The SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems. The CERT Threat Analysis (TA) Directorate conducts research and development activities to identify, analyze, coordinate disclosure, and mitigate threats and vulnerabilities in systems and software. The TA Directorate is currently comprised of three teams: Artificial Intelligence (AI) Security, Malware and Vulnerability Exploitation, and Platform and Mission Engineering. The AI Security team works on advancing the state of the art in AI security at a national and global scale. The Malware and Vulnerability Exploitation (MVE) team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies. The vulnerability side of MVE (home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems. The Platform and Mission Engineering team develops and maintains tools, environments, and operational support for the malware analysis, reverse engineering, vulnerability analysis, and AI security domains. As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts. But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do. While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior