AI Security Research & Red Team Engineer
$166k - $208k • Hybrid
Posted 10d ago
Remote Work Policy
On-site
Categories
AI Research Engineer
About the job
We are seeking a highly skilled AI Security Research & Red team engineer to join our Red Team within the Security Threat Detection, Response and Emulation organization. This is a critical role that will be at the forefront of protecting our company and customers from malicious threats. You will be responsible for driving security research, exercises, and activities that emulate real world attackers and attacks to drive improvements in Cloudflare’s security posture focusing on AI, Agents, harnesses and LLM’s. You will act as the "sparring partner" for SIRT, conduct unannounced exercises to help them refine playbooks, test on-call rotations, and ensure forensic tooling is effective. You will partner closely with Threat Detection & Threat Engineering teams to bridge the gap between adversary simulation and defensive coverage, proactively identify detection gaps, lead the development of new detection logic, and establish rigorous validation frameworks. You will also drive resilience in processes and implementations by providing empirical evidence of control effectiveness to GRC.
Responsibilities
- Perform AI security and vulnerability research, identifying AI-specific vulnerabilities and risks.
- Conduct rigorous testing of agentic implementations and LLM usage to identify AI-related attack surfaces.
- Execute full-chain red team operations targeting Cloudflare’s infrastructure, networks, and product ecosystems.
- Establish a framework for testing security efficacy of WAF, EDR, and SIEM detections.
- Collaborate with the Blue Team to translate findings into defensive improvements.
- Provide technical expertise and mentorship, fostering a culture of curiosity and ethical hacking.
- Translate complex technical exploits into risk-based narratives for leadership.
- Act as a sparring partner for the Security Incident Response Team (SIRT).
- Partner with Threat Detection & Threat Engineering to identify detection gaps and develop new detection logic.
- Drive resilience in processes and implementations by providing empirical evidence of control effectiveness to GRC.
Requirements
- 4+ years in offensive security, application security, or a relevant field.
- Deep knowledge of AI, coding agents, LLMs, prompt engineering, AI-related attack vectors (e.g., prompt injection, jailbreaking), and Agentic concepts.
- Strong background in manual penetration testing, exploit development, or cloud security (AWS/GCP/Bare Metal).
- Experience using the MITRE ATT&CK framework to map coverage and identify defensive telemetry blind spots.
- Ability to explain complex exploits to non-technical stakeholders.