About this role
Start date: February 2027 · Duration: 6 months
Please include your latest academic transcripts with your application. Applications submitted without transcripts will not be considered.
With protocols like MCP, an AI agent is no longer a single application: it is assembled from tools such as a mail connector, a database, a document store, a ticketing system or a code interpreter. Each tool is reviewed on its own, but the risk comes from the combination. An agent that can read confidential data and send emails can leak that data; an agent that reads untrusted web content and has write access can be tricked into acting on instructions that did not come from its user.
Today these combinations are checked by hand, if at all. In this 6-month internship or master thesis starting in February 2027, you will conduct applied research to build the equivalent of a firewall rule for an agent's toolset: a way to describe what each tool can read and write, rules for allowed combinations, a check before deployment, and monitoring of tool calls at runtime.
Your tasks
- Formulate the research questions: what can go wrong when tools are combined, which existing security models can be reused, and what is genuinely new
- Define a model describing tools by what they read and write, the sensitivity of the data they reach, and how much their output can be trusted
- Design a way to express rules over that model and refine them against realistic cases
- Build an analyzer that accepts or rejects a set of tools before deployment, and allows, restricts or blocks tool calls at runtime
- Add monitoring of tool calls with warnings, human escalation and an explainable trace
- Test the approach on realistic setups and adversarial cases, measure security gained versus usefulness lost, and synthesize results in a report
What we offer
- A dynamic, collaborative workplace with a highly motivated, multicultural team working across international sites
- The chance to work on what could be the next generation of agentic security architecture
- Internal coding events such as Hackathons and Brownbag sessions, plus our technical blog
- Monthly After-Works organized at each location
About your profile
- Interest in Large Language Models and Generative AI
- Some proficiency with Python and agentic technologies (e.g. LangChain, MCP)
- Basic understanding of IT security concepts (authentication, authorization, access control)
- Ability to work autonomously on an open research problem and structure your own approach
- Good written and spoken French and English