Six months securing AI systems: prompt injection, scoped access, audit trails and the boring controls that matter.
About the Role
Security work on systems that are genuinely new. Our AI agents act inside real business systems, which means the interesting attack surface is not a login form, it is what happens when a model is persuaded to do something it should not.
What You'll Do
Test AI agents and chatbots for prompt injection and jailbreaks
Review credential scoping so a compromised component cannot reach far
Help build and check audit logging on systems that take real actions
Run dependency and configuration reviews across our apps
Write up findings clearly enough for an engineer to act on them
Help harden public endpoints against abuse and rate-limit evasion
What You'll Bring
Final-year student or recent graduate in CS, IT or a related field
Understanding of common web vulnerabilities and how they are exploited
Comfort in a terminal and reading code you did not write
Curiosity: security is mostly asking what happens if I do the unexpected thing
Available for a 6-month full-time internship
Nice to Have
CTF participation or a security writeup you are proud of
Familiarity with Burp Suite, OWASP ZAP or similar
Any exposure to LLM security or AI red-teaming
What You'd Build
These aren't hypothetical projects, they're live products you can try before your first interview.