Security Engineer – Agentic AI Security
Red Alpha Cybersecurity · Singapore
The team is hiring a hands-on security engineer to build and security-test a realistic clinical agentic AI system. The target system is a clinical assistant that retrieves and reasons over synthetic patient records and clinical guidelines, drafts clinical documentation, and answers clinician queries. Human confirmation will be required before any action that writes back or sends information. The engineer will build the prototype and conduct a structured security assessment covering the key attack surfaces of agentic AI, with a focus on practical security assurance for healthcare deployment. What the role involves Build the clinical agent Implement a clinical agent using LangGraph, with MCP, RAG and synthetic patient recordsImplement basic access controls, data protection and human-in-the-loop action gatingDocument the architecture, trust boundaries and security assumptions Threat model and red-team Develop a threat model covering the agent, tools, memory and data flowsConduct structured security testing covering: indirect prompt injection; malicious/poisoned MCP tools; memory poisoning; action-gate bypass and unauthorised tool use; sensitive-data exfiltration; code-execution risks, where applicableAdapt existing agentic-AI security benchmarks and tools where appropriate Findings and mitigation Document security findings, severity and attack pathsRecommend and, where feasible, validate practical mitigationsProvide deployment recommendations for secure use of agentic AI in clinical settings Key Deliverables Working clinical agent security testbed (LangGraph + MCP + RAG + synthetic data)Threat model and documented attack surfaceReusable red-team/security evaluation harnessSecurity assessment report with findings, mitigations and deployment recommendationsPractical security testing guidelines for future healthcare agentic-AI systems