Principal GRC Engineer
9 hours ago
Slough
About The AI Security Institute The AI Security Institute is the world's largest and best-funded team dedicated to understanding advanced AI risks and translating that knowledge into action. We’re in the heart of the UK government with direct lines to No. 10 (the Prime Minister's office), and we work with frontier developers and governments globally. We’re here because governments are critical for advanced AI going well, and UK AISI is uniquely positioned to mobilise them. With our resources, unique agility and international influence, this is the best place to shape both AI development and government action. About The Team Security Engineering at the AI Security Institute (AISI) exists to help our researchers move fast, safely. We are founding the Security Engineering team in a largely greenfield cloud environment, we treat security as a measurable, researcher centric product. Secure by design platforms, automated governance, and intelligence led detection that protects our people, partners, models, and data. We work shoulder to shoulder with research units and core technology teams, and we optimise for enablement over gatekeeping, proportionate controls, low ego, and high ownership. What You Might Work On • Help design and ship paved roads and secure defaults across our platform so researchers can build quickly and safely, • Build provenance and integrity into the software supply chain (signing, attestation, artefact verification, reproducibility), • Support strengthened identity, segmentation, secrets, and key management to create a defensible foundation for evaluations at scale, • Develop automated, evidence driven assurance mapped to relevant standards, reducing audit toil and improving signal, • Create detections and response playbooks tailored to model evaluations and research workflows, and run exercises to validate them, • Threat model new evaluation pipelines with research and core technology teams, fixing classes of issues at the platform layer, • Assess third party services and hardware/software supply chains; introduce lightweight controls that raise the bar, • Translate regulatory frameworks (e.g. GovAssure, CAF) into programmatic controls and technical artefacts, • Build and maintain a continuous control validation and evidence pipeline, • Develop and own a capability-based risk management approach aligned to AISI's delivery model, • Maintain the AISI risk register and risk acceptance/exception handling process, • Act as the key interface for DSIT governance, policy, and assurance stakeholders, • Work cross-functionally to ensure risk and compliance are embedded into AISI delivery lifecycles, • Extend controls and evidence to the frontier AI model, • Integrate AI safety evidence (e.g., model/dataset documentation, evaluations, red-team results, release gates) into automated compliance workflows, • Define and implement controls for model weights handling, compute governance, third-party model/API usage, and model misuse/abuse monitoring, • Staff or Principal-level engineer or technical GRC specialist, • Experience in compliance-as-code, control validation, or regulated cloud environments, • Familiar with YAML, GitOps, structured artefacts, and automated policy checks, • Equally confident in engineering meetings and policy/gov forums, • Practical understanding of frontier AI system risks and artefacts (e.g., model evaluations, red-teaming, model/dataset documentation, release gating, weights handling) sufficient to translate AI policy into controls and machine-checkable evidence, • Translating policy into technical controls, • Designing controls as code or machine-checkable evidence, • Familiarity with frameworks (GovAssure, CAF, NIST) and AI governance standards (NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894), • Experience building risk management workflows, including for AI-specific risks (model misuse, capability escalation, data/weights security), • Incredibly talented, mission-driven and supportive colleagues., • Direct influence on how frontier AI is governed and deployed globally., • Work with the Prime Minister’s AI Advisor and leading AI companies., • Pre-release access to multiple frontier models and ample compute., • Extensive operational support so you can focus on research and ship quickly., • If you’re talented and driven, you’ll own important problems early., • 5 days off learning and development, annual stipends for learning and development and funding for conferences and external collaborations., • Freedom to pursue research bets without product pressure., • Modern central London office (cafes, food court, gym) or option to work in similar government offices in Birmingham, Cardiff, Darlington, Edinburgh, Salford or Bristol., • Hybrid working, flexibility for occasional remote work abroad and stipends for work-from-home equipment., • At least 25 days’ annual leave, 8 public holidays, extra team-wide breaks and 3 days off for volunteering., • Generous paid parental leave (36 weeks of UK statutory leave shared between parents + 3 extra paid weeks + option for additional unpaid time)., • On top of your salary, we contribute 28.97% of your base salary to your pension., • Level 3: £65,000–£75,000 (Base £35,720 + Technical Allowance £29,280–£39,280), • Level 4: £85,000–£95,000 (Base £42,495 + Technical Allowance £42,505–£52,505), • Level 5: £105,000–£115,000 (Base £55,805 + Technical Allowance £49,195–£59,195), • Level 6: £125,000–£135,000 (Base £68,770 + Technical Allowance £56,230–£66,230)