About Ocean
Ocean is an email security company. Our research & detection team is the analytical core behind the product: we build AI systems that catch the attacks that slip past everyone else — phishing, social engineering, BEC, impersonation, AiTM/credential phishing, and AI-generated campaigns — and we back our customers' security teams with deep investigation and research.
About the role
We're hiring an AI Engineer to build autonomous agents at the heart of our detection work. You'll join a multi disciplinary research & detection team spanning three disciplines — cyber research, classical ML, and agent engineering — and you'll own the agent-building side: designing, shipping, and iterating on autonomous systems that investigate and detect email threats end-to-end.
This role is for a builder who gets excited by a new framework, invents solutions in a space that doesn't have a playbook yet, and turns detection and cyber insight into working agentic systems.
You need to be a strong engineer who understands how detection and attacks work, is genuinely energized by agents, and learns fast in a field that's changing every month.
Responsibilities
- Design and build autonomous investigation and detection agents on frameworks like deepagents / LangGraph — orchestration, tools, memory, and state — and take them to production with an eye on reliability, latency, and cost
- Fold detection and cyber understanding (phishing, social engineering, BEC, impersonation) directly into how the agents reason and decide
- Work hands-on with LLMs — prompting, tool/function calling, model routing, and evaluating agent behavior
- Partner with the cyber researchers and data scientists on the team to close detection gaps quickly
- Stay on top of a fast-moving space and bring new techniques back into the product
Requirements
- Strong, production-grade Python engineering
- Real enthusiasm for building LLM agents / agentic workflows (LangGraph, deepagents, LangChain, or similar) — hands-on experience or a proven drive to go deep, fast
- A working understanding of cyber / security — meaningful plus for email threats, phishing, BEC, or social engineering
- Creativity and initiative: comfortable inventing solutions where there's no established pattern
- Ability to learn fast and adapt — the agent space is young, and staying current (blogs, latest research, what shipped last week) is part of the job
- End-to-end ownership in a fast-moving startup environment
Nice to have
- Background in ML / classification, especially NLP or transformer-based models (not required — the core of this role is agent building, not model training)
- Experience with MCP servers, RAG, or online/incremental learning
- Experience with cloud infrastructure (GKE / Kubernetes) and observability (Datadog and similar)
- Experience with sandboxed / code-execution environments for agents
- Military-unit or equivalent cyber research background