Sr. AI Red Team Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Cambridge, Massachusetts, United States; hybrid 70/30 work model with 70% in-office collaboration. Only U.S. persons—citizens, permanent residents, asylees, or refugees—are eligible due to U.S. export control requirements. is unable to sponsor non-U.S. persons for an export control license.
Salary: $145,900–$234,200 per year, with potential annual bonus, incentive compensation, or equity award.
Company
develops mRNA technology and medicines through a biotechnology platform.
What you will do
- Plan, execute, and document full-spectrum red team operations across digital, physical, and hybrid environments.
- Run end-to-end attack simulations covering reconnaissance, initial access, lateral movement, privilege escalation, exploitation, post-exploitation, and data exfiltration.
- Develop and maintain covert offensive infrastructure, including C2 frameworks, payload obfuscation, cloud staging, and beacon management.
- Build custom scripts and exploits with Python, PowerShell, Bash, Go, and other languages to emulate adversary TTPs.
- Conduct adversary emulation informed by threats targeting biotech, pharma, and critical manufacturing sectors, including AI-enabled attack paths.
- Partner with Incident Response, Threat Intelligence, and Detection Engineering to measure detection effectiveness and improve security controls.
Requirements
- 4+ years of cybersecurity experience with deep red team, offensive security, or adversary simulation expertise.
- Experience conducting complete attack chains, including initial access, lateral movement, privilege escalation, and data exfiltration.
- Expertise in network penetration testing, Active Directory exploitation, AWS, Azure, O365, endpoint evasion, and AI systems.
- Strong knowledge of MITRE ATT&CK, C2 frameworks, offensive tooling, purple team methods, and OPSEC.
- Solid scripting and automation skills in at least one major language, including Python, PowerShell, Bash, or Go.
- Must qualify as a U.S. person to access export-controlled technology and data.
Nice to have
- Experience targeting OT or laboratory-connected systems.
- OSCP, OSEP, OSED, CRTO, or equivalent hands-on offensive security certification.
- Ability to communicate complex offensive findings to technical engineers and executive stakeholders.
Culture & Benefits
- In-person collaboration supported by a 70/30 work model.
- Healthcare and voluntary benefit programs.
- Fitness, mindfulness, and mental health resources.
- Family planning benefits covering fertility, adoption, and surrogacy.
- Paid time off including vacation, volunteer days, sabbatical, global recharge days, and discretionary year-end shutdown.
- Savings and investment programs plus location-specific perks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →