AI Red Team Security Engineer

Ethos Life
United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$152,000.0 - $269,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Software Applications Software System Penetration Testing Authentication Protocols Microsoft Azure Cloud Computing Cloud Computing Security Code Generation Fuzz Testing
+21 more
Identity and Access Management Machine Learning Open Source Technology Open Web Application Security Tensorflow Phishing Red Team (Cyber Security) Reverse Engineering Web Applications Scripting Google Cloud Cloud Platform System Large Language Models Mitre Att&ck Generative AI GWAPT Kubernetes Graphql Machine Learning Operations Virtual Agents Docker

Job description

We are looking for a skilled and creative AI Red Team Engineer to join our offensive security team. In this role, you will simulate real-world adversaries, exploit vulnerabilities across applications, cloud infrastructure, and AI/ML systems using both traditional penetration testing techniques and cutting-edge AI-augmented attack tooling.

You will operate across the full attack surface: web apps, APIs, mobile, internal networks, and AI-powered products including LLM pipelines, model APIs, agents, and RAG systems. You will help us find the flaws before the adversaries do, and work closely with engineering and product teams to close those gaps., * Design and execute adversarial attacks against large language model (LLM)-powered products including prompt injection, jailbreaking, goal hijacking, and context manipulation.

  • Test retrieval-augmented generation (RAG) pipelines for data exfiltration, poisoning, and unauthorized knowledge extraction.
  • Assess AI agent systems and agentic workflows for unsafe tool-use, privilege escalation, and indirect prompt injection via environment feedback.
  • Conduct model extraction, membership inference, and adversarial example attacks against deployed ML models.
  • Evaluate AI guardrails, safety filters, and content moderation layers for bypass techniques., * Perform full-scope penetration tests across web applications, REST/GraphQL APIs, mobile apps (iOS/Android), cloud environments (AWS, GCP, Azure), and internal networks.
  • Conduct red team exercises simulating advanced persistent threat (APT) actors using MITRE ATT&CK and AI-augmented techniques.
  • Exploit vulnerabilities across the OWASP Top 10 and beyond: SSRF, IDOR, XXE, SSTI, authentication bypasses, and logic flaws.
  • Perform social engineering and phishing simulations as part of combined red team campaigns.
  • Conduct cloud and Kubernetes security assessments including IAM misconfigurations, container escapes, and privilege escalation paths.

AI-Augmented Attack Operations

  • Leverage AI models and tools (e.g., LLMs, code generation, fuzzing assistants) to accelerate vulnerability discovery, payload crafting, and exploit development.
  • Build or adapt AI-powered reconnaissance, exploitation, and evasion tooling for internal use in red team engagements.
  • Stay current with adversarial AI research and translate academic findings into practical red team techniques.
  • Use AI to automate repetitive testing tasks and generate novel attack variants at scale.

Requirements

Do you have experience in Scripting?, * 7+ years of hands-on penetration testing and offensive security experience in a professional setting

  • Demonstrated experience testing AI/ML systems, LLM-powered products, or AI APIs
  • Experience conducting red team engagements
  • Scripting and tool development
  • Strong understanding of authentication protocols and common implementation flaws
  • Familiarity with cloud security architectures and common misconfigurations
  • Working knowledge of Docker/Kubernetes and container security
  • Understanding of LLM architectures and how they relate to attack surfaces.
  • Familiarity with OWASP LLM Top 10
  • Practical experience with prompt injection and jailbreak techniques against LLMs
  • Ability to use LLMs as force-multipliers in red team workflows, * Certifications: OSCP, OSEP, CRTO, CRTE, PNPT, CEH, GPEN, GWAPT, or equivalent
  • Experience with adversarial ML frameworks
  • Contributions to open-source security tooling or published CVEs / bug bounty hall-of-fame credits
  • Familiarity with AI governance frameworks
  • Experience with GenAI infrastructure
  • Background in threat modeling for AI-powered applications
  • Reverse engineering skills for binary and mobile assessments
  • CTF participation or competitive hacking experience

Benefits & conditions

3.13.1 out of 5 stars Remote $152,000 - $269,000 a year - Full-time, The US national base salary range for this full-time position is $152,000 - $269,000. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

Please note that the compensation details listed in US role postings reflect the base salary only and do not include applicable bonus, equity, or benefits.

You can find further details of our US benefits at https://www.ethoslife.com/careers

About the company

Ethos is a leading life insurance technology company on a mission to protect families by democratizing access to life insurance and empowering agents at scale. With its robust three-sided technology platform, Ethos is transforming the life insurance experience for consumers, agents, and carriers alike. Ethos offers instant, accessible products and a seamless online process that requires no medical exams and just a few health questions; it eliminates traditional barriers, making it easier than ever for everyone to protect their families. Ethos is redefining how life insurance is bought, sold, and underwritten.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:52 min

Generating APIs with the Neo4j GraphQL library

William Lyon · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

51 sec

Exploring offensive security with red team tooling

Stefania Chaplin · WWC 2022

4:33 min

Overview of the GraphQL API query language

William Lyon · LIVE

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · WWC Europe 2026

Videos

See all

Related articles

See all