top of page
deep-divers.png

Heron AI Security
Research Fellowship

September - November 2026 | 10-12 Research teams | Commit 8 - 30 hours/week
Applications for our autumn cycle are now closed
Express interest in future cohorts


Collaborative projects at the intersection of Cybersecurity and frontier AI​, where experienced cybersecurity professionals join AI security field leaders to build concrete projects that secure transformative AI systems.

Remote-first, with access to coworking hubs in London, Tel Aviv, and San Francisco for those who want a desk and in-person community.

Why This Matters

AI systems have become deeply integrated into global infrastructure and this trend shows no sign of slowing. Society’s resilience will depend on how secure transformative AI is, from development through deployment. While many people are using today’s AI capabilities, far too few cybersecurity professionals are thinking about how rapidly AI will reshape society or working to mitigate the emerging and worrying threat models.

Projects and Expert Advisors

Projects are proposed and guided by field leaders in AI Security - leading researchers and engineers shaping how AI systems are secured.

Our vision is high quality and productive collaborations that produce publishable and impactful work in a short time frame. Cybersecurity professionals bring domain expertise; field leaders bring frontier-AI context. Together, they build proofs-of-concept, benchmarks, or defensive strategies.

brad.png
Brad Edwards

Architect & Researcher, Palo Alto Networks

Project

Reproducible-Purpleteam

Yossi.png
Yossi Gandelsman

Scientist, Reve.art and Assistant Prof, TTIC

Project

Gabriel_Matt.png
Gabriel Kulp + Matt Schultz

Fellow at the RAND Center on AI, Security, and Technology + Researcher

Project

Training-Leakage

Zainab_Evan.png
Zainab Majid + Evan Harris

Co-Founder, Asymmetric Security +
Agentic Systems Reasearcher 

Project

Dfir-Agents

sean_simon.png
Simon Lermen + Sean McGregor

AI safety researcher + Co-Founder and Lead Research Engineer, AVERI and Fellow, Harvard University

Project

Tiered-Disclosure

ben+shay.png
Shay Yahal + Ben Hagag

Co-founder, Stealth + AI Security Researcher @ Carnegie Mellon University & MATS

Projects

Containment-Redteam | | Cross-Monitor

Amir_Jannis_edited.png
Amir Sarid + Jannis Kirschner

AI Safety Researcher + Security Engineer, Niantic

Project

Backdoor-Inheritance

Jam_Jan_edited.png
Jam Kraprayoon + Jan Wehner

Senior Researcher, IAPS + Researcher at IAPS

Project

Insider-Honeypots

lisa+guy.png
Lisa Thiergart + Guy

Co-founder and Senior Director, SL5 Task Force + Member of Technical Staff at Security Level 5 Task Force

Projects

Encryptor-Risk | Enclave-Api

Amir+pingshan.png
Amir Sarid + Pingshan Zhang

AI Safety Researcher + GovAI Fellow, Ex-Microsoft

Project

Training-Custody

nitzan+christine_edited.png
Nitzan Shulman + Christine Lai

Head of Cyber, Heron + Cybersecurity R&D

Projects

Ot-Decoy

Itay Yona
Itay Yona

Founder, Mentaleap, ex-DeepMind

Projects

Cot-Leakage

Program Overview

Research teams will work on an impactful project proposed and guided by a frontier AI expert advisor, and produce publishable results, open-source prototypes, or technical reports by the end of the program.

Duration

3 months
September - November 2026

Research Teams

Expert advisor +
2-4 cybersecurity professionals + project manager + technical advisor

Time Commitment

Commitment of 8-30 hours
a week per person

Biweekly programming at either 15:00-16:00 UTC on Tuesdays or 18:00-19:00 UTC on Saturdays

Locations

Remote
Tel Aviv
London
San Francisco

Format

Two-stage research sprint

Workshop → Conference paper

Support

Research guidance / Compute / APIs / Community / Conference travel funding 

Who Should Join

We’re seeking experienced cybersecurity professionals (5 + years) interested in applying their skills to securing transformative AI systems. Ideal participants bring curiosity, technical depth, research experience and the desire to collaborate with AI researchers on real security problems.
Useful skill sets
  • Cryptography (ZK proofs, verifiable compute)
     

  • AI/ML implementation or agent security
     

  • Red-team operations and adversarial testing
     

  • Secure systems and infrastructure design
     

  • Building proof-of-concepts or attack simulations
     

  • For more specifics, check the projects! Each has unique needs which may be the perfect fit for your expertise

deep divers parallax.png

Focus Areas

AI Infrastructure and Hardware Security

Hardware-level protections (e.g. GPU secure boot, tamper-secure environments), cluster security and TEEs, research into Security Level 4 and SL5, low-bandwidth ML infrastructure

Technical AI Governance

Location attestation, offline licensing, workload attestation (proof of training), model usage verification

Adversarial & Model Security

Jailbreaks and prompt injections, mechanisms for independent audits, protections against model extraction, threat-modeling, backdoor discovery

AI Control & Containment

Zero-knowledge proofs for bounded behavior, containment paradigms, sandboxes, untrusted monitoring

Cybersecurity Evaluations & Demos

Offense–defense balance in AI-driven cyber ops, stealthy intrusion and persistence, real-world vulnerabilities and monitoring, searches for catastrophic misuse cases in the wild

Why Join

445e17d7-a921-416a-839a-7c1711193917.png
  • Apply your cyber skills to frontier AI: Expand your expertise and get hands-on experience working directly with frontier-model security challenges.

  • Build your research portfolio: Co-author papers suitable for top-tier AI security venues and conferences.
     

  • Create meaningful impact: Contribute to research on some of the most important AI security questions today.
     

  • Build your professional visibility: Connect with and be seen within the global AI security community.
     

  • Be part of a strong network: Get access to Heron’s mentorship and career connections.

Key Dates

June-July 2026

Applications open

Early August 2026

Teams announced

1 September 2026

Projects launched

September-November 2026

Weekly research meetings with experts, project manager and technical advisor

October 2026

Mid-project presentations and milestone submission

November 2026

Final submissions and showcase event.

Guaranteed presentation at AI Security Forum in Tel Aviv.

FAQ

Do I need an AI background?

No - strong cybersecurity or cryptography experience is what we value most.

Is this paid?

No, but all teams receive $1000+ in compute, as well as Claude Code Team Accounts for the duration of the Fellowship. In addition, we provide support for conference attendance (up to $5k per team)

Can I participate while working full-time?

Only if you can dedicate at least 8 hours per week.

What if I’m not matched?

You’ll stay in the Heron network for future projects and Forum extensions.

What is the application process?

The application process consists of the application form, a work trial and a short interview, after which candidates will be matched to projects based on team fit.

Can I receive financial support?

If financial support is a blocker, please apply anyways! We may be able to connect you with external funding or scholarships, although we can't commit ahead of time.

Ready to Secure the Future of AI?

bottom of page