AI Red Team Engineer

ByLabs

San Francisco (CA)

On-site

USD 150,000 - 190,000

Full time

48 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ByLabs is seeking a skilled Red Team Security Engineer to join our SOC team in San Francisco. You will simulate adversary TTPs at the APT level to validate detection and response capabilities while researching AI/LLM security risks.

You will design end-to-end red team operations, replicate APT TTPs, develop offensive tools, and contribute to BAS playbooks across Windows, macOS, and Linux. Collaboration with blue teams and threat intel is essential.

Qualifications

  • 3+ years of hands-on pentesting or red team experience.
  • Proficiency with at least one mainstream C2 framework (Cobalt Strike, Sliver, Havoc).
  • Strong vulnerability exploitation fundamentals: web (OWASP Top 10), internal network (AD attack chains), cloud environments.
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding attack scenarios
  • Understanding of LLM application architectures (RAG, Agent, MCP, Tool Use) and ability to identify attack surfaces
  • Hands-on research or PoC experience with Prompt Injection, jailbreaking, or model extraction attacks
  • Familiar with MITRE ATLAS framework and AI/ML threat classification
  • (Preferred) Holds at least one major red team certification: OSCP, CRTO, CRTE
  • (Preferred) Web3 / blockchain security background (smart contract audits, on-chain attack analysis)
  • (Preferred) CTF experience or published vulnerability research (CVE, conference talks, technical blog)

Responsibilities

  • Design and execute end-to-end red team operations covering the full attack chain: reconnaissance, initial access, lateral movement, privilege escalation, and data exfiltration
  • Replicate APT group TTPs (e.g., Lazarus, APT41) to validate detection and incident response capabilities
  • Develop and maintain custom offensive tools, C2 frameworks, and evasion techniques to simulate advanced threats
  • Participate in BAS (Breach and Attack Simulation) playbook design and execution across Windows, macOS, and Linux platforms
  • Research AI/LLM attack surfaces: Prompt Injection, model poisoning, adversarial examples, training data contamination, and AI Agent security risks
  • Evaluate security risks in AI/LLM applications (RAG, MCP, Tool Use, Agentic workflows) and provide red team findings
  • Track AI security research (MITRE ATLAS, OWASP LLM Top 10) and produce internal threat intelligence
  • Collaborate with the blue team to translate red team findings into detection rules and defensive hardening
  • Produce high-quality red team reports with actionable remediation recommendations

Skills

Penetration testing
Red team operations
MITRE ATT&CK
AI/LLM security
Prompt injection
Jailbreak techniques
Model extraction
Threat modeling
C2 evasion

Tools

Cobalt Strike
Sliver
Havoc

Job description

We are looking for a skilled Red Team Security Engineer to join our SOC team. You will simulate real-world adversary TTPs — including APT-level attacks — to validate our detection and response capabilities, while also conducting cutting-edge research into AI/LLM security risks. You will work closely with the blue team, threat intelligence, and security engineering to continuously strengthen our defensive posture.

Key Responsibilities
  • Design and execute end-to-end red team operations covering the full attack chain: reconnaissance, initial access, lateral movement, privilege escalation, and data exfiltration
  • Replicate APT group TTPs (e.g., Lazarus, APT41) to validate detection and incident response capabilities
  • Develop and maintain custom offensive tools, C2 frameworks, and evasion techniques to simulate advanced threats
  • Participate in BAS (Breach and Attack Simulation) playbook design and execution across Windows, macOS, and Linux platforms
  • Research AI/LLM attack surfaces: Prompt Injection, model poisoning, adversarial examples, training data contamination, and AI Agent security risks
  • Evaluate security risks in AI/LLM applications (RAG, MCP, Tool Use, Agentic workflows) and provide red team findings
  • Track AI security research (MITRE ATLAS, OWASP LLM Top 10) and produce internal threat intelligence
  • Collaborate with the blue team to translate red team findings into detection rules and defensive hardening
  • Produce high-quality red team reports with actionable remediation recommendations
Major Requirements
  • 3+ years of hands-on penetration testing or red team experience
  • Proficiency with at least one mainstream C2 framework (Cobalt Strike, Sliver, Havoc, etc.)
  • Strong vulnerability exploitation fundamentals: web (OWASP Top 10), internal network (AD attack chains), cloud environments
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding attack scenarios
  • Understanding of LLM application architectures (RAG, Agent, MCP, Tool Use) and ability to identify attack surfaces
  • Hands-on research or PoC experience with Prompt Injection, jailbreaking, or model extraction attacks
  • Familiar with MITRE ATLAS framework and AI/ML threat classification
  • (Preferred) Holds at least one major red team certification: OSCP, CRTO, CRTE
  • (Preferred) Web3 / blockchain security background (smart contract audits, on-chain attack analysis)
  • (Preferred) CTF experience (DEFCON CTF, GeekCon, etc.) or published vulnerability research (CVE, conference talks, technical blog)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Red Team Engineer: LLM Security & Adversarial Research
AI Red Team Engineer: LLM Security & Adversarial Research

ByLabs • San Francisco (CA)

On-site
USD 150,000 - 190,000
AI Red Team Engineer
AI Red Team Engineer

Arcitix Security • United States

On-site
USD 100,000 - 140,000
Associate AI Red Team Engineer
Associate AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 120,000 - 180,000
AI Red Team Lead Engineer
AI Red Team Lead Engineer

U.S. Bank • Cincinnati (AR)

On-site
USD 140,000 - 210,000
Security Validation Engineer (Red Team)
Security Validation Engineer (Red Team)

Athena • Palo Alto (CA)

On-site
USD 140,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software Technologies • City of Niagara Falls (NY)

On-site
USD 150,000 - 230,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Austin (TX)

On-site
USD 140,000 - 210,000
AI Red Team Engineer - 2025000
AI Red Team Engineer - 2025000

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 120,000 - 170,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Chicago (IL)

On-site
USD 150,000 - 210,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • San Francisco (CA)

On-site
USD 150,000 - 210,000