Carnegie Mellon University

Associate AI Red Team Engineer

Carnegie Mellon University$95K — $115K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's or Master's degree in Computer Science or relevant technical discipline; PhD is a plus.
  • 3+ years of experience in penetration testing or red teaming, or 1+ year with a Master's degree.
  • Hands-on experience with command and control frameworks like Cobalt Strike or Sliver.
  • Proficient in programming languages: Python, C, BASH, and willing to learn PowerShell.
  • Experienced with reverse engineering tools such as NSA Ghidra and IDA Pro.
  • Strong understanding of TCP/IP and OSI model; familiarity with Wireshark.
  • One relevant security certification (e.g., OSCP, CPTS, GPEN) preferred but not mandatory.

Responsibilities

  • Red team AI-enabled systems for national security objectives.
  • Develop tactics, techniques, and procedures to enhance defender preparedness.
  • Create tools in Python, PowerShell, C, and BASH to assist red team operations.
  • Communicate technical work and collaborate with external mission partners and internal teams.
  • Assess real-world systems in a fast-paced environment.
  • Plan and rehearse red team tactics, techniques, and procedures.
  • Present findings and insights to various stakeholders.

Benefits

  • Opportunities for perpetual learning and professional development.
  • Work within a cutting-edge research organization.
  • Engagement in challenging, real-world projects.
  • Collaboration with mission partners in the national security space.
  • Flexible travel opportunities to various SEI offices and conferences.
Full Job Description

Position Summary 

As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts. 
 

But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do. 

  

While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming (CTF experience may be relevant for Assistant and Associate levels). 
 

What you’ll do: 

  • Red team real-world AI-enabled systems (both the model and the hardware/software/network that it runs on) in support of national security objectives. 

  • Develop new tactics, techniques, and procedures for attacking AI-enabled systems and related software in order to better prepare defenders for real-world threats.  

  • Write tools in Python, PowerShell, C, and BASH to enable red team operations. 

  • Represent the CERT technical portfolio of work and operations; communicate with external mission partners and internal collaborators in concert with CERT directorates and teams.  

 

Who you are: 

  

  • Bachelor's Degree in Computer Science or a relevant technical discipline with three (3) years of relevant work experience; or a MS in Computer Science or a relevant technical discipline with one (1) year of relevant work experience; or a PhD in Computer Science or other relevant technical discipline. Other educational backgrounds of a technical nature with experience as described may be considered. 

  • You havepreviouspenetration testing, red teaming, or exploit development experience. 

  • You haveprevioushands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).

  • You have experience programming/scripting in Python, C, and BASH(without theassistanceof AI) and are willing to learn PowerShell. 

  • You haveexperiencewith reverse engineering tools (e.g.NSA Ghidra, IDA Pro).

  • Youare able toread code and quickly spot basic vulnerabilities without the assistanceof AI or fuzzing. 

  • You arevery familiarwith TCP/IP and all layers of the OSI model.You have experience using Wireshark and can explain how common network protocols work. 

  • You have experience in assessing the security of both Linux and Windows systems. Experience with mobile(e.g., Android)and other operations systems is also appreciated.

  • You have at leastoneof the following relevant certifications: OSCP, CPTS, FORGE/RIOT,eJPT, CBBH, BSCP, PNPT, GRTP, GPEN.Applicants without these certifications will still be considered if equivalent experience is clearlydemonstratedduring technical interviews.

  • You have excellent communication skills (oral and written), particularlyregardingtechnical communications with non-experts.  

  • You enjoy mentoring and cross-training others and sharing knowledge within the broader community. 

  • You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings. 

  • You will be subject to a background investigation, and you must have the ability to obtain andmaintaina Department of Warsecurity clearance.

 

  

 

Location

Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full Time/Part time

Full time

Pay Basis

Salary

More Information: 

  • Please visit “” to learn more about becoming part of an institution inspiring innovations that change the world. 

  • Click

About Carnegie Mellon University

Carnegie Mellon University is a private research university that was founded in 1900. The university is located in Pittsburgh, Pennsylvania and is known for its programs in computer science, engineering, and the arts. Carnegie Mellon has a diverse student body and offers undergraduate and graduate programs in a variety of fields. The university has a strong focus on research and has partnerships with a number of companies and organizations. Carnegie Mellon is consistently ranked among the top universities in the United States.
Learn more about Carnegie Mellon University
Size
14,000 employees
Industry

Similar Jobs

More Jobs at Carnegie Mellon University

More Aerospace & Defense Jobs

Find similar Associate AI Red Team Engineer jobs: