SonicJobs Logo
Left arrow iconBack to search

AI Red Team Engineer

Software Engineering Institute | Carnegie Mellon University
Posted a day ago, valid for 13 days
Location

Arlington, VA, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • SEI is seeking an AI Red Team Engineer to join the AI Security team, focusing on adversary emulation and capability development for national security applications.
  • Candidates should have a BS in a technical field with eight years of experience, an MS with five years, or a PhD with two years of experience, along with relevant certifications.
  • The role involves red teaming real-world AI-enabled systems, developing new tactics for attacking these systems, and writing tools in programming languages such as Python and C.
  • The position requires familiarity with penetration testing, command and control frameworks, and experience with both Windows and Linux systems.
  • The salary for this full-time position is competitive, and candidates must be willing to travel up to 25% for work-related activities.

Who We AreĀ 

Ā 

SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government.Ā The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems.Ā 

Ā 

What We DoĀ 
Ā 

The CERT Threat Analysis (TA) Directorate conducts research and development activities toĀ identify, analyze, coordinate disclosure, and mitigateĀ threats andĀ vulnerabilities in systems and software. The TA Directorate is currentlyĀ comprisedĀ ofĀ threeĀ teams:Ā Ā Artificial Intelligence (AI)Ā Security,Ā MalwareĀ andĀ VulnerabilityĀ Exploitation, andĀ Platform and Mission Engineering.Ā Ā The AI Security team worksĀ on advancing the state of the art in AI security at a national and global scale.Ā The MalwareĀ and Vulnerability Exploitation (MVE)Ā team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies.Ā Ā TheĀ vulnerabilityĀ side of MVEĀ (home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems.Ā Ā TheĀ Platform and Mission Engineering teamĀ develops andĀ maintainsĀ tools,Ā environments, and operational support forĀ theĀ malware analysis, reverse engineering, vulnerability analysis, and AI securityĀ domains.Ā 
  

Position SummaryĀ 

As an AI Red Team Engineer on the AI Security team, you will playĀ a central roleĀ in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems weĀ red-teamĀ fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts.Ā 

But thisĀ isn'tĀ a "make the LLM say the bad thing" type of AI red team. WeĀ operateĀ across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do.Ā 

  

While our red team exists within a research organization, research is only aĀ portionĀ of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, weĀ don'tĀ get toĀ pick and chooseĀ our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming.Ā 
Ā 

WhatĀ you’llĀ do:Ā 

  • Red team real-world AI-enabled systemsĀ (both the model and the hardware/software/network that it runs on) in support of national securityĀ objectives.Ā 

  • Develop new tactics, techniques, and procedures for attacking AI-enabled systemsĀ and related softwareĀ in order toĀ better prepare defenders for real-world threats.Ā Ā 

  • Write tools in Python, PowerShell, C, and BASH to enable red team operations.Ā 

  • Represent the CERT technical portfolio of work and operations; communicate with external mission partners andĀ internalĀ collaboratorsĀ in concert with CERT directorates and teams.Ā Ā 

Ā 

Who you are:Ā 

Ā Ā 

  • BS in computer science, software engineering, networking, information systems, or a related technical field with eight (8) years of experience; MS in computer science or technical/engineering field with five (5) years of experience; PhD in computer science or technical/engineering field with two (2) years of experience or equivalent combination of training and experience. Other educational backgrounds of a technical nature with experience as described may be considered.Ā 

  • You haveĀ previousĀ penetration testing, red teaming, or exploit development experience.Ā Ā 

  • You haveĀ previousĀ hands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).Ā 

  • You have experience programming/scripting in Python, C, and BASHĀ (without theĀ assistanceĀ of AI)Ā andĀ are willing to learn PowerShell.Ā Ā 

  • You haveĀ experienceĀ with reverse engineering tools (e.g.Ā NSAĀ Ghidra, IDA Pro).Ā 

  • YouĀ are able toĀ read code and quickly spot basic vulnerabilities without theĀ assistanceĀ of AI or fuzzing.   

  • You areĀ very familiarĀ with TCP/IP and all layers of the OSI model.Ā You have experienceĀ using Wireshark and can explainĀ how common network protocols work.Ā Ā 

  • You have experience in assessing the security of both Linux and Windows systems. Experience with mobileĀ (e.g., Android)Ā and other operations systems is also appreciated.Ā 

  • You have at least two of the following relevant certifications:Ā OSCP, CPTS,Ā FORGE/RIOT,Ā GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWEE.Ā Applicants without theseĀ certifications willĀ still be consideredĀ if equivalentĀ experience isĀ clearlyĀ demonstratedĀ duringĀ technical interviews.Ā 

  • You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.

  • You have excellent communication skills (oral and written), particularlyĀ regardingĀ technical communications with non-experts.   

  • You enjoy mentoring and cross-training others and sharing knowledge within the broader community.  

  • You will be subject to a background investigation, and you must have the ability to obtain andĀ maintainĀ a Department ofĀ WarĀ security clearance.Ā 

Ā 

Ā 

  

Ā 

Location

Arlington, VA, Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full time/Part time

Full time

Pay Basis

Salary

More Information:Ā 

  • Please visit ā€œWhy Carnegie Mellonā€ to learn more about becoming part of an institution inspiring innovations that change the world.Ā 

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.Ā 

  • Statement of Assurance




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.