AI Red Teamer, Cybersecurity (Remote)

Handshake

2h ago 0 views 0 applications
Contract Remote
Remote (USA)
$65 - $125
Contract

Job Description

Cybersecurity Red TeamerLocation: Seattle, WA, or Remote within the United StatesWork arrangement: Flexible, including part-time availabilityHandshake was founded on a simple belief: everyone deserves a path to a great career, regardless of where they went to school or who they know. Today, we support 25 million job seekers, more than 1 million employers, and 1,600 educational institutions.In 2025, we started Handshake AI and built the fastest-growing AI data business in history. We work directly with researchers at frontier AI labs to create evaluations, publish benchmarks, and push the boundaries of data. We have grown from $0 to approximately $1 billion in run rate and pay approximately $60 million to more than 30,000 individuals every month.Why join Handshake nowShape how careers evolve in the AI economy at a global scale, with an impact your friends, family, and peers can see and feelPartner closely with world-class AI labs, Fortune 500 companies, and leading educational institutionsWork with engineers, scientists, operators, and other professionals from organizations such as Palantir, Meta, and Scale AI, as well as former YC foundersHelp build a massive, rapidly growing business with billions in revenueWork from Seattle or remotely from anywhere within the United StatesAbout Handshake AIHuman data is core infrastructure for AI advancement. Frontier AI labs currently improve model capabilities through data-intensive post-training techniques. We believe spending on AI training data will increase three to five times over the next few years and continue growing as models expand into new domains.Handshake AI supports frontier AI labs by working on their most complex data challenges at scale.About the roleAs a Cybersecurity Red Teamer, you will evaluate whether AI models can be manipulated into generating functional malware, viable exploit code, attack tooling, or step-by-step operational guidance that could give a threat actor meaningful assistance in carrying out cyberattacks.Your job is to find the gaps between what a model’s safety guardrails are intended to block and what a skilled adversary can actually extract.This role requires you to think like an attacker who has access to a highly capable AI assistant. You will craft adversarial prompts and multi-turn interaction chains that simulate how real threat actors, ranging from inexperienced attackers to advanced persistent threat operators, might use LLMs to accelerate reconnaissance, weaponization, exploitation, lateral movement, persistence, and exfiltration.You will then evaluate whether the model’s output is genuinely dangerous or merely surface-level noise.Deep cybersecurity expertise is essential. Your value will come from being able to examine a model-generated payload, exploit chain, or attack plan and determine whether it would actually work, how much refinement it would require, and what type of attacker it could meaningfully assist.This position may be performed from our Seattle location or remotely within the United States. Seattle-based and remote team members will collaborate closely through shared evaluation workflows, regular feedback, and virtual working sessions.What you will doDesign technically grounded adversarial prompts that test whether models provide meaningful assistance across the cyber kill chain, from reconnaissance through exfiltration and impactEvaluate model-generated code and technical output for functional correctness, determining whether outputs represent real exploits, plausible attack tooling, or nonfunctional noiseTest model behavior across offensive categories, including malware generation, vulnerability exploitation, social engineering, credential harvesting, privilege escalation, command-and-control infrastructure, and data exfiltrationProbe dual-use boundaries by testing how models respond to queries that combine legitimate security research, penetration testing, and defensive operations with offensive applicationsSimulate attacker personas at varying skill levels, including opportunistic, intermediate, and advanced or APT-level actorsTest multi-step and multi-turn attack chains, including scenarios in which early turns establish benign context before pivoting to malicious requestsScore model responses using structured harm taxonomies and severity rubrics calibrated to real-world exploitabilityDocument findings with clear technical reasoning, including what a response gets right, what it gets wrong, and what level of attacker it could realistically assistContribute to the development and refinement of cybersecurity-specific evaluation frameworks and threat modelsCollaborate with red teamers, AI researchers, and policy teams to translate findings into actionable model improvementsStay current on evolving tactics, techniques, and procedures, CVEs, jailbreak techniques, and the intersection of AI and offensive securityCore qualificationsProfessional experience in offensive security, penetration testing, red teaming, vulnerability research, malware analysis, threat intelligence, or incident responseAbility to read, write, and evaluate code in languages commonly used for offensive tooling, such as Python, PowerShell, Bash, C/C++, or JavaScriptUnderstanding of common attack frameworks, techniques, and procedures, including MITRE ATT&CK and OWASPAbility to assess the functional correctness and real-world exploitability of model-generated technical outputStrong hands-on experience using multiple LLMs, such as ChatGPT, Claude, Gemini, or open-source modelsCreative and adversarial problem-solving skillsClear and precise written communication, including the ability to explain technical risk to nonspecialist audiencesStrong ethical judgment and the ability to separate adversarial thinking from personal valuesAbility to work independently while collaborating effectively in a feedback-heavy, distributed environmentNice to haveRelevant certifications, such as OSCP, OSCE, GPEN, GXPN, CRTO, CRTL, CEH, or similarActive or previous security clearanceExperience with exploit development, reverse engineering, or binary analysisBackground in cloud security, container security, or infrastructure-as-code attack surfacesFamiliarity with AI and machine-learning attack surfaces, including prompt injection, model extraction, training-data poisoning, and adversarial examplesExperience building or operating command-and-control frameworks, custom implants, or offensive toolingA bug-bounty track record or published CVEsPrevious work in trust and safety, content moderation, or AI evaluationFamiliarity with LLM APIs or evaluation toolingYou may be a strong fit ifYou have spent years breaking into systems and want to apply that mindset to testing AI modelsYou can examine a model-generated reverse shell, phishing template, or privilege-escalation script and quickly determine whether it would work in a real environmentYou think in kill chains and attack graphs, not just individual promptsYou understand that the difference between a useful coding assistant and a dangerous one often comes down to context, specificity, and operational detailYou closely follow the offensive-security community and stay current when new techniques emergeYou care about AI safety because you understand what can happen when powerful tools are used irresponsiblyYou can collaborate effectively with a team whether you are working from Seattle or remotelyContent noticeThis role involves regular and deliberate engagement with offensive cybersecurity content. You will create and evaluate scenarios involving malware, exploit code, social engineering, network-intrusion techniques, and other attack methodologies.All work is conducted within a structured evaluation framework with strict ethical guidelines. Candidates must be able to engage with this material professionally, responsibly, and sustainably.