-first and privacy-respecting: no telemetry, no LLM calls on user code, and network use only when the user opts in.
  • Honest about limits: a clean scan is not a security guarantee, and our docs and output say so.
  • Tested and reviewed: every rule ships with positive and negative tests, documentation and an OWASP mapping.
  • Open source: your work is public, used by the community and credited.

How to apply

Send your CV or LinkedIn profile along with one of these:

  • a link to security research, a detection rule or an open-source contribution you're proud of, or
  • a short write-up (one page or less) on how you would statically detect one OWASP Agentic risk, such as memory poisoning, and where that approach would fall short.

AgentLatch is an independent project, not affiliated with or endorsed by OWASP.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

England, United Kingdom

Sign up to applySee more jobs like this