Talent: the actual constraint
The hybrid security-research-plus-post-training hire is rarer and harder to compete for than capital in this category.
Capital is available for this category, at least at seed. The hire that actually gates a European AI cyber lab is a person who can do both offensive/defensive security research and ML post-training — exploit development and red-teaming on one side, RLHF/fine-tuning/eval-harness construction on the other. That combination sits at the intersection of two communities that historically never overlapped, and the people who already have it are disproportionately employed by the three US frontier labs. Most of this page's comp figures are directional, not survey data — the compensation-benchmarking sources needed to confirm them were unreachable during this research pass, and every number below is marked accordingly.
#Where the hybrid talent actually is
Ex-frontier-lab security/red-teaming teams. This is the dominant 2025–2026 hiring pattern visible in the funding data itself: RunSybil was founded by Ari Herbert-Voss, OpenAI's first security hire, and Vlad Ionescu, ex-Meta offensive-security red-team lead (Fortune). Irregular's own origin — testing frontier models before release — put its founders directly inside this hybrid job before they left to build a company. People who did "AI red-teaming" inside OpenAI, Anthropic, Google DeepMind, or Meta already did both halves of the job as a single role; poaching them is the fastest path to the skill, and it's exactly what every credible entrant in The AI cyber lab category has done.
CTF and offensive-security researchers who paired with, rather than became, ML specialists. XBOW's own account of how it built its system — assembling human hackers to help train it, per its CISO — suggests the more common on-ramp is pairing strong security researchers with ML engineers, not expecting security researchers to independently become post-training specialists. This matters for hiring sequencing: the first hybrid hire doesn't have to be a unicorn who already does both; team composition can manufacture the hybrid.
AIxCC alumni — a genuinely underexploited pool. DARPA's AI Cyber Challenge produced seven finalist teams whose systems combined exactly this skillset — LLM orchestration plus program analysis plus offensive security — under real time pressure, judged, and all published open source (see AIxCC: the closest thing to a proof). Team Atlanta (1st, $4M), Trail of Bits' Buttercup team (2nd, $3M), and Theori's RoboDuck team (3rd, $1.5M) are named, public, GitHub-verifiable track records of people who have already built the exact hybrid capability this category needs. This pool is underexploited because it's small — dozens of people across seven teams, not hundreds — regionally concentrated in the US academic/CTF scene, and not yet systematically recruited by anyone outside the US offensive-security cluster. A European lab that reaches out to AIxCC finalists directly, not through a generic job posting, is fishing where almost nobody else is fishing.
Academic groups. CISPA Helmholtz Center for Information Security (Saarbrücken) is Europe's largest dedicated security research institute, with faculty groups publishing in adversarial ML alongside classical security research — a genuine pipeline for both halves of the hybrid role. TU Darmstadt hosts one of Germany's strongest applied-crypto and systems-security groups (part of ATHENE, the joint TU Darmstadt/Fraunhofer/CISPA-adjacent national cybersecurity research center), with strong existing placement into German enterprise. Ruhr-Universität Bochum's Horst Görtz Institute for IT Security is Germany's other major security powerhouse, historically strongest in applied cryptography and hardware/embedded security. ETH Zürich runs Switzerland's top systems-security group — Florian Tramèr won the USENIX Security Test of Time Award in August 2026 for adversarial-ML work, individual credibility at the highest tier, though with no visible startup spinout on the Gray Swan model. EPFL's security and systems research groups round out the Swiss cluster, less individually documented here than ETH's, but part of the same talent pool. None of these institutions has produced a Gray-Swan-style commercial spinout focused on frontier-model cyber capability, despite CMU, Stanford, and Berkeley all doing exactly that in the US — either a warning that the European academic-to-startup pipeline doesn't convert the same way, or an opening nobody has taken yet.
#What this talent costs
Every compensation figure in this section is a directional estimate based on general 2025–2026 market knowledge, not a freshly sourced compensation survey — the benchmarking sources (Levels.fyi-equivalent data, a current comp-benchmarking firm) were not reachable during this research pass. Confirm against a live source before using any of these numbers in an offer or a fundraising deck.
| Role | Berlin (EUR, total comp) [unverified] | London (GBP, total comp) [unverified] | San Francisco (USD, total comp) [unverified] |
|---|---|---|---|
| Senior security researcher (offensive/red-team) | ~€90k–€140k | ~£100k–£160k | ~$220k–$350k |
| ML research engineer (post-training/RLHF) | ~€100k–€160k | ~£110k–£180k | ~$280k–$450k+ |
| Hybrid "AI-security researcher," senior/staff | ~€130k–€200k+ | ~£150k–£230k+ | ~$350k–$600k+ |
| Founding/early engineer equity | 0.5–2%+ typical | 0.5–2%+ typical | 0.25–1.5%+ typical (larger seed rounds dilute this) |
The honest gap: for the specific hybrid role, Berlin sits at roughly a third of San Francisco total comp, and meaningfully below London. That gap is the single largest practical obstacle to building an AI-security research team — as opposed to a go-to-market or generalist engineering team — in Europe. The roles most in demand are exactly the roles OpenAI, Anthropic, Google DeepMind, and Meta pay SF/London premiums to retain, which pulls the top of the CISPA/TU Darmstadt/Bochum/ETH pipeline toward the labs, or toward US-headquartered startups (RunSybil, Irregular) offering US-scale packages, rather than toward a standalone Berlin lab. This isn't a solvable-with-more-money problem at seed stage — a Berlin lab cannot out-bid Anthropic for the same candidate on cash alone.
#How a small European lab actually competes
Not on cash. On the things cash can't buy at a frontier lab:
Mission specificity. "Secure European/German critical infrastructure and AI deployments, independent of any single US frontier lab's incentives" is a mission a candidate inside OpenAI or Anthropic's internal safety team cannot claim — they work for the entity being evaluated. This is the same structural independence argument that makes METR credible (see The AI cyber lab category), applied to recruiting rather than evaluation contracts.
Publishing rights. Frontier-lab internal security researchers frequently cannot publish their most interesting findings — they're internal, proprietary, or gated behind a Responsible Scaling Policy review. A candidate who wants a public research record (papers, CTF writeups, conference talks) that follows them professionally, not the lab's, is a real draw a small lab structurally can offer. Make it an explicit, contractual commitment in an offer, not an implied cultural norm.
Equity that means something at this stage. At 0.5–2% for an early hire, equity in a lab with a real shot at the European gap described in Where the gaps actually are is a materially different bet than the same percentage inside a company already valued at hundreds of millions — but only if the story is concrete, paired with the specific The first 90 days and Go to market sequencing, not pitched abstractly.
Compute access. The single most concrete, checkable commitment a small lab can make: guaranteed API/inference budget for post-training and eval work, ideally backed by a frontier-lab partnership or credit arrangement — frontier labs have shown willingness to provide in-kind API credits to independent evaluators (METR's compensation structure is built on exactly this). A candidate choosing between a well-funded lab job and a startup weighs "will I actually have the compute" as heavily as salary; a specific, guaranteed compute budget beats a general promise of "resources."
A realistic Berlin-based strategy is to hire the security-research half of the team locally, where the CISPA/Bochum/Darmstadt/ETH pipeline is genuinely excellent and cost-competitive, and either hire the ML post-training half remotely at a smaller premium than a full SF relocation would cost, or deliberately not build frontier-scale post-training capability in-house at all — lean on API access to frontier models plus targeted fine-tuning, rather than competing for pretraining-scale ML research talent the lab cannot afford to retain against SF/London comp. See Post-training playbook for what this implies technically.
#The European CTF scene and how to recruit from it
Standard reference set of strong European CTF teams and security-research groups, as of the mid-2020s scene: hxp (Darmstadt/CISPA-adjacent, top-ranked globally on CTFtime for several consecutive years), saarsec (Saarbrücken/CISPA), KITCTF (Karlsruhe Institute of Technology), FAUST (Erlangen-Nürnberg), Sauercloud (a German all-star team), Eat Sleep Pwn Repeat (ESPR), and internationally, Perfect Blue (Japan, frequently collaborates with European teams) and France's École 42/Sorbonne/EPITA-affiliated teams. This reflects general CTF-scene knowledge, not a freshly verified 2026 CTFtime snapshot — verify current rosters against ctftime.org before using it in a recruiting plan.
Practical recruiting mechanics that follow from how this scene actually works: sponsor or co-host a CTF, don't just attend one — reputations are made and watched at these events, and sponsorship buys visibility before there's a job posting to react to. Hire through open-source contributions, not resumes — AIxCC's finalist systems are all public GitHub repos (see AIxCC: the closest thing to a proof and The open-source stack); a candidate's actual commits to Buttercup, ATLANTIS, or a comparable tool are a far better signal than a CV. École 42 (including 42 Berlin) is a source of strong generalist systems engineers, not published security researchers — less useful for the core hybrid hire, genuinely useful for early infrastructure roles that free the research hires to stay research-focused. CISPA and TU Darmstadt PhD students and postdocs are a direct pipeline — both institutions already place graduates into German enterprise and international security vendors; a lab offering publishing rights and mission specificity competes on genuinely different terms than a corporate offer.
#The first five hires, in order
- A senior security researcher with red-team or exploit-development depth, from the CISPA/Bochum/Darmstadt pipeline or the European CTF scene directly. Unlocks: a credible technical eval or benchmark artifact — the first rung on the credibility ladder in The AI cyber lab category — without outside contractors.
- A founding ML engineer with post-training/fine-tuning experience, likely the hardest and most expensive hire here given the Berlin-vs-SF comp gap; worth recruiting remotely rather than insisting on local-only. Unlocks: running and iterating on model evaluations, turning hire #1's expertise into a working product.
- A generalist infrastructure/platform engineer, plausibly from École 42. Unlocks: a real, demoable eval harness or red-team platform — the public artifact the credibility ladder depends on.
- A second security researcher, targeted from the AIxCC alumni pool or a comparable open-source-verifiable background. Unlocks: enough depth to run a public red-team competition (the Gray Swan Arena playbook) without pulling hire #1 off deeper research.
- A go-to-market/BD hire with government-relations experience (BSI, EU policy contacts) or direct frontier-lab relationships. Unlocks: the first paid pilot with a mid-tier or open-weight lab, per the sequencing in The AI cyber lab category, and the positioning in Germany: §202c and the Berlin question and EU regulation as a demand engine.
#What this means for us
- The hybrid hire is the real constraint, not capital — see Who funds this and at what price for why seed money is comparatively available in this category while the specific skillset is not.
- Don't try to out-bid frontier labs on cash for the ML post-training half of the team; compete on mission, publishing rights, equity story, and guaranteed compute access instead, and make all four concrete and contractual, not implied.
- AIxCC's finalist alumni are a small, public, underexploited recruiting pool — direct outreach based on specific GitHub commits beats a generic job posting, and almost nobody outside the US offensive-security cluster is doing this yet.
- Sequence the first five hires to produce a public artifact fast: security researcher first, ML engineer second, infrastructure engineer third — by hire three, there should be something demoable, because the credibility ladder in The AI cyber lab category runs on public artifacts, not headcount.
- Treat every comp figure on this page as directional; run a real Berlin/London/SF benchmarking exercise before making an offer, since the numbers here could not be confirmed against a live compensation-survey source in this research pass.
- CISPA, TU Darmstadt, and Ruhr-Bochum are genuinely strong and underpriced relative to SF/London for the security-research half of the hire — this is the clearest talent-cost advantage in the whole plan, and it should shape where the lab is physically based.