Graduate Data Analyst
- Hiring from
- United Kingdom
- Work type
- Hybrid
- Posted
- Sep 30, 2026
About Outerlimit
Outerlimit is one of the most exciting UK startups to join right now. We help organisations stay in control of the AI agents running across their business. We find what's there, set rules for what those agents can do, and give security teams the visibility they need to act. Our customers are deploying agents at scale across Microsoft Copilot Studio, Azure AI Foundry, AWS Bedrock, Anthropic Claude, and beyond. We make sure those agents are known, controlled, and easy to audit. We're building the universal security layer for agentic AI, and we think it's one of the most important problems in technology today.
The Role
Our Discover capability is the foundation of everything we do. Before you can govern an agent, you need to know it exists: who built it, what tools it can use, where it runs, and whether it's set up safely. Today we keep track of agents, tools, and surfaces across ten platforms using read-only connectors, and we're only getting started.
This is a hands-on role with plenty of room to experiment, bringing together cybersecurity, AI platforms, and product engineering. You'll own the research and prototyping that shapes what Outerlimit's Discovery capability can see and tell customers about their agents.
You'll work closely with our founders and engineering team, and your ideas will be heard from day one. We don't have a rigid hierarchy or a long approval chain. What we do have is a hard problem, a strong team, and a real commitment to helping you grow fast.
The work has two main parts:
- Connector breadth: finding out what data we can get from the APIs of the platforms our customers use (Microsoft, AWS, Anthropic, and others), and spotting which new signals would be genuinely useful for security and governance.
- AI Security Posture Management: once we've found an agent, what can its setup tell us about security or quality risks? Think missing scope definitions, weak spots for prompt injection, too many tool permissions, or overlapping topic routing, all checked consistently across a whole organisation.
What You'll Do
- Explore platform APIs: read the API docs for AI platforms (Copilot Studio, Azure AI Foundry, AWS Bedrock, Anthropic, LangChain, OpenAI, Google ADK, and others) and map out what data you can get, what's useful, and what's missing
- Prototype new connectors: build early versions of discovery connectors that pull in agents, tools, and surfaces from new platforms, using Outerlimit's existing connector setup
- Design posture checks: research and define security and setup checks we can run on the agents we find (for example, missing safety instructions, too many tool permissions, no human-in-the-loop controls, or exposure to prompt injection)
- Map findings to frameworks: link the issues we find to MITRE ATLAS, OWASP Top 10 for LLM Applications, and NIST AI RMF so customers understand the risk behind what we show them
- Write up findings: write clear technical notes on what each platform shares, which checks are possible, and why they matter to customers. These feed straight into the product roadmap
- Stay current: keep an eye on new agent platforms, new API features, and the changing AI security threat landscape, and share what you learn with the team
- Shape technical decisions: join architecture reviews, design discussions, and trade-off conversations with the whole team from early on
- Experiment and learn fast: we move quickly, test ideas, and learn from what doesn't work
What We're Looking For
Essential
- A degree in Cybersecurity, Computer Science, Electronic Engineering, Mathematics, Information Security, or a related STEM subject.
- A real curiosity about AI systems. You find yourself reading about how LLM agents work, what MCP is, and how tool-calling works
- Excited by the challenge of keeping AI behaviour safe and under control, whether that interest comes from security, systems design, or pure engineering
- Comfortable reading and working with REST APIs and JSON. You can pick up an API reference and understand what it's telling you
- Clear communication in writing, in conversation, and in code. You can explain a technical finding clearly to both an engineer and a product manager
- An analytical mindset. You can look at a set of API fields and reason about what's security-relevant and what isn't
- Understanding of concepts like prompt injection, jailbreaking, excessive agency, or LLM supply chain risk
- A structured, curious approach to unclear problems. You ask good questions before jumping to solutions
- Happy in a small team where ownership is broad and your contributions are genuinely felt
Desirable
- Familiarity with any of: Microsoft Copilot Studio, Azure AI Foundry, AWS Bedrock, Anthropic Claude, OpenAI Assistants
- Exposure to security frameworks: OWASP, MITRE ATT&CK/ATLAS, NIST
- Any experience with Python or .NET, even from coursework or personal projects
- Experience with cloud platforms (Azure, AWS) at any level
- Signs that you enjoy technical problems beyond your coursework, such as side projects, CTFs or hackathons, a final-year project that went deep, or open-source contributions
- We don't need prior industry experience. Internships and placements are a bonus, not a requirement, as we know access to them isn't equal
What You Won't Be Doing
This is not a SOC analyst role, a pen-testing role, or a pure software engineering role. You won't be writing production code from day one or responding to live incidents. You'll be researching, experimenting, and prototyping, and your work will directly shape what Outerlimit builds next.
Why This Role
- Work at the frontier: you'll work on AI security, a space that barely existed two years ago and is moving fast. The future of AI security isn't written yet, so come and help us write it.
- See your impact: your research goes straight into the product, with no big layer of management between your findings and what gets built. You'll be part of a small team where your work is visible and credited.
- Real ownership: Outerlimit is early-stage, so you'll have real ownership and real impact from day one, plus meaningful equity for everyone. When Outerlimit wins, you win.
- Build rare expertise: you'll get to know the major AI agent platforms in depth at a moment when that expertise is rare.
- Invest in your craft: our founders are invested in your long-term growth, and you'll have a real budget for conferences, courses, books, and gear.
- Get paid like it matters: top-of-market pay, with benefits built to attract the best.
- Work where you think best: in the office, or hybrid. You decide what works for you.
- Offices worth showing up for: flagship spaces in London King's Cross and New York City.
- Real connection, four times a year: the whole team comes together in one room at least once a quarter, building relationships you can't build online.
- Serious backing: we're funded by Evolution Equity Partners, AlbionVC, and Crane Venture Partners, who back companies built to lead.
Our Values
Our values shape how we work together every day. We'd love for them to feel like you too.
- Seek the truth: We're deeply curious, and we don't settle for the easy answer. Clarity beats comfort.
- We own it: No job is too small or too big. If something needs doing, we don't wait to be asked.
- Never complacent: Good enough today isn't good enough tomorrow. We hold ourselves to a standard that keeps moving, and we aim for relentless improvement.
- Do the right thing: Especially when it's hard, when no one's watching, and when we're under pressure.