AI Red Team Engineer

Posted 5 Days Ago
Be an Early Applicant
2 Locations
In-Office
Senior level
Edtech
The Role
Conduct red-team assessments of AI-enabled systems, including models, hardware, software, and networks, supporting national security missions. Develop offensive tactics, techniques, procedures, and operational tools using Python, C, Bash, and PowerShell. Perform penetration testing, exploit development, reverse engineering, vulnerability analysis, and Windows/Linux security assessments. Communicate findings to mission partners, travel to field sites, and mentor colleagues.
Summary Generated by Built In

Who We Are 

 

SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems. 

 

What We Do 
 

The CERT Threat Analysis (TA) Directorate conducts research and development activities to identify, analyze, coordinate disclosure, and mitigate threats and vulnerabilities in systems and software. The TA Directorate is currently comprised of three teams:  Artificial Intelligence (AI) Security, Malware and Vulnerability Exploitation, and Platform and Mission Engineering The AI Security team works on advancing the state of the art in AI security at a national and global scale. The Malware and Vulnerability Exploitation (MVE) team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies The vulnerability side of MVE (home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems.  The Platform and Mission Engineering team develops and maintains tools, environments, and operational support for the malware analysis, reverse engineering, vulnerability analysis, and AI security domains. 
 

Position Summary 

As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts. 

But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do. 

 

While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming. 
 

What you’ll do: 

  • Red team real-world AI-enabled systems (both the model and the hardware/software/network that it runs on) in support of national security objectives. 

  • Develop new tactics, techniques, and procedures for attacking AI-enabled systems and related software in order to better prepare defenders for real-world threats.  

  • Write tools in Python, PowerShell, C, and BASH to enable red team operations. 

  • Represent the CERT technical portfolio of work and operations; communicate with external mission partners and internal collaborators in concert with CERT directorates and teams 

 

Who you are: 

  

  • BS in computer science, software engineering, networking, information systems, or a related technical field with eight (8) years of experience; MS in computer science or technical/engineering field with five (5) years of experience; PhD in computer science or technical/engineering field with two (2) years of experience or equivalent combination of training and experience. Other educational backgrounds of a technical nature with experience as described may be considered. 

  • You have previous penetration testing, red teaming, or exploit development experience.  

  • You have previous hands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver). 

  • You have experience programming/scripting in Python, C, and BASH (without the assistance of AI) and are willing to learn PowerShell.  

  • You have experience with reverse engineering tools (e.g. NSA Ghidra, IDA Pro). 

  • You are able to read code and quickly spot basic vulnerabilities without the assistance of AI or fuzzing.  

  • You are very familiar with TCP/IP and all layers of the OSI model. You have experience using Wireshark and can explain how common network protocols work.  

  • You have experience in assessing the security of both Linux and Windows systems. Experience with mobile (e.g., Android) and other operations systems is also appreciated. 

  • You have at least two of the following relevant certifications: OSCP, CPTS, FORGE/RIOT, GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWEE. Applicants without these certifications will still be considered if equivalent experience is clearly demonstrated during technical interviews. 

  • You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.

  • You have excellent communication skills (oral and written), particularly regarding technical communications with non-experts.   

  • You enjoy mentoring and cross-training others and sharing knowledge within the broader community.  

  • You will be subject to a background investigation, and you must have the ability to obtain and maintain a Department of War security clearance. 

 

 

 

 

Joining the CMU team opens the door to an array of exceptional benefits.

Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance. 

Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!

For a comprehensive overview of the benefits available, explore our Benefits page.

At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it’s about finding the perfect fit for your professional growth and personal aspirations.

Are you interested in an exciting opportunity with an exceptional organization?! Apply today!

Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full Time/Part time

Full time

Pay Basis

Salary

More Information: 

  • Please visit “Why Carnegie Mellon” to learn more about becoming part of an institution inspiring innovations that change the world. 

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran

  • Statement of Assurance

Skills Required

  • Bachelor’s degree in computer science, software engineering, networking, information systems, or a related technical field plus eight years of experience; or equivalent combination of training and experience
  • Master’s degree in computer science or a technical or engineering field plus five years of experience, or PhD plus two years of experience
  • Previous penetration testing, red teaming, or exploit development experience
  • Hands-on experience with at least one command and control framework, such as Cobalt Strike or Sliver
  • Programming or scripting experience in Python, C, and Bash, and willingness to learn PowerShell
  • Experience with reverse engineering tools such as NSA Ghidra or IDA Pro
  • Ability to read code and identify basic vulnerabilities without AI or fuzzing assistance
  • Strong knowledge of TCP/IP and all OSI model layers
  • Experience using Wireshark and explaining common network protocols
  • Experience assessing the security of Linux and Windows systems
  • At least two relevant certifications, such as OSCP, CPTS, GXPN, CRTO, OSEP, OSWE, CCNA, or CWEE, or equivalent demonstrated experience
  • Willingness to travel 25% outside the office location
  • Excellent oral and written communication skills, especially technical communication with non-experts
  • Ability to obtain and maintain a Department of War security clearance
  • Experience with mobile operating systems such as Android
  • Experience with other operating systems
  • Enjoyment of mentoring, cross-training, and knowledge sharing

Carnegie Mellon University Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Carnegie Mellon University and has not been reviewed or approved by Carnegie Mellon University.

  • Retirement Support Retirement support is positioned as a standout, with automatic employer contributions to a TIAA-administered plan at 8% of base salary (and 9.78% for 9‑month academic appointments), plus optional employee deferrals. Vesting after three years is clearly specified, which helps set expectations for long-term value.
  • Parental & Family Support Parental and family support is strengthened by 100% paid parental leave for six weeks and 100% paid maternity leave for 6–8 weeks (delivery-type dependent), effective July 1, 2024. Childcare support is also referenced through a Cyert Center subsidy up to $5,000 per family, alongside no-cost EAP access.
  • Wellbeing & Lifestyle Benefits Wellbeing and lifestyle benefits include free Pittsburgh Regional Transit access and access to fitness classes and facilities, adding recurring non-cash value to the overall package. Pittsburgh’s relatively affordable cost of living can further increase the perceived adequacy of a given salary compared with higher-cost coastal hubs.

Carnegie Mellon University Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Pittsburgh, PA
9,172 Employees
Year Founded: 1990

What We Do

Carnegie Mellon University founder Andrew Carnegie said: "My heart is in the work."​ No statement better captures the passion and drive of our people to make a real difference. At Carnegie Mellon, we're not afraid of the work. Our educational environment creates problem solvers, drivers of innovation and pioneers in technology and the arts. Employers in every field say our graduates are ready to hit the ground running the day they graduate. So, join us. Whether you're looking for a career or an education. Or both.

Similar Jobs

In-Office
2 Locations
9172 Employees

Citizens Logo Citizens

Consumer Counselor - Mortgage Collections

Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
In-Office or Remote
2 Locations
17000 Employees

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Inside Sales Representative

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
11 Locations
40000 Employees
45K-85K Annually

Gusto Logo Gusto

Staff Software Engineer

Fintech • HR Tech
Easy Apply
Remote or Hybrid
United States
4405 Employees
163K-247K Annually

Similar Companies Hiring

ReUp Education Thumbnail
Social Impact • Edtech
Austin, TX
180 Employees
Learneo Thumbnail
Software • Machine Learning • Edtech • Artificial Intelligence
NL
397 Employees
CodePath.org Thumbnail
Edtech • Social Impact
San Francisco, CA
55 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account