Pittsburgh, PA
Arlington, VA
Full time
2025000
Who We Are
SEI conducts research and development in software engineering, systems engineering, cybersecurity, and many other areas of computing, working to introduce private-sector innovations into government. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Its core purposes are to help organizations improve software engineering capabilities, advance cybersecurity methods and technologies, and bring the discipline of software engineering to AI systems.
What We Do
The CERT Threat Analysis (TA) Directorate conducts research and development activities to identify, analyze, coordinate disclosure, and mitigate threats and vulnerabilities in systems and software. The TA Directorate is currently comprised of three teams: Artificial Intelligence (AI) Security, Malware and Vulnerability Exploitation, and Platform and Mission Engineering. The AI Security team works on advancing the state of the art in AI security at a national and global scale. The Malware and Vulnerability Exploitation (MVE) team works to improve cyber-tradecraft analysis within strategic target communities to counter adversarial use of the Internet and related technologies. The vulnerability side of MVE (home of the CERT Coordination Center) works with an expansive network of vendors, partners, and collaborators to reduce the societal harm of vulnerable software and systems. The Platform and Mission Engineering team develops and maintains tools, environments, and operational support for the malware analysis, reverse engineering, vulnerability analysis, and AI security domains.
Position Summary
As an AI Red Team Engineer on the AI Security team, you will play a central role in adversary emulation exercises and capability development for our mission partners. Due to our unique position within the TA Directorate, the systems we red-team fall outside the realm of 'traditional' enterprise red teaming. Our targets are commonly AI-enabled platforms used within national security @contexts.
But this isn't a "make the LLM say the bad thing" @type of AI red team. We operate across multiple domains, meaning that our red teamers are expected to be experts in offensive cyber in addition to AI security. If you are experienced with offensive cyber tradecraft and have an interest in breaking into AI, this could be a good fit. Most of our red teamers are actively taking graduate-level technical courses at CMU and/or pursuing technical certifications. Perpetual learning is a core part of what we do.
While our red team exists within a research organization, research is only a portion of the work performed by our red team. Much of the work will involve red teaming real-world systems, sometimes at an aggressive cadence. This can involve planning and rehearsing red team TTPs, traveling to field sites, and presenting relevant findings. Like most red teams, we don't get to pick and choose our targets. This means that our red team needs to be well-rounded (both as individuals and as a team). Thus, we expect all applicants to be savvy with both Windows and Linux, solid with TCP/IP, and have some experience with penetration testing and/or red teaming.
What you'll do:
Red team real-world AI-enabled systems(both the model and the hardware/software/network that it runs on) in support of national securityobjectives.
Develop new tactics, techniques, and procedures for attacking AI-enabled systemsand related softwarein order tobetter prepare defenders for real-world threats.
Write tools in Python, PowerShell, C, and BASH to enable red team operations.
Represent the CERT technical portfolio of work and operations; communicate with external mission partners andinternalcollaboratorsin concert with CERT directorates and teams.
Who you are:
BS in computer science, software engineering, networking, information systems, or a related technical field with eight (8) years of experience; MS in computer science or technical/engineering field with five (5) years of experience; PhD in computer science or technical/engineering field with two (2) years of experience or equivalent combination of training and experience. Other educational backgrounds of a technical nature with experience as described may be considered.
You havepreviouspenetration testing, red teaming, or exploit development experience.
You haveprevioushands-on experience with at least one command and control framework (e.g., Cobalt Strike, Sliver).
You have experience programming/scripting in Python, C, and BASH(without theassistanceof AI)andare willing to learn PowerShell.
You haveexperiencewith reverse engineering tools (e.g.NSAGhidra, IDA Pro).
Youare able toread code and quickly spot basic vulnerabilities without theassistanceof AI or fuzzing.?
You arevery familiarwith TCP/IP and all layers of the OSI model.You have experienceusing Wireshark and can explainhow common network protocols work.
You have experience in assessing the security of both Linux and Windows systems. Experience with mobile(e.g., Android)and other operations systems is also appreciated.
You have at least two of the following relevant certifications:OSCP, CPTS,FORGE/RIOT,GXPN, GAWN, GCPN, CRTO, CRTL, OSEP, OSWE, CCNA, CWEE.Applicants without thesecertifications willstill be consideredif equivalentexperience isclearlydemonstratedduringtechnical interviews.
You have a willingness to travel (25%) outside of your office location to other SEI offices, sponsor sites, conferences, and offsite meetings.
You have excellent communication skills (oral and written), particularlyregardingtechnical communications with non-experts.?
You enjoy mentoring and cross-training others and sharing knowledge?within the broader community.?
You will be subject to a background investigation, and you must have the ability to obtain andmaintaina Department ofWarsecurity clearance.
Joining the CMU team opens the door to an array of exceptional benefits.
Benefits eligible (https://www.cmu.edu/hr/benefits/eligibility/index.html) employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance (https://www.cmu.edu/hr/benefits/health-welfare/index.html) as well as a generous retirement savings program (https://www.cmu.edu/hr/benefits/retirement-savings/index.html) with employer contributions. Unlock your potential with tuition benefits (https://www.cmu.edu/hr/benefits/tuition/index.html) , take well-deserved breaks with ample paid time off (https://www.cmu.edu/hr/benefits/time-away/pto.html) and observed holidays (https://www.cmu.edu/hr/benefits/time-away/holidays.html) , and rest easy with life and accidental death and disability insurance.
Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team (https://www.cmu.edu/hr/work-life/support/family-child-care-resources/index.html) to help navigate childcare needs, fitness center access (https://athletics.cmu.edu/recreation/facilities) ,and much more!
For a comprehensive overview of the benefits available, explore our Benefits page (https://www.cmu.edu/hr/benefits/index.html) **.
At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it's about finding the perfect fit for your professional growth and personal aspirations.
Are you interested in an exciting opportunity with an exceptional organization?! Apply today!
Location**
Arlington, VA, Pittsburgh, PA
Job Function
Software/Applications Development/Engineering
Position Type
Staff - Regular
Full Time/Part time
Full time
Pay Basis
Salary
More Information:
Please visit "Why Carnegie Mellon (http://www.cmu.edu/jobs/why-cmu/index.html) " to learn more about becoming part of an institution inspiring innovations that change the world.
Click here (https://www.cmu.edu/jobs/benefits-at-a-glance/) to view a listing of employee benefits
Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran .
Statement of Assurance (https://www.cmu.edu/policies/administrative-and-governance/statement-of-assurance.html)
Effective August 24, the URL for the CMU Careers site will change to https://cmu.wd115.myworkdayjobs.com/CMU .
Interested in a career with Carnegie Mellon University but not finding anything that currently aligns with your interests, background, or experience? Learn how to sign up for Job Alerts (https://www.cmu.edu/jobs/external-applicants.html#job-alerts) through your candidate profile.
If your heart is in your work, come work with us. Carnegie Mellon University isn't just one of the world's most renowned educational institutions - it's also a hotspot for some of the most talented doers, dreamers, and difference-makers on the planet. When you join our staff, you'll become an important part of our mission to create a healthier, safer, and more just life for all. No matter what your role or location, you'll connect and collaborate with dedicated, passionate colleagues - and you'll have the satisfaction of delivering work that truly matters.
We cultivate a vibrant, welcoming environment where everyone is valued and encouraged to contribute and achieve. In addition to competitive benefits and a robust support network, you'll have access to many tools and resources to sharpen your abilities and professional skills, as well as opportunities to engage and share perspectives with a dynamic and inspiring community of uniquely talented staff, faculty, students, and alumni.
The future is awaiting your expertise and intellect. Come join the architects of what's next. Apply now.
Learn more about Student Employment (https://www.cmu.edu/sfs/student-employment/index.html) .
Please see Faculty Careers. (https://www.cmu.edu/faculty-office/faculty-recruitment/faculty-careers.html)
For technical assistance, email HR Services (hr-help@andrew.cmu.edu) or call 412-268-4600.
We are committed to providing an accessible experience throughout our recruitment process. If you need assistance or a reasonable accommodation at any stage of the application, interview, or hiring process, please contact Equal Opportunity Services by email at employeeaccess@andrew.cmu.edu or by phone at 412-268-5072.
Prospective Employee Disclosures (https://www.cmu.edu/jobs/disclosures/index.html)