AI Penetration Tester (Red Team)
Core
Conducting internal and external network, web application, API, and cloud security assessments while executing adversary emulation exercises and testing AI/LLM systems for vulnerabilities like prompt injection and model abuse.
Role type
Senior IC AI Penetration Tester (Red Team)
Builds
Security assessments, adversary emulation scenarios, and AI security testing workflows for enterprise clients.
Domain
Cybersecurity, Offensive Security, Artificial Intelligence, Machine Learning
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, Red teaming, AI/LLM architecture understanding, Networking, Windows/Linux administration, Active Directory, Web technologies, Python, Bash, PowerShell, Cloud security (AWS/Azure/GCP)
Preferred skills
Offensive security certifications (OSCP/OSEP/CRTO/GPEN/GWAPT), Testing AI/ML systems in production, Secure software development, Cloud-native/containerized environments, Open-source security contributions
Technologies
Burp Suite, Metasploit, Nmap, BloodHound, Command-and-control frameworks, AI APIs, LLMs, MITRE ATT&CK, OWASP
Responsibilities
Conduct internal and external network penetration tests, Perform web application and API security assessments, Execute cloud security reviews across AWS, Azure, or GCP, Identify, exploit, and document vulnerabilities in a controlled and ethical way, Validate remediation efforts through structured retesting, Prepare detailed technical reports and executive summaries, Plan and run adversary emulation exercises aligned with real-world threat actors, Simulate full attack chains including initial access, privilege escalation, lateral movement, persistence, and data exfiltration, Carry out authorized social engineering and phishing campaigns, Assess detection and response capabilities alongside defensive teams, Develop and refine offensive tools and techniques to mirror evolving threats, Use AI and LLM-based tools to improve reconnaissance, payload development, and automation, Build workflows that integrate AI into penetration testing and red team operations, Evaluate the strengths and limitations of AI tools in offensive security work, Continuously review emerging AI technologies for security use cases, Assess the security of AI-powered applications and services, Test for prompt injection, jailbreak attempts, model abuse, and data leakage, Evaluate risks such as model extraction, model inversion, and training data poisoning, Assess RAG implementations and AI plugin integrations, Contribute to AI threat modeling and secure deployment guidance, Stay current on emerging threats, vulnerabilities, and offensive security methods, Help develop internal tools, scripts, and red team frameworks, Maintain knowledge of standards such as MITRE ATT&CK and OWASP, including AI-focused frameworks, Support ongoing improvement of offensive security methodologies
Seniority
Senior, hands-on IC