AI Red Team Engineer

Confidential

San Francisco (CA)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Confidential is seeking a skilled Red Team Security Engineer to join the SOC team in San Francisco, California. The ideal candidate will simulate real-world adversary TTPs, including APT-level attacks, and will conduct research into AI and LLM security risks.

This role involves designing red team operations, collaborating with blue team members, and producing high-quality reports with actionable remediation recommendations. Candidates should have a strong background in penetration testing and familiarity with the MITRE ATT&CK framework.

Qualifications

  • 3+ years of hands-on penetration testing or red team experience.
  • Proficiency with at least one mainstream C2 framework.
  • Understanding of AI/LLM application architectures and attack surfaces.

Responsibilities

  • Design and execute end-to-end red team operations.
  • Replicate APT group TTPs to validate detection and incident response capabilities.
  • Research AI/LLM attack surfaces and evaluate security risks.

Skills

Penetration Testing
Red Team Operations
C2 Frameworks
Vulnerability Exploitation
MITRE ATT&CK Framework
AI Security
Web3 Security

Education

Major red team certification (e.g., OSCP, CRTO, CRTE)

Tools

Cobalt Strike
Sliver
Havoc

Job description

We are looking for a skilled Red Team Security Engineer to join our SOC team. You will simulate real-world adversary TTPs — including APT-level attacks — to validate our detection and response capabilities, while also conducting cutting-edge research into AI/LLM security risks. You will work closely with the blue team, threat intelligence, and security engineering to continuously strengthen our defensive posture.

Key Responsibilities
  • Design and execute end-to-end red team operations covering the full attack chain: reconnaissance, initial access, lateral movement, privilege escalation, and data exfiltration
  • Replicate APT group TTPs (e.g., Lazarus, APT41) to validate detection and incident response capabilities
  • Develop and maintain custom offensive tools, C2 frameworks, and evasion techniques to simulate advanced threats
  • Participate in BAS (Breach and Attack Simulation) playbook design and execution across Windows, macOS, and Linux platforms
  • Research AI/LLM attack surfaces: Prompt Injection, model poisoning, adversarial examples, training data contamination, and AI Agent security risks
  • Evaluate security risks in AI/LLM applications (RAG, MCP, Tool Use, Agentic workflows) and provide red team findings
  • Track AI security research (MITRE ATLAS, OWASP LLM Top 10) and produce internal threat intelligence
  • Collaborate with the blue team to translate red team findings into detection rules and defensive hardening
  • Produce high-quality red team reports with actionable remediation recommendations
Major Requirements
  • 3+ years of hands‑on penetration testing or red team experience
  • Proficiency with at least one mainstream C2 framework (Cobalt Strike, Sliver, Havoc, etc.)
  • Strong vulnerability exploitation fundamentals: web (OWASP Top 10), internal network (AD attack chains), cloud environments
  • Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding attack scenarios
  • Holds at least one major red team certification: OSCP, CRTO, CRTE (preferred)
  • (AI Security) Understanding of LLM application architectures (RAG, Agent, MCP, Tool Use) and ability to identify attack surfaces
  • (AI Security) Hands‑on research or PoC experience with Prompt Injection, jailbreaking, or model extraction attacks
  • (AI Security) Familiar with MITRE ATLAS framework and AI/ML threat classification
  • (Bonus) Web3 / blockchain security background (smart contract audits, on‑chain attack analysis)
  • (Bonus) CTF experience (DEFCON CTF, GeekCon, etc.) or published vulnerability research (CVE, conference talks, technical blog)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Red Team Engineer
AI Red Team Engineer

Arcitix Security • United States

On-site
USD 100,000 - 140,000
AI Red Teaming Engineer
AI Red Teaming Engineer

DeWinter Group • Campbell (CA)

Remote
AI Red Team Lead Engineer
AI Red Team Lead Engineer

Jobtailor • Illinois

On-site
USD 180,000 - 240,000
AI Security Engineer AI Security Unit
AI Security Engineer AI Security Unit

Check Point Software Technologies • Washington

On-site
USD 135,000 - 195,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Chicago (IL)

On-site
USD 150,000 - 230,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Denver (CO)

On-site
USD 120,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • New York (NY)

On-site
USD 150,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Austin (TX)

On-site
USD 120,000 - 160,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Washington

On-site
USD 140,000 - 190,000
AI Security Engineer, AI Security Unit
AI Security Engineer, AI Security Unit

Check Point Software • Seattle (WA)

On-site
USD 180,000 - 240,000