THE OPPORTUNITY
Apollo Research works with most frontier AI companies (OpenAI, Anthropic, Google, Meta, Thinking Machines and others) to test their models before deployment and collaborate on fundamental scheming research. Our coding agent security product, Watcher, is deployed in production and monitors billions of agent tokens per month across engineering teams at agent-building scale-ups and enterprises.
We’re hiring a Product Security Engineer to make Watcher safe to deploy at enterprises. You will own the day to day of Watcher’s security posture, from product security standards to the security conversations with our customers. You will work closely with the internal Infra & Security team who owns Apollo’s overall security roadmap and priorities .
KEY RESPONSIBILITIES
Design, build, and operate Watcher’s core security controls: identity and access management, infrastructure and cloud security, endpoint management, and incident response.
Build paved roads that make the secure path the default, easy path
Establish and advocate for security practices across Apollo, and build the organizational trust needed for people to adopt them, communicating security decisions and tradeoffs clearly along the way.
Evaluate vendors and tooling, make build-vs-buy calls on security infrastructure, and assess vendor security posture before adoption.
Lead major security projects end to end, from ideation through implementation and rollout.
Own security questionnaire responses, product security whitepapers, and support for customer pen-tests.
Own the technical content of customer-facing communications during incidents.
Collaboratively define and shape Watcher’s security roadmap and priorities with the Apollo Infrastructure & Security team
Join customer/prospect calls to understand security needs firsthand, and map them onto the AI Security & Control Researcher's threat models and failure mode library.
Maintain awareness of how enterprises currently secure coding agents (or don't), what tools they use (SIEM, DLP, CSPM), and how Watcher fits into their existing stack.
Understand which failure modes are the biggest problems for security buyers, and prioritize systematically what's most useful to solve; feeding that buyer signal into the AI Security & Control Researcher's failure mode prioritization.
Security Engineering & Operations
Support Product Strategy
JOB REQUIREMENTS
5+ years in security roles in a hands-on technical capacity (not purely GRC/compliance). Able to read code, understand infrastructure, and evaluate technical controls, not just write policies.
Engineering mindset: you treat security as an engineering problem, capable of building custom solutions rather than gluing together off-the-shelf tools. You prioritize automation and systems-level thinking, and are comfortable leveraging AI to accelerate development.
Direct experience with application security, cloud security, or product security. ideally having owned or significantly contributed to the security posture of a product handling sensitive customer data.
Experience in a security vendor or security product company. Building security products is different from consuming them, and someone who has done both will bridge the gap between "what CISOs want" and "what we can actually build" more effectively.
Comfortable working in a small, fast-moving team, context-switching between hands-on security work and strategic product thinking within the same week.
Strong written communication, this role produces security questionnaire responses, whitepapers, and incident communications that need to be clear and precise.
Strong understanding of enterprise security buyer concerns, ideally from having been a security engineer or leader at an organization that buys security tooling, or from working closely enough with those buyers to internalize their priorities.
Experience with incident response, specifically leading a real security incident through to resolution and customer communication.
Experience with AI/ML systems security or LLM security.
Must-haves
Nice-to-haves
REPRESENTATIVE PROJECTS
Design a security roadmap for keeping Watcher's customer data secure: Watcher runs on top of coding agents and accesses highly sensitive information; ensure that data is stored securely and the attack surface Watcher itself introduces is as small as possible.
Stand up product security standards for the product engineering team: code review security checklists, dependency scanning, secrets management in CI/CD, and container hardening that engineers will actually use.
BENEFITS
This role offers market competitive salary, equity, and competitive benefits.
Salary: San Francisco: $227,000 - $296,000; London: £152,000 - £199,000. We will be looking to meaningfully raise salaries soon.
Our engineers effectively have an unlimited token budget. If a better result costs more compute, use it.
Flexible work hours and schedule
Unlimited vacation
Unlimited sick leave
Up to 6 months of paid parental leave
Comprehensive health, dental and vision insurance
Retirement savings with competitive employer matching (e.g. 401(k) for US employees)
Lunch, dinner, and snacks are provided for all employees on workdays
Paid work trips, including staff retreats, business trips, and relevant conferences
A yearly $1,000 (USD) professional development budget
Relocation support and visa fees (if applicable)
LOGISTICS
Time Allocation: Full-time
Location: This is an in-person role working out of our London or San Francisco office. We offer flexible working hours and some wfh arrangements.
Visa sponsorship: We sponsor visas in both the UK and US. Sponsorship isn't guaranteed for every role or candidate, but if we make you an offer, we'll work with you to find the right visa route.

