Skip to content

Open nowPosted 50 days ago

Associate AI Red Team Engineer

CMU137 open roles

Where
Pittsburgh, PA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAssociate AI Red Team EngineerCMU · Pittsburgh, PA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on CMU's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. CMU postings stay open a median of 4 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.1%30 days
This job: posted 50 days ago

CMU median: 4 days open

The posting

Who We Are

SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems.

What We Do

The CERT Threat Analysis (TA) Directorate conducts research and development activities to identify, analyze, coordinate disclosure, and mitigate threats and vulnerabilities in systems and software. The TA Directorate is currently comprised of three teams: Artificial Intelligence (AI) Security, Malware and Vulnerability Exploitation, and Platform and Mission Engineering. The AI Security team works on advancing the state of the art in AI security at a national and global scale. The Malware and Vulnerability Exploitation (MVE) team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies. The vulnerability side of MVE (home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems. The Platform and Mission Engineering team develops and maintains tools, environments, and operational support for the malware analysis, reverse engineering, vulnerability analysis, and AI security domains.

Position Summary

As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security contexts.

But this isn't a "make the LLM say the bad thing" type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do.

While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming (CTF experience may be relevant for Assistant and Associate levels).

What you’ll do:

  • Red team real-world AI-enabled systems (both the model and the hardware/software/network that it runs on) in support of national security objectives.
  • Develop new tactics, techniques, and procedures for attacking AI-enabled systems and related software in order to better prepare defenders for real-world threats.
  • Write tools in Python, PowerShell, C, and BASH to enable red team operations.
  • Represent the CERT technical portfolio of work and operations; communicate with external mission partners and internal collaborators in concert with CERT directorates and teams.

Who you are:

  • Bachelor's Degree in Computer Science or a relevant technical discipline with three (3) years of relevant work experience; or a MS in Computer Science or a relevant technical discipline with one (1) year of relevant work experience; or a PhD in Computer Science or other relevant technical discipline. Other educational backgrounds of a technical nature with experience as described may be considered.
  • You have previous penetration testing, red teaming, or exploit development experience.
  • You have previous hands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).
  • You have experience programming/scripting in Python, C, and BASH (without the assistance of AI) and are willing to learn PowerShell.
  • You have experience with reverse engineering tools (e.g. NSA Ghidra, IDA Pro).
  • You are able to read code and quickly spot basic vulnerabilities without the assistance of AI or fuzzing.
  • You are very familiar with TCP/IP and all layers of the OSI model. You have experience using Wireshark and can explain how common network protocols work.
  • You have experience in assessing the security of both Linux and Windows systems. Experience with mobile (e.g., Android) and other operations systems is also appreciated.
  • You have at least one of the following relevant certifications: OSCP, CPTS, FORGE/RIOT, eJPT, CBBH, BSCP, PNPT, GRTP, GPEN. Applicants without these certifications will still be considered if equivalent experience is clearly demonstrated during technical interviews.
  • You have excellent communication skills (oral and written), particularly regarding technical communications with non-experts.
  • You enjoy mentoring and cross-training others and sharing knowledge within the broader community.
  • You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.
  • You will be subject to a background investigation, and you must have the ability to obtain and maintain a Department of War security clearance.

Location

Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full time/Part time

Full time

Pay Basis

Salary

More Information:

  • Please visit “Why Carnegie Mellon” to learn more about becoming part of an institution inspiring innovations that change the world.
  • Click here to view a listing of employee benefits
  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
  • Statement of Assurance
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against CMU's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on CMU's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    CMU's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.