Own the end-to-end platform architecture for Refractal’s Security Context Graph, designing APIs, SDKs, and operator tools to enable secure AI agent deployments. Focus on multi-tenant security, real-time observability, and customer integrations while shaping technical standards and product roadmaps. Requires deep expertise in backend systems, authentication, and high-assurance data modeling.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
About Us
Refractal is building security infrastructure for autonomous systems. Tomorrow’s attacks will use adaptive reasoning agents; cyber defenders need the right tools for adaptive defence. Refractal builds the Security Context Graph, which allows defenders to reason more effectively about risk and enforce controls.
Our founding team combines technical pedigree from MIT, NASA, Microsoft, and government with commercial experience in VC and startups. We have also been recognised by MIT's flagship CSAIL AI lab as part of CSAIL Alliances, as well as being selected as the only British AI Security company in Google's highly selective Gemini Cybersecurity Startup Forum. We are today working with leading, high-assurance AI startups and a European government to help secure their AI deployments.
The Mission
For most of the last decade, AI safety and security lived inside the frontier labs. It was seen as the preserve of the labs to ‘solve’ alignment at the model level, with too little consideration of downstream cybersecurity infrastructure.
2026 has ended this illusion. The gated release of Mythos, Cybersecurity over-refusal on Fable, and the incidents with Anthropic and OpenAI have all shown that the labs cannot be trusted to solve these problems alone. At the same time, the risks have moved beyond the models themselves: agents are being given credentials, tools, and decision-making authority faster than security can catch up, all while frontier models can be exploited for (or autonomously engage in) offensive cyber operations.
Europe is particularly vulnerable. With little domestic choice of frontier models, European defenders are forced to turn to either American models (and risk over-refusal mid-incident), or to Chinese models, which poses other governance questions.
Refractal is building a world-class team of researchers and product builders to galvanise AI and Cyber talent across Europe and build a leading company in AI Security.
The Role: Platform Engineer
As a Platform Engineer, you will own the core product platform from the external interface to the service and data layers. Your main focus will be the APIs and SDKs that customers use to connect Refractal to their systems. You will also build the FastAPI services, authentication, multi-tenant isolation, data contracts and event interfaces that support these integrations.
You will build customer onboarding, policy integration and operator tools. Refractal also has a dashboard that helps security teams inspect activity, review evidence, manage policy and act on enforcement decisions. The dashboard is powered by the core APIs and services that support customer integrations.
Searching for Development & Programming roles that provide visa sponsorship? Connect with international employers through Development & Programming Jobs with Visa Sponsorship opportunities actively seeking talented professionals.
You will work directly with the founders and early customers. You will convert operational security needs into simple and reliable platform interfaces. You will also help set the technical direction, engineering standards and product roadmap.
What You'll Work On
· Own the platform API and its SDKs. Define stable, versioned contracts, clear client interfaces, error behaviour, compatibility rules, documentation and examples.
· Design and build the FastAPI services behind these interfaces. Provide access to enforcement decisions, evidence, policies and red-team results.
· Own identity and access at the platform layer. This includes authentication, sessions, API keys, authorisation and multi-tenant access control. A tenant must never have access to another tenant's data.
· Design the platform's data and event interfaces. This includes read models, request and span records, real-time SSE streams and a tamper-evident audit ledger.
· Present security data accurately. The API, SDKs and user interfaces must clearly identify data that is missing, not measured or not captured. They must never create false values.
· Build the customer integration and onboarding flows. This includes tenant setup, policy binding, integrations, sign-in and API-key issue.
· Build the operator dashboard as a client of the platform API. It includes the agent-action heatmap, attacker trajectories, traces, policy compiler, decision traces and audit ledger.
· Own the build, test and deployment process. This includes API compatibility tests, browser smoke tests, the esbuild pipeline, Cloud Run and Cloud SQL.
· Work directly with customers. Understand their systems and operating processes, then convert these needs into clear product requirements.
· Define engineering standards for APIs, SDKs, components, tests and customer-facing quality.
What We Are Looking For
We need a product-minded platform engineer who takes end-to-end ownership. You can work from the data model to the external API, SDK and customer integration. You can also build operator tools when required.
You make complex systems clear and predictable. You understand that an incorrect permission, an unstable API or a misleading user interface can cause a serious security fault. You deliver small, correct changes and improve them with evidence. You do not spend months designing an abstraction before you test it. You use real system data and do not hide missing data with false or cosmetic states.
Explore our comprehensive directory of visa sponsorship jobs from employers worldwide who are ready to sponsor talented international professionals.
Most importantly, you want to build the platform that security teams use to deploy autonomous systems safely at scale.
Qualifications
We assess demonstrated ability, rather than a specific credential or number of years in industry.
You should have:
·Strong backend experience with HTTP APIs. Experience with Python and FastAPI, or similar tools, is preferred.
·Experience with observability and tracing systems. You can trace agent actions, tool calls, requests, spans and enforcement decisions across services.
·Experience with relational databases. This should include Postgres or SQLite, SQLAlchemy and database migrations.
·Experience in API design, versioning and compatibility. You can create SDKs, documentation and examples that make integration simple.
·A good understanding of authentication, sessions, API keys, authorisation and multi-tenant access control.
·Experience with data models, event streams, audit records and error handling.
·Good JavaScript and React skills. You can build and test an operator interface that uses the same APIs as customers.
·The ability to work independently, communicate clearly and take ownership of technically uncertain customer problems.
Particularly strong signals include:
·An external API or SDK that you owned from the data model to customer use.
·Experience with B2B or enterprise integrations, especially where trust, auditability or compliance was important.
Interested in opportunities specifically in United Kingdom? Discover our dedicated Visa Sponsorship Jobs in United Kingdom page featuring roles from top employers in this location.
·Experience with data-dense or real-time systems, such as security consoles, observability tools, event streams or SSE.
·Experience with containers, continuous integration and deployment, and cloud platforms such as GCP Cloud Run and Cloud SQL.
·Experience in AI security, cyber security or another high-assurance technical field.
·Open-source or side-project work that shows clear engineering decisions and good product judgement.
We do not expect any candidate to have worked across all of these areas.
What We Offer
·Competitive salary, meaningful founding equity, and a performance-linked bonus.
·Direct influence over the product, its architecture, and company direction.
·Access to real, high-consequence AI deployments rather than purely synthetic environments.
·The opportunity to establish Refractal's platform engineering function and grow into a senior technical leadership role.
·The chance to work directly with founders whose experience spans MIT, NASA, Microsoft, government, venture capital, and early-stage technology companies.
·London-based, with an in-person culture. We sponsor UK Skilled Worker and can assist with Global Talent visas.
How to Apply
Email careers@refractal-ai.com with your CV and a short note on the most interesting thing you have built and shipped, ideally something you owned end to end. Links to live products, open-source work, or write-ups are strongly encouraged.
Our process is fast: an intro call with the founders, a technical deep-dive on your past work, a short practical exercise, and an offer, typically within two weeks.
Similar Jobs
Explore other opportunities that match your interests