AI Red Team Engineer
ByLabs - Seattle, WA
Hiring: AI Red Team Engineer Company: ByLabs Location: Seattle, WA Job Posted Time: 2026-09-17 04:39:11 Employment Type: Contract Target Skills & Keywords : Blockchain, LLM, Linux, OWASP, Penetration Testing, PowerShell, Python, RAG, SOC, Smart Contracts, Web3, macOS About the job Experience: •3+ years of hands-on penetration testing or red team experience Required Skills: •Design and execute end-to-end red team operations covering the full attack chain: reconnaissance, initial access, lateral movement, privilege escalation, and data exfiltration •Replicate APT group TTPs (e.g., Lazarus, APT41) to validate detection and incident response capabilities •Develop and maintain custom offensive tools, C2 frameworks, and evasion techniques to simulate advanced threats •Participate in BAS (Breach and Attack Simulation) playbook design and execution across Windows, macOS, and Linux platforms •Research AI/LLM attack surfaces: Prompt Injection, model poisoning, adversarial examples, training data contamination, and AI Agent security risks •Evaluate security risks in AI/LLM applications (RAG, MCP, Tool Use, Agentic workflows) and provide red team findings •Track AI security research (MITRE ATLAS, OWASP LLM Top 10) and produce internal threat intelligence •Partner cross-functionally with the blue team to translate red team findings into detection rules and defensive hardening Qualifications: •Proficiency with at least one mainstream C2 framework •Strong vulnerability exploitation fundamentals: web (OWASP Top 10), internal network (AD attack chains), cloud environments •Familiar with MITRE ATT&CK framework; able to map TTPs and design corresponding attack scenarios •Scripting/tooling development skills (Python, Go, or PowerShell) •Understanding of LLM application architectures (RAG, Agent, MCP, Tool Use) and ability to identify attack surfaces •Hands-on research or PoC experience with Prompt Injection, jailbreaking, or model extraction attacks •Familiar with MITRE ATLAS framework and AI/ML threat classification •(Preferred) Holds at least one major red team certification: OSCP, CRTO, CRTE •(Preferred) Web3 / blockchain security background (smart contract audits, on-chain attack analysis) •(Preferred) CTF experience or published vulnerability research (CVE, conference talks, technical blog) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!