> Markdown version of [/jobs/ext/2554475-ai-red-team-engineer](https://www.wearedevelopers.com/jobs/ext/2554475-ai-red-team-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Red Team Engineer - **Company:** Carnegie Mellon University - **Location:** Pittsburgh, PA, United States - **Contract:** Permanent contract - **Skills:** C (Programming Language), Microsoft Windows, Artificial Intelligence, Software System Penetration Testing, Bash Shell, Information Systems, Computer Programming, Linux, Python (Programming Language), Network Protocols, Open Systems Interconnection (OSI), Windows PowerShell, Red Team (Cyber Security), Reverse Engineering, Software Engineering, TCP/IP, Wireshark, Scripting, Large Language Models, Information Technology, IDA Pro, Operational Systems - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/60CE74BC563043868D48C285C8909AEA/job/ ## About the Role * BS in computer science, software engineering, networking, information systems, or a related technical field with eight (8) years of experience; MS in computer science or technical/engineering field with five (5) years of experience; PhD in computer science or technical/engineering field with two (2) years of experience or equivalent combination of training and experience. Other educational backgrounds of a technical nature with experience as described may be considered. * You havepreviouspenetration testing, red teaming, or exploit development experience. * You haveprevioushands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver). * You have experience programming/scripting in Python, C, and BASH(without theassistanceof AI)andare willing to learn PowerShell. * You haveexperiencewith reverse engineering tools (e.g.NSAGhidra, IDA Pro). * Youare able toread code and quickly spot basic vulnerabilities without theassistanceof AI or fuzzing. * You arevery familiarwith TCP/IP and all layers of the OSI model.You have experienceusing Wireshark and can explainhow common network protocols work. * You have experience in assessing the security of both Linux and Windows systems. Experience with mobile(e.g., Android)and other operations systems is also appreciated. * You have at least two of the following relevant certifications:OSCP, CPTS,FORGE/RIOT,GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWEE.Applicants without thesecertifications willstill be consideredif equivalentexperience isclearlydemonstratedduringtechnical interviews. * You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings. * You have excellent communication skills (oral and written), particularlyregardingtechnical communications with non-experts. * You enjoy mentoring and cross-training others and sharing knowledge within the broader community. * You will be subject to a background investigation, and you must have the ability to obtain andmaintaina Department ofWarsecurity clearance. ## Description As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts. But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do. While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming. What you'll do: * Red team real-world AI-enabled systems(both the model and the hardware/software/network that it runs on) in support of national securityobjectives. * Develop new tactics, techniques, and procedures for attacking AI-enabled systemsand related softwarein order tobetter prepare defenders for real-world threats. * Write tools in Python, PowerShell, C, and BASH to enable red team operations. * Represent the CERT technical portfolio of work and operations; communicate with external mission partners andinternalcollaboratorsin concert with CERT directorates and teams. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Hiring AI Native Talents](https://www.wearedevelopers.com/videos/100268-hiring-ai-native-talents) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)