The team is hiring a hands-on security engineer to build and security-test a realistic clinical agentic AI system.
The target system is a clinical assistant that retrieves and reasons over synthetic patient records and clinical guidelines, drafts clinical documentation, and answers clinician queries. Human confirmation will be required before any action that writes back or sends information.
The engineer will build the prototype and conduct a structured security assessment covering the key attack surfaces of agentic AI, with a focus on
practical security assurance for healthcare deployment.
What the role involves
Build the clinical agent
Implement a clinical agent using
LangGraph
, with
MCP
, RAG and synthetic patient records
Implement basic access controls, data protection and human-in-the-loop action gating
Document the architecture, trust boundaries and security assumptions
Threat model and red-team
Develop a threat model covering the agent, tools, memory and data flows
Conduct structured security testing covering: indirect prompt injection; malicious/poisoned MCP tools; memory poisoning; action-gate bypass and unauthorised tool use; sensitive-data exfiltration; code-execution risks, where applicable
Adapt existing agentic-AI security benchmarks and tools where appropriate
Findings and mitigation
Document security findings, severity and attack paths
Recommend and, where feasible, validate practical mitigations
Provide deployment recommendations for secure use of agentic AI in clinical settings
Key Deliverables
Working
clinical agent security testbed
(LangGraph + MCP + RAG + synthetic data)
Threat model
and documented attack surface
Reusable
red-team/security evaluation harness
Security
assessment report
with findings, mitigations and deployment recommendations
Practical
security testing guidelines
for future healthcare agentic-AI systems
Red Alpha is a cybersecurity talent development company. Our mission is to develop next-generation cybersecurity talents. Our Alpha Programmes are geared towards transforming aspiring cyber defenders into competent specialists ready to take on real-world cyber domain. Our wide network of public and private organisations trusts us and our talents to help build their cybersecurity capacity. Together, we are redefining the future of the cybersecurity frontier.