Senior AI Red Team Engineer
About the role
The CERT Threat Analysis (TA) Directorate conducts research and development activities to identify, analyze, coordinate disclosure, and mitigate threats and vulnerabilities in systems and software. The TA Directorate is currently comprised of three teams: Artificial Intelligence (AI) Security, Malware and Vulnerability Exploitation, and Platform and Mission Engineering.
As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts. But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security.
What you'll do
- Red team real-world AI-enabled systems (both the model and the hardware/software/network that it runs on) in support of national security objectives.
- Develop new tactics, techniques, and procedures for attacking AI-enabled systems and related software in order to better prepare defenders for real-world threats.
- Write tools in Python, PowerShell, C, and BASH to enable red team operations.
- Represent the CERT technical portfolio of work and operations; communicate with external mission partners and internal collaborators in concert with CERT directorates and teams.
Qualifications
- BS in computer science, software engineering, networking, information systems, or a related technical field with ten (10) years of experience; MS in computer science or technical/engineering field with eight (8) years of experience; PhD in computer science or technical/engineering field with five (5) years of experience or equivalent combination of training and experience. Other educational backgrounds of a technical nature with experience as described may be considered.
- Previous penetration testing, red teaming, or exploit development experience.
- Previous hands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).
- Experience programming/scripting in Python, C, and BASH (without the assistance of AI) and are willing to learn PowerShell.
- Experience with reverse engineering tools (e.g. NSA Ghidra, IDA Pro).
- Able to read code and quickly spot basic vulnerabilities without the assistance of AI or fuzzing.
- Very familiar with TCP/IP and all layers of the OSI model.
- Experience using Wireshark and can explain how common network protocols work.
- Experience in assessing the security of both Linux and Windows systems. Experience with mobile (e.g., Android) and other operating systems is also appreciated.
- At least two of the following relevant certifications: OSCP, CPTS, FORGE/RIOT, GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWEE. Applicants without these certifications will still be considered if equivalent experience is clearly demonstrated during technical interviews.
- Willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.
- Excellent communication skills (oral and written), particularly regarding technical communications with non-experts.
- Enjoy mentoring and cross-training others and sharing knowledge within the broader community.
- Will be subject to a background investigation, and must have the ability to obtain and maintain a Department of War security clearance.
Location
Arlington, VA; Pittsburgh, PA
Position type
Staff – Regular full time