AI Red Team Engineer

Carnegie Mellon University

Pittsburgh (Allegheny County)

On-site

USD 150,000 - 210,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Carnegie Mellon University in the United States seeks an experienced AI Red Team Engineer to emulate adversaries against AI-enabled platforms. You will contribute to national security objectives by developing TTPs, scripting tools in Python, PowerShell, C, and BASH, and collaborating with CERT teams and partners.

Strong background in offensive cyber and AI security is required. Ideal candidates are seasoned professionals with penetration testing or red-teaming experience, capable of traversing

Qualifications

  • BS in CS/SE/IS with 8+ years, MS with 5+, or PhD with 2+ years.
  • Experience in penetration testing, red teaming, or exploit development.
  • Experience with at least one command-and-control framework (e.g., Cobalt Strike, Sliver).
  • Programming/scripting in Python, C, and BASH; willing to learn PowerShell.
  • Experience with reverse engineering tools (e.g., Ghidra, IDA Pro).
  • Able to read code and spot basic vulnerabilities without AI or fuzzing.
  • Strong TCP/IP knowledge and ability to explain network protocols.
  • Experience securing Linux and Windows systems; mobile OS appreciated.
  • Two of the following certifications: OSCP, CPTS, FORGE/RIOT, GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWNE.
  • Willingness to travel 25% outside official location.
  • Excellent communication skills; mentoring and knowledge sharing.
  • Able to obtain and maintain DoD security clearance.

Responsibilities

  • Red team real-world AI-enabled systems to support national security objectives.
  • Develop new tactics, techniques, and procedures for attacking AI-enabled systems.
  • Write tools in Python, PowerShell, C, and BASH for redteam operations.
  • Represent CERT portfolio and communicate with external mission partners and internal collaborators.

Skills

Penetration testing
Red teaming
Exploit development
Python
PowerShell
C
BASH
Cobalt Strike
Sliver
Reverse engineering
Ghidra
IDA Pro
TCP/IP
Wireshark
Linux
Windows
OSCP
CPTS
OSWE

Education

BS in CS/SE/IS, 8+ years
MS in CS/Engineering, 5+ years
PhD in CS/Engineering, 2+ years

Tools

NSAGhidra
IDA Pro
Ghidra
Nmap
Wireshark

Job description

Who We Are

SEI conducts research and development in software engineering,systems engineering, cybersecurity, and many other areas ofcomputing, working to introduce private-sector innovations intogovernment. The SEI works closely with defense and governmentorganizations, industry, and academia to continually improvesoftware-intensive systems. Its core purposes are to helporganizations improve software engineering capabilities, advancecybersecurity methods and technologies, and bring the discipline ofsoftware engineering to AI systems.

What We Do

The CERT Threat Analysis (TA) Directorate conducts research anddevelopment activities to identify, analyze, coordinate disclosure,and mitigate threats and vulnerabilities in systems and software.The TA Directorate is currently comprised of three teams:Artificial Intelligence ( AI) Security, Malware and VulnerabilityExploitation, and Platform and Mission Engineering . The AISecurity team works on advancing the state of the art in AIsecurity at a national and global scale. The Malware andVulnerability Exploitation (MVE) team works to improvecyber-tradecraft analysis within strategic target communities tocounter adversarial use of the Internet and related technologies .The v ulnerability side of MVE (home of the CERT CoordinationCenter) works with an expansive network of vendors, partners, andcollaborators to reduce the societal harm of vulnerable softwareand systems . The Platform and Mission Engineering team developsand maintains tools, environments, and operational support for themalware analysis, reverse engineering, vulnerability analysis, andAI security domains .

Position Summary

As an AI Red Team Engineer on the AI Security team, you will play acentral role in adversary emulation exercises and capabilitydevelopment for our mission partners. Due to our unique positionwithin the TA Directorate, the systems we red- team fall outsidethe realm of 'traditional' enterprise red teaming. Our targets arecommonly AI-enabled platforms used within national securitycontexts.

But this isn't a \"make the LLM say the bad thing\" type of AI redteam. We operate across multiple domains, meaning that our redteamers are expected to be experts in offensive cyber in additionto AI security. If you are experienced with offensive cybertradecraft and have an interest in breaking into AI, this could bea good fit. Most of our red teamers are actively takinggraduate-level technical courses at CMU and/or pursuing technicalcertifications. Perpetual learning is a core part of what wedo.

While our red team exists within a research organization, researchis only a portion of the work performed by our red team. Much ofthe work will involve red teaming real-world systems, sometimes atan aggressive cadence. This can involve planning and rehearsing redteam TTPs, traveling to field sites, and presenting relevantfindings. Like most red teams, we don't get to pick and choose ourtargets. This means that our red team needs to be well-rounded(both as individuals and as a team). Thus, we expect all applicantsto be savvy with both Windows and Linux, solid with TCP/IP, andhave some experience with penetration testing and/or redteaming.

What you’ll do:
  • Red team real-world AI-enabled systems (both the model and thehardware/software/network that it runs on) in support of nationalsecurity objectives .
  • Develop new tactics, techniques, and procedures for attackingAI-enabled systems and related software in order to better preparedefenders for real-world threats.
  • Write tools in Python, PowerShell, C, and BASH to enable redteam operations.
  • Represent the CERT technical portfolio of work and operations;communicate with external mission partners and internalcollaborators in concert with CERT directorates and teams .
Who you are:
  • BS in computer science, software engineering, networking,information systems, or a related technical field with eight (8)years of experience; MS in computer science ortechnical/engineering field with five (5) years of experience; PhDin computer science or technical/engineering field with two (2)years of experience or equivalent combination of training andexperience. Other educational backgrounds of a technical naturewith experience as described may be considered.
  • You have previous penetration testing, red teaming, or exploitdevelopment experience.
  • You have previous hands-on experience with at least one commandand control framework (e.g., Cobalt Strike, Sliver).
  • You have experience programming/scripting in Python, C, andBASH ( without the assistance of AI) and are willing to learnPowerShell.
  • You have experience with reverse engineering tools ( e.g. NSAGhidra, IDA Pro) .
  • You are able to read code and quickly spot basicvulnerabilities without the assistance of AI or fuzzing.
  • You are very familiar with TCP/IP and all layers of the OSImodel . You have experience using Wireshark and can explain howcommon network protocols work.
  • You have experience in assessing the security of both Linux andWindows systems. Experience with mobile ( e.g., Android) and otheroperations systems is also appreciated.
  • You have at least two of the following relevant certifications:OSCP, CPTS, FORGE/RIOT, GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE,CCNA, CWEE . Applicants without these certifications will still beconsidered if equivalent experience is clearly demonstrated duringtechnical interviews.
  • You have a willingness to travel (25%) outside of your officelocation to other SEI offices, sponsor sites, conferences, andoffsite meetings.
  • You have excellent communication skills (oral and written),particularly regarding technical communications withnon-experts.
  • You enjoy mentoring and cross-training others and sharingknowledgewithin the broader community.
  • You will be subject to a background investigation, and you musthave the ability to obtain and maintain a Department of Warsecurity clearance.
Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full time/Part time

Full time

Pay Basis

Salary More Information:

  • Please visit “ Why Carnegie Mellon ” to learn more aboutbecoming part of an institution inspiring innovations that changethe world.
  • Click here to view a listing of employee benefits
  • Carnegie Mellon University is an Equal OpportunityEmployer/Disability/Veteran .
  • Statement of Assurance
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Associate AI Red Team Engineer
Associate AI Red Team Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 120,000 - 190,000
Senior AI Red Team Engineer
Senior AI Red Team Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 180,000 - 230,000
AI Red Team Engineer
AI Red Team Engineer

Carnegie Mellon University • Arlington (VA)

On-site
USD 150,000 - 210,000
Bus pass
Family Concierge Team
Fitness center access
+4
Senior AI Red Team Engineer
Senior AI Red Team Engineer

Carnegie Mellon University • Arlington (VA)

On-site
USD 150,000 - 230,000
Tuition benefits
Paid time off
Retirement plan with employer-contrib.
+4
Senior AI Security Software Engineer
Senior AI Security Software Engineer

Carnegie Mellon University • Pittsburgh

Hybrid
USD 100,000 - 120,000
8% employer retirement contribution
Tuition benefits for employees and dependents
Flexible work arrangements
+2
AI Security Software Engineer
AI Security Software Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 100,000 - 130,000
8% employer retirement contribution
Tuition benefits for employees and dependents
Flexible work arrangements
+2
Senior AI Security Software Engineer
Senior AI Security Software Engineer

Carnegie Mellon University • Arlington (VA)

On-site
USD 140,000 - 190,000
8% employer retirement contribution (p
Tuition benefits for employees and dep
Flexible work arrangements
+3
Senior AI Security Researcher
Senior AI Security Researcher

The Chronicle Of Higher Education, Inc. • Pittsburgh

On-site
USD 130,000 - 190,000
Tuition benefits to CMU
Relocation assistance
Flexible work arrangements
+1
Senior AI Security Engineer — Flexible Work & Tuition
Senior AI Security Engineer — Flexible Work & Tuition

Carnegie Mellon University • Arlington (VA)

On-site
USD 140,000 - 190,000
AI Security Researcher
AI Security Researcher

Carnegie Mellon University • Pittsburgh

On-site
USD 110,000 - 130,000
Comprehensive medical, prescription, dental, and vision insurance
Generous retirement savings program
Tuition benefits for employees and their children
+2