- As a Cybersecurity Red Teamer, you will evaluate whether AI models can be manipulated into generating functional malware, viable exploit code, attack tooling, or step-by-step operational guidance that could give a threat actor meaningful assistance in carrying out cyberattacks
- Your job is to find the gaps between what a model’s safety guardrails are intended to block and what a skilled adversary can actually extract
- This role requires you to think like an attacker who has access to a highly capable AI assistant
- You will craft adversarial prompts and multi-turn interaction chains that simulate how real threat actors, ranging from inexperienced attackers to advanced persistent threat operators, might use LLMs to accelerate reconnaissance, weaponization, exploitation, lateral movement, persistence, and exfiltration
- You will then evaluate whether the model’s output is genuinely dangerous or merely surface-level noise
- Deep cybersecurity expertise is essential
- Your value will come from being able to examine a model-generated payload, exploit chain, or attack plan and determine whether it would actually work, how much refinement it would require, and what type of attacker it could meaningfully assist
- This position may be performed from our Seattle location or remotely within the United States
- Seattle-based and remote team members will collaborate closely through shared evaluation workflows, regular feedback, and virtual working sessions
- Design technically grounded adversarial prompts that test whether models provide meaningful assistance across the cyber kill chain, from reconnaissance through exfiltration and impact
- Evaluate model-generated code and technical output for functional correctness, determining whether outputs represent real exploits, plausible attack tooling, or nonfunctional noise
- Test model behavior across offensive categories, including malware generation, vulnerability exploitation, social engineering, credential harvesting, privilege escalation, command-and-control infrastructure, and data exfiltration
- Probe dual-use boundaries by testing how models respond to queries that combine legitimate security research, penetration testing, and defensive operations with offensive applications
- Simulate attacker personas at varying skill levels, including opportunistic, intermediate, and advanced or APT-level actors
- Test multi-step and multi-turn attack chains, including scenarios in which early turns establish benign context before pivoting to malicious requests
- Score model responses using structured harm taxonomies and severity rubrics calibrated to real-world exploitability
- Document findings with clear technical reasoning, including what a response gets right, what it gets wrong, and what level of attacker it could realistically assist
- Contribute to the development and refinement of cybersecurity-specific evaluation frameworks and threat models
- Collaborate with red teamers, AI researchers, and policy teams to translate findings into actionable model improvements
- Stay current on evolving tactics, techniques, and procedures, CVEs, jailbreak techniques, and the intersection of AI and offensive security
Benefits
- Health Insurance: Comprehensive medical , dental, and vision coverage
- Fertility and family forming: Through a partnership, Handshake offers comprehensive family benefits, including infertility treatments and a $15K stipend, to its employees.
- LGTBQ+ coverage: All medical plans cover transgender services.
- Mental health: Discounts on a variety of wellness apps and an Employee Assistance Program with access to five free counseling sessions.
- Tax savings: Tax-advantaged benefits to save money on healthcare, dependent care, and other expenses.
- Life & disability insurance: Essential benefits and automatic coverage with basic life insurance, plus short-term and long-term disability coverage.
- 401k match: Dollar-for-dollar match up to 1% of pay, with a max of $1,200 per year.
- Equity: Our equity program includes grants at hire, refresher grants after two years of tenure, and grants alongside promotions.
- Financial management: Handshake partners to provide free professional financial planning services.
- Learning & development: Employees are provided with an annual stipend to use towards professional development, career development workshops, manager trainings, and 1-on-1 coaching through external partnerships
- Community leader support: Employee Resource Group leaders are compensated with a quarterly bonus for the high-impact work the role requires
- Parental leave: Leaves of 16 weeks for birth-giving parents and 10 weeks for non-birth-giving parents; the policy applies to adoptions as well. Handshake also partners to provide one-on-one coaching on preparing for leave and coming back from leave
- Flexible time off: No accrued time off or waiting period to take vacation. Two paid flexible holiday days off to observe holidays that closely align with religious, cultural, and personal needs
- Sabbatical: Paid six-week sabbatical to recharge and reset beginning at six years of continuous, full-time employment, and every four years thereafter
- Volunteer time off: Two days off for social and civil activism, volunteer work, and/or any related activities, including attending and participating in protests
Strong ethical judgment and the ability to separate adversarial thinking from personal valuesAbility to read, write, and evaluate code in languages commonly used for offensive tooling, such as Python, PowerShell, Bash, C/C++, or JavaScriptStrong hands-on experience using multiple LLMs, such as ChatGPT, Claude, Gemini, or open-source modelsUnderstanding of common attack frameworks, techniques, and procedures, including MITRE ATT&CK and OWASPProfessional experience in offensive security, penetration testing, red teaming, vulnerability research, malware analysis, threat intelligence, or incident responseCreative and adversarial problem-solving skillsAbility to work independently while collaborating effectively in a feedback-heavy, distributed environmentClear and precise written communication, including the ability to explain technical risk to nonspecialist audiencesAbility to assess the functional correctness and real-world exploitability of model-generated technical outputRelevant certifications, such as OSCP, OSCE, GPEN, GXPN, CRTO, CRTL, CEH, or similarExperience with exploit development, reverse engineering, or binary analysisActive or previous security clearanceBackground in cloud security, container security, or infrastructure-as-code attack surfacesFamiliarity with AI and machine-learning attack surfaces, including prompt injection, model extraction, training-data poisoning, and adversarial examplesExperience building or operating command-and-control frameworks, custom implants, or offensive toolingA bug-bounty track record or published CVEsPrevious work in trust and safety, content moderation, or AI evaluationFamiliarity with LLM APIs or evaluation toolingYou have spent years breaking into systems and want to apply that mindset to testing AI modelsYou can examine a model-generated reverse shell, phishing template, or privilege-escalation script and quickly determine whether it would work in a real environmentYou think in kill chains and attack graphs, not just individual promptsYou understand that the difference between a useful coding assistant and a dangerous one often comes down to context, specificity, and operational detailYou closely follow the offensive-security community and stay current when new techniques emergeYou can collaborate effectively with a team whether you are working from Seattle or remotelyYou care about AI safety because you understand what can happen when powerful tools are used irresponsibly