Description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Data Analytics & Computational SciencesJob Sub Function:
Data ScienceJob Category:
Scientific/TechnologyAll Job Posting Locations:
Barcelona, Spain, Madrid, SpainJob Description:
Johnson & Johnson Innovative Medicine is recruiting a Senior Scientist, AI Safety to join our Data, Data Science & AI organization in Madrid or Barcelona. We work in a hybrid work model which means 3 days per week in the office.
This is a newly created scientific role, reporting directly to the Scientific Fellow, AI Safety.
Agentic AI is becoming central to pharmaceutical R&D—from discovery and translational science to development and regulatory work—where evidence standards are rigorous and errors can ultimately affect patient safety and outcomes. Our GenAI Platform supports that shift across a rapidly expanding population of autonomous workflows. Safety at this scale cannot be retrofitted through checks written into individual applications; it must be a property of how these systems are built.
You will define how pharmaceutical R&D agentic AI can be governed through provable controls and continuously tested through adversarial assurance—then use that evidence to shape safety-native AI architectures in which safeguards are designed in from the start. The role spans three connected mandates:
- Provable controls. Define deterministic, explainable controls that persist throughout agentic workflows.
- Adversarial assurance. Continuously test safeguards against credible failure scenarios and produce defensible evidence.
- Safety-native architecture. Investigate and implement pre- and post-training safety alignment and defense-in-depth techniques to make agentic AI safe by construction for regulated pharmaceutical R&D.
This is a hands-on scientific role. You will set the technical direction, build the prototypes that prove it, and carry the results into the platform with our engineering partners.
In partnership with cross-functional teams, including the Johnson & Johnson Gen AI, Technology and Infosec teams, you will translate safety requirements into scalable controls, assurance, and safety-native AI architectures.
Key Responsibilities
Controls & Deterministic Enforcement
- Design machine-readable control policies that govern agent actions, tool use, data access, and information flow across agentic workflows.
- Implement deterministic policy enforcement for high-impact agent actions, with auditable decisions and defined human-approval paths.
- Enable domain and system owners to author, test, and maintain controls through accessible policy interfaces.
Continuous Adversarial Assurance
- Develop continuous red-teaming methods for agentic AI, combining established AI threat models with pharmaceutical R&D failure modes.
- Embed adversarial evaluation into the GenAI Platform to continuously test models, agents, tools, and end-to-end workflows.
- Define evaluation protocols, adjudication criteria, and evidence thresholds that distinguish demonstrated safety properties from unverified claims.
Safety-Native Architecture & Alignment Research
- Research and prototype safety-native architectures that constrain agent behavior through layered technical controls.
- Evaluate pre-training data interventions and post-training methods—including supervised fine-tuning, preference optimization, and safety tuning—for regulated scientific use cases.
- Translate scientific, quality, privacy, and regulatory requirements into testable system specifications for models, agents, tools, and runtime controls.
Evidence, Accountability & Partnership
- Define the accountability bar for this work and the measures that demonstrate it is met, so claims about safety rest on evidence rather than assertion.
- Ensure control decisions are traceable and reconstructable as audit evidence for scientific, quality, and regulatory review.
- Partner with R&D scientists, platform engineering, and the security, privacy, legal, and quality functions; set the scientific direction for a small cross-functional team and represent the work externally through publications and standards contributions.
What This Role Is Not
- Not frontier model development. We are not pre-training foundation models at scale. The research question is how alignment and architecture should be adapted so that the models and platforms available to us are safe for pharmaceutical R&D.
- Not a replacement for existing controls. Identity, access management, classification, lineage, and source-system controls remain owned by their teams. This work composes on top of them rather than re-implementing them.
- Not a compliance or audit function. You build the mechanisms that produce auditable evidence; you are not the second-line reviewer who signs off on it.
- Not a guardrail-prompt role. Safety here is architectural and enforcement is deterministic. A system prompt asking a model to behave is not a control.
- Not an enterprise-wide rollout role at hire. Scope begins with selected R&D workflows. Breadth follows evidence.
- Not people leadership at hire. This is an individual-contributor scientific role on a small founding team.
You Might Be Right If
- You have built AI systems where success required verifying a safety or behavioral property, not merely generating a plausible output.
- You understand AI alignment and safety methods and can distinguish what transfers to regulated scientific domains from what requires domain-specific adaptation.
- You do not treat model-generated explanations or chain-of-thought as assurance evidence; you design independent behavioral and system-level tests.
- You have applied policy-as-code, information-flow control, formal methods, or provenance systems to govern agent actions, tool use, and data access—and understand that policy exceptions are a primary attack surface.
- You have adversarially evaluated deployed AI systems, reproduced failure modes, and reported findings independently of the teams that built them.
- You can detect evaluation leakage, overfitting, weak baselines, and test-set artifacts before they are mistaken for genuine safety performance.
- You treat unusable safeguards as a safety failure because controls that disrupt scientific work will be bypassed or disabled.
- You want to advance AI safety where model and agent failures can affect scientific evidence, regulatory decisions, and patient outcomes.
Key Qualifications
- PhD in computer science, AI/ML, applied mathematics, or a closely related technical field—required.
- At least one year of post-PhD research or industry experience developing and deploying AI/ML, autonomous-agent, or security-critical systems.
- Deep, hands-on expertise in agentic AI, including foundation models, retrieval-augmented generation, tool orchestration, memory, planning, multi-agent frameworks, and associated failure modes.
- Demonstrated research or applied expertise in AI safety and alignment, such as supervised fine-tuning, preference optimization, safety tuning, adversarial evaluation, interpretability, or scalable oversight, including their limits in specialized domains.
- Demonstrated expertise in at least one of the following: policy-as-code and authorization; adversarial machine learning and AI red teaming; information-flow or data-access control; provenance and lineage; formal specification or verification.
- Strong AI engineering skills, including prototyping evaluation and control methods, building reproducible experiments, and writing production-ready code.
- Excellent written and verbal communication, with the ability to present technically defensible AI safety arguments to scientific, engineering, and executive stakeholders.
- Scientific rigor in characterizing model and agent behavior, including uncertainty, limitations, failure conditions, and the strength of supporting evidence.
Preferred Qualifications
- Published or recognized work in top-tier journals/conferences in AI safety, alignment, adversarial ML, verified systems, information-flow control, or human oversight.
- Experience adapting foundation models to scientific domains and testing whether safety properties persist.
- Hands-on experience with policy engines, authorization languages, or formal policy specifications.
- Familiarity with AI threat and governance frameworks, including MITRE ATLAS, OWASP LLM guidance, NIST AI RMF, ISO/IEC 42001, or the EU AI Act.
- Experience with data classification, de-identification, and privacy-preserving ML, including their limitations.
- Experience deploying AI in life sciences or another regulated, high-stakes domain.
- Familiarity with GxP, data integrity, and validation of AI-enabled computerized systems.Experience evaluating third-party AI safety, evaluation, or control technologies.
- Experience building reusable AI safety capabilities adopted across teams.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers , internal employees contact AskGS to be directed to your accommodation resource.
Required Skills:
Preferred Skills:
Advanced Analytics, Business Intelligence (BI), Coaching, Collaboration, Critical Thinking, Data Analysis, Database Management, Data Privacy Standards, Data Reporting, Data Savvy, Data Science, Data Visualization, Econometric Models, Process Improvements, Technical Credibility, Technologically Savvy, Workflow AnalysisThe anticipated base pay range for this position is:
€55.400,00 - €87.860,00Benefits:
In addition to base pay, we offer the following benefits*: an annual bonus with set target (% of pay) depending on pay grade / location, where the actual amount is based on the employees’ and companies’ performance of the previous calendar year, or sales commissions. Moreover, we offer vacation days, parental leave for a minimum of 12 weeks, bereavement leave, caregiver leave, volunteer leave, well-being reimbursement, programs for financial, physical and mental health. We also offer service anniversary and recognition awards, and subject to the terms of their respective plans, employees - and in some location’s eligible dependents - can participate in several insurance plans. For more information, visit Employee benefits | Supporting well-being & career growth | Johnson & Johnson Careers.
*This is for informative purposes only. Amounts and actual benefits may vary by location and are subject to change.

