> Markdown version of [/jobs/ext/2198719-sr-ai-red-team-engineer](https://www.wearedevelopers.com/jobs/ext/2198719-sr-ai-red-team-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. AI Red Team Engineer - **Company:** ModernaTX, Inc. - **Location:** Cambridge, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $145,900.0 - $234,200.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Red Team (Cyber Security), Systems Integration, AI Infrastructure, Office365, Mitre Att&ck, Cyber Threat Analysis, Purple Team (Cyber Security), Blue Team (Cyber Security) - **Published:** August 23, 2026 - **Apply:** https://www.jofdav.com/jobs/59371914-sr-ai-red-team-engineer ## About the Role * 4+ years in cybersecurity with deep experience in red teaming, offensive security, or adversary simulation. * Proven ability to conduct end-to-end attack chains, including initial access, lateral movement, privilege escalation, and data exfiltration. * Expertise in network penetration testing, Active Directory exploitation, cloud attacks (Azure, AWS, O365), endpoint evasion, and AI systems. * Experience targeting OT or lab-connected systems is a plus. * Experience with modern AI based attacks and how to leverage them in a longer attack path. * Strong knowledge of MITRE ATT&CK, C2 frameworks, and offensive tooling. * Familiarity with purple team methodologies and integrating offensive results into defensive playbooks and detections. * OPSEC discipline and experience running stealth operations under blue team monitoring. * Solid scripting and automation skills in at least one major language (Python, PowerShell, Bash, or Go). Here's What You'll Bring to the Table (Preferred Qualifications) * Preferred certifications: OSCP, OSEP, OSED, CRTO, or equivalent hands-on offensive credentials. * Ability to communicate complex offensive findings clearly to both technical engineers and executive stakeholders. ## Description In this role, you will design, execute, and evolve advanced adversarial simulation campaigns to test Moderna's cyber resilience across corporate, laboratory, and manufacturing environments with a focus on AI and the attack surface it exposes. You will act as a hands-on operator, building and running end-to-end offensive campaigns - from initial reconnaissance to network exploitation and post-exploitation within high-value segments like lab, OT systems, cloud, and AI infrastructure. This role reports to the Red Team Program Lead and works very deeply and closely with Incident Response, Threat Intelligence, and Detection Engineering to convert findings into durable defenses. The primary output of the program focuses on building defenses, detections that result in prevention of real adversarial tradecraft. Your mission: identify, emulate, and weaponize attacker tradecraft before real adversaries do against Moderna. Here's What You'll Do: * Plan, execute, and document full-spectrum red team operations targeting digital, physical, and hybrid environments. * Develop and maintain offensive toolchains and infrastructure for covert operations (C2 frameworks, payload obfuscation, cloud-based staging, and beacon management). * Conduct external-to-internal attack simulations. * Collaborate with detection and incident response teams to measure time-to-detect, time-to-contain, and overall detection efficacy. * Build and maintain custom scripts and exploits using Python, PowerShell, and other languages to simulate real adversary TTPs. * Perform adversary emulation based on threat intel tied to biotech, pharma, and critical manufacturing sectors. * Lead post-operation technical debriefs with IR and Threat Intel to derive new detection opportunities and security controls. * Contribute to the development of internal red team maturity, progressing toward a continuous red team model. ## Related Videos - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Reusing apps between teams and environments through Containers](https://www.wearedevelopers.com/videos/107-reusing-apps-between-teams-and-environments-through-containers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)