Associate AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University

Pittsburgh (Allegheny County)

On-site

USD 120,000 - 190,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Software Engineering Institute (SEI) at Carnegie Mellon University in Pittsburgh seeks an AI Red Team Engineer to drive adversary emulation and capability development for mission partners. You will operate across AI security domains, applying offensive cyber tradecraft alongside deep AI security expertise.

You will collaborate with CMU researchers and industry partners, travel up to 25% for field work and conferences, and contribute to real-world threat analyses while mentoring peers.

Qualifications

  • Bachelor’s Degree in Computer Science or a relevant technical discipline with 3 years of experience, or MS with 1 year.
  • Experience in penetration testing, red teaming, or exploit development.
  • Experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).
  • Experience programming/scripting in Python, C, and BASH; willingness to learn PowerShell.
  • Experience with reverse engineering tools (e.g., Ghidra, IDA Pro).
  • Ability to read code and spot vulnerabilities without the assistance of AI or fuzzing.
  • Very familiar with TCP/IP and OSI; able to explain network protocols; experience with Wireshark.
  • Experience on Linux and Windows security; mobile OS experience appreciated.
  • At least one of OSCP, CPTS, FORGE/RIOT, eJPT, CBBH, BSCP, PNPT, GRTP, GPEN; others considered with demonstrated equivalence.
  • Excellent communication skills; willingness to mentor; travel 25% outside office; able to obtain DoD clearance.

Responsibilities

  • Red team real-world AI-enabled systems in support of national security objectives.
  • Develop new tactics, techniques, and procedures for attacking AI-enabled systems to better prepare defenders.
  • Write tools in Python, PowerShell, C, and BASH to enable red team operations.
  • Represent the CERT technical portfolio and communicate with mission partners and internal collaborators.

Skills

Penetration testing
Red teaming
Exploit development
Python
PowerShell
C
BASH
Reverse engineering
TCP/IP
Wireshark
Linux
Windows

Education

Bachelor’s Degree in Computer Science
MS in Computer Science
PhD in Computer Science

Tools

Cobalt Strike
Sliver
Ghidra
IDA Pro

Job description

Who We Are

SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government.The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems.

What We Do

The CERT Threat Analysis (TA) Directorate conducts research and development activities toidentify, analyze, coordinate disclosure, and mitigatethreats andvulnerabilities in systems and software. The TA Directorate is currentlycomprisedofthreeteams:Artificial Intelligence (AI)Security,MalwareandVulnerabilityExploitation, andPlatform and Mission Engineering.The AI Security team workson advancing the state of the art in AI security at a national and global scale.The Malwareand Vulnerability Exploitation (MVE)team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies.Thevulnerabilityside of MVE(home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems.ThePlatform and Mission Engineering teamdevelops andmaintainstools,environments, and operational support forthemalware analysis, reverse engineering, vulnerability analysis, and AI securitydomains.

Position Summary

As an AI Red Team Engineer on the AI Security team, you will playa central rolein adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems wered-teamfall outside the realm of ‘traditional’ enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts.

But thisisn’ta “make the LLM say the bad thing” type of AI red team. Weoperateacross multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do.

While our red team exists within a research organization, research is only aportionof the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, wedon’tget topick and chooseour targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming (CTF experience may be relevant for Assistant and Associate levels).

Whatyou’lldo:
  • Red team real-world AI-enabled systems(both the model and the hardware/software/network that it runs on) in support of national securityobjectives.

  • Develop new tactics, techniques, and procedures for attacking AI-enabled systemsand related softwarein order tobetter prepare defenders for real-world threats.

  • Write tools in Python, PowerShell, C, and BASH to enable red team operations.

  • Represent the CERT technical portfolio of work and operations; communicate with external mission partners andinternalcollaboratorsin concert with CERT directorates and teams.

Who you are:
  • Bachelor’s Degree in Computer Scienceor a relevant technical discipline with three (3) years of relevant work experience; or a MS in Computer Science or a relevant technical discipline with one (1) year of relevant work experience; or a PhD in Computer Science or other relevant technical discipline.Other educational backgrounds of a technical nature with experience as described may be considered.

  • You havepreviouspenetration testing, red teaming, or exploit development experience.

  • You haveprevioushands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).

  • You have experience programming/scripting in Python, C, and BASH(without theassistanceof AI)andare willing to learn PowerShell.

  • You haveexperiencewith reverse engineering tools (e.g.NSAGhidra, IDA Pro).

  • Youare able toread code and quickly spot basic vulnerabilities without theassistanceof AI or fuzzing.

  • You arevery familiarwith TCP/IP and all layers of the OSI model.You have experienceusing Wireshark and can explainhow common network protocols work.

  • You have experience in assessing the security of both Linux and Windows systems. Experience with mobile(e.g., Android)and other operations systems is also appreciated.

  • You have at leastoneof the following relevant certifications:OSCP, CPTS, FORGE/RIOT,eJPT, CBBH, BSCP, PNPT, GRTP, GPEN.Applicants without these certifications will still be considered if equivalent experience is clearlydemonstratedduring technical interviews.

  • You have excellent communication skills (oral and written), particularlyregardingtechnical communications with non-experts.

  • You enjoy mentoring and cross-training others and sharing knowledgewithin the broader community.

  • You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.

  • You will be subject to a background investigation, and you must have the ability to obtain andmaintaina Department ofWarsecurity clearance.

Location

Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full time/Part time

Full time

Pay Basis

Salary

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Red Team Engineer
AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University • Arlington (VA)

On-site
USD 120,000 - 180,000
AI Red Team Engineer
AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 130,000 - 180,000
Associate AI Red Team Engineer
Associate AI Red Team Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 120,000 - 190,000
AI Red Team Engineer
AI Red Team Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 150,000 - 210,000
AI Red Team Engineer - 2025000
AI Red Team Engineer - 2025000

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 120,000 - 170,000
Senior AI Red Team Engineer
Senior AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 180,000 - 250,000
Senior AI Red Team Engineer
Senior AI Red Team Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 180,000 - 230,000
Assistant AI Security Researcher
Assistant AI Security Researcher

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 110,000 - 160,000
Relocation assistance
Tuition benefits
Flexible work arrangements
+2
AI Security Software Engineer
AI Security Software Engineer

Software Engineering Institute | Carnegie Mellon University • Pittsburgh

On-site
USD 140,000 - 180,000
Relocation assistance
Tuition benefits for employees and/or/
Flexible work arrangements
+2
Senior AI Security Software Engineer
Senior AI Security Software Engineer

Carnegie Mellon University • Pittsburgh

On-site
USD 100,000 - 120,000
8% employer retirement contribution
Tuition benefits for employees and dependents
Flexible work arrangements
+2