1

Red Team Jobs in California (NOW HIRING)

AI is seeking a Jailbreaking Lead (Red Team) whose personal mission and obsession is to jailbreak the world's leading frontier AI models. You will sit at the tip of the spear of one of the world ...

AI Red Team Engineer

San Francisco, CA · On-site

$200 - $250/hr

As the AI Red Team Engineer, you will help build the practice of red-teaming AI monitors (both Watcher's own defenses and frontier labs' monitoring systems (see our pilot campaign red-teaming ...

New

AI Red Team Engineer

San Francisco, CA · On-site

$182K - $238K/yr

As the AI Red Team Engineer, you will help build the practice of red-teaming AI monitors (both Watcher's own defenses and frontier labs' monitoring systems (see our pilot campaign red-teaming ...

About the role Anthropic's Safeguards team is seeking a Red Team Engineer to help ensure the safety of our deployed AI systems and products. In this role, you'll take an adversarial approach to ...

About the role The Safeguards team is seeking a Red Team Engineer to help ensure the safety of our deployed AI systems and products. In this role, you'll take an adversarial approach to uncover ...

About the Role As a Red Team Specialist focused on cyber, you will help answer two practical questions: What cyber capabilities can our models provide to real-world attackers, and do our safeguards ...

next page

Showing results 1-20

Red Team information

See California salary details

$10

$25

$71

How much do red team jobs pay per hour?

As of Sep 8, 2026, the average hourly pay for red team in California is $25.40, according to ZipRecruiter salary data. Most workers in this role earn between $15.19 and $23.70 per hour, depending on experience, location, and employer.

What does a red team do?

A Red Team job involves simulating real-world cyberattacks to identify security weaknesses before malicious hackers can exploit them. Red Team professionals use a variety of tactics, techniques, and procedures (TTPs) to test an organization's defenses, often mimicking advanced persistent threats (APTs). Their goal is to improve security by providing actionable recommendations based on their findings. This role requires expertise in penetration testing, social engineering, and adversarial thinking.

What skills and qualifications are needed for a red team?

To thrive as a Red Team member, you need strong expertise in penetration testing, vulnerability assessment, and a deep understanding of cybersecurity principles, usually demonstrated through relevant experience or certifications such as OSCP or CEH. Familiarity with tools like Metasploit, Burp Suite, Kali Linux, and various scripting languages is essential for effective simulation of threat actor techniques. Excellent problem-solving abilities, creative thinking, and strong communication skills help with reporting findings and collaborating with other cybersecurity professionals. These skills are critical for identifying and addressing security weaknesses to enhance an organization's defense strategies.

What are the daily activities and responsibilities of a red team?

As a Red Team professional, your typical day may involve planning and executing simulated cyberattacks, testing company networks and systems for vulnerabilities, and documenting your findings in detailed reports. You’ll often collaborate with Blue Teams (defensive security teams) and other IT staff to ensure your assessments provide meaningful insights into organizational security. Regular activities include researching emerging attack vectors, developing new testing methodologies, and conducting debriefs or training sessions to share lessons learned. This role requires staying current with evolving threats and adapting strategies to address complex, real-world scenarios.

How to get a job as a red teamer?

To become a red teamer, develop strong skills in cybersecurity, penetration testing, and scripting languages like Python or Bash. Obtain relevant certifications such as OSCP or CREST, gain experience with security tools like Kali Linux and Metasploit, and build a portfolio of simulated attack assessments to demonstrate your expertise.

What are red team jobs?

Red team jobs involve simulating cyberattacks to test an organization's security defenses. Professionals in these roles use hacking techniques, security tools, and penetration testing skills to identify vulnerabilities and improve security measures. These jobs often require knowledge of networks, systems, and security protocols, and may involve certifications like OSCP or CEH.

What are the most commonly searched types of Red Team jobs in California?

The most popular types of Red Team jobs in California are:

What are popular job titles related to Red Team jobs in California?

For Red Team jobs in California, the most frequently searched job titles are:

What job categories do people searching Red Team jobs in California look for?

The top searched job categories for Red Team jobs in California are:

What cities in California are hiring for Red Team jobs?

Cities in California with the most Red Team job openings:

Infographic showing various Red Team job openings in California as of September 2026, with employment types broken down into 80% Full Time, and 20% Part Time. Highlights an 100% In-person job distribution, with an average salary of $52,823 per year, or $25.4 per hour.

Jailbreaking Lead, Red Team

Berkeley, CA • On-site

$200 - $250/hr

Other

Posted 7 days ago


Key responsibilities

  • Personally develop and identify universal jailbreaks against frontier AI models, including dismantling defense-in-depth stacks and escalating vulnerabilities.

  • Invent new attack techniques, incorporate state-of-the-art methods, and shape the jailbreaking research agenda to stay ahead of evolving defenses.

  • Mentor team members, review red-teaming deliverables, and collaborate with frontier labs and government agencies to translate jailbreak findings into real-world mitigations.


Job description

FAR.AI is seeking a Jailbreaking Lead (Red Team) whose personal mission and obsession is to jailbreak the world's leading frontier AI models. You will sit at the tip of the spear of one of the world's leading AI red-teams, with a single, critical focus: find the universal jailbreaks that no one else can find, in the models used by hundreds of millions of people, and make sure they get fixed.

This is primarily a senior IC role with some management responsibilities, ideally for candidates who want to build and lead a jailbreaking team over time. An IC-only track is also available. Either way, you will spend the majority of your time hands‑on, building attacks and breaking frontier models, and setting the technical bar for what a world‑class jailbreak looks like.

About the Role

Jailbreaking is the core technical engine of the red team. As Jailbreaking Lead, you own that engine. You are the person who personally breaks the hardest targets, sets the bar the rest of the team pushes toward, and makes sure we keep discovering the highest severity, universal vulnerabilities – the most important vulnerabilities to fix – in the most heavily defended frontier models on the planet, faster than anyone else.

We expect you to spend at least 50-70% of your time hands‑on across 2026: breaking models, chaining novel attack classes through defense‑in‑depth stacks, helping to invent new techniques when existing ones fail, and setting the standard for what constitutes a significant vulnerability and a credible mitigation. The remaining time will go to managing/mentoring ICs, helping to shape the jailbreaking research agenda with Kellin, and making sure our findings land with frontier labs, governments, and the broader field. The rest of the red team will empower your work, whether through direct collaboration and support, novel research and red‑teaming infrastructure, or toolkits and agent build‑outs.

This is a senior IC role by default, intended to attract a world‑class jailbreaker whose personal mission is to find critical jailbreaks in the most heavily defended domains of the leading frontier AI models, and who has a track record of repeatedly doing so. We are open to a management track for candidates who want to hire and lead a jailbreaking team over time. We will not water down the IC bar to support the management track: both versions of this role require you to be, or be on a clear trajectory to being, one of the best jailbreakers in the world.

In practice, this role spans:

  • Lead jailbreaking on the highest‑stakes engagements:
    • Personally develop universal and near‑universal jailbreaks against frontier closed‑ and open‑weight models, in CBRNE, cyber, agentic security, extreme persuasion, and emerging risk domains;
    • Systematically dismantle defense‑in‑depth stacks (input filters, model‑level refusal and safe completion, reasoning monitors, output filters, account‑level moderation), chaining novel and established techniques;
    • Escalate initial vulnerabilities to expose their most severe form, maximising universality, success rate, and capability of elicited output;
    • Own the technical bar for vulnerability severity and generality on every major engagement.
  • Push the frontier of jailbreaking techniques:
    • Invent new attack classes when existing techniques fail (e.g., we have recently shipped novel attacks against Constitutional Classifiers and fine‑tuning APIs);
    • Monitor and rapidly incorporate state‑of‑the‑art methods from the literature, and build our own proprietary portfolio;
    • Shape the jailbreaking research agenda in partnership with Kellin, ensuring our toolkit stays ahead as defences evolve;
    • Stress‑test novel affordances (innovations in agents, tool use, long context, multimodal, reasoning, etc.) as frontier systems evolve.
  • Raise the technical bar across the team:
    • Set the standard for rigour, creativity, and precision in jailbreaking across the red team;
    • Mentor ICs on attack craft, running pairing sessions, post‑engagement retros, and internal writeups that turn your craft into team capability;
    • Review major red‑teaming deliverables for technical quality, severity judgment, and clarity;
    • If on the management track: hire, manage, and grow a jailbreaking team without sacrificing your personal technical edge.
  • Translate jailbreaks into real‑world impact:
    • Work directly with frontier labs and government agencies so that findings lead to real mitigations, not just disclosed vulnerabilities;
    • Contribute to public reports, benchmarks, and the FAR.AI safety leaderboard that shape industry norms;
    • Make precise, calibrated technical judgments about what is universal, what is reliable, and what a capable threat actor could actually do with a finding.

This role would be a great fit if you:

  • Obsess over frontier model jailbreaks the way elite security researchers obsess over zero‑days. If breaking the newest, most heavily defended models is already what you do for fun, you are the person we are looking for;
  • Have a track record (public, private, or both) of finding non‑obvious, high‑severity vulnerabilities in frontier AI systems, including universal or near‑universal jailbreaks in the most heavily defended risk domains;
  • Combine deep technical craft with the judgment to know which vulnerabilities actually matter and how defences are put together across different frontier models. Have the communication skills to make frontier labs and governments act on them;
  • Are excited by high‑stakes, real‑world technical work where success is measured by mitigations adopted and standards shifted, not papers published;
  • Want to work with leading AI companies, governments, and academics. We’re a lean organisation and leverage impact through strategic partnerships;
  • Value independence and the ability to publish and speak honestly about risks;
  • Care deeply about AI safety and impacting how advanced AI systems are deployed;
  • Has a “get shit done” attitude and is willing to do whatever it takes to change the world;
  • Thrive in fast‑moving, ambiguous environments with shifting threat models and defences.

This role would be a poor fit if you:

  • Prefer narrowly scoped research problems with clear academic metrics of success;
  • Want to prioritise foundational research disconnected from red‑teaming outcomes. Our Research Scientist position may be a better fit;
  • Are primarily motivated by equity upside or compensation;
  • Wish to operate within clearly defined bounds. FAR.AI is planning to double in size in the next 12‑18 months, and the red team will grow even faster. A lot will change and navigating uncertainty is core to the role;
  • Are not willing to move at the velocity we need or want a slow‑moving, highly structured environment with fixed problem definitions;
  • Are looking for a pure management role where you stop shipping jailbreaks yourself. Even on the management track, this role requires you to remain a top‑tier hands‑on jailbreaker.
  • Are not willing to be relentless.
About You

Strong candidates for this role typically have many (but not necessarily all) of the following:

  • Personally developed universal or near‑universal jailbreaks against at least one leading frontier model;
  • Demonstrated ability to discover non‑obvious, high‑severity vulnerabilities in frontier AI systems, complex software systems, or other hardened adversarial targets;
  • Deep, hands‑on jailbreaking experience with demonstrated success against modern frontier models with layered defences, including chaining multiple attack techniques through defense‑in‑depth stacks;
  • Experience with black‑box optimisation methods, multimodal attacks, and/or agentic red‑teaming;
  • Deep understanding of large language model architectures, training processes, and failure modes, including how these factors influence model behavior under adversarial conditions;
  • Strong existing track record in AI, adversarial ML, security, or another highly technical subject (e.g., CS, cybersecurity, math, physics);
  • Have thrived in rapidly evolving environments where techniques go obsolete fast and you have to invent your way forward;
  • Invented novel attack classes;
  • Demonstrated drive for mission/impact and desire to create real impact on frontier AI systems;
  • Demonstrated relentlessness in achieving ambitious goals.

It is a strong plus (but not required) if you have:

  • Prior collaboration with AI labs, security teams, or government safety institutes;
  • A track record in top CTF teams, offensive security research, or adversarial ML research;
  • Published work in AI safety, security, or robustness;
  • Can communicate technical findings and recommended mitigations to both technical and non‑technical audiences, including frontier lab safety teams and senior policymakers;
  • Prior experience mentoring technical ICs or leading a small technical team (required only for the management track).

If you are earlier in your career but have a standout jailbreaking track record, we still encourage you to apply as we are also hiring for less senior positions on the team. If you are missing the hands‑on jailbreaking depth but have adjacent strengths, we encourage you to consider our other open roles on the red team.

Logistics

If based in the USA or Singapore, you will be an employee of FAR.AI (501(c)(3) research non‑profit / non‑profit CLG). Outside the USA or Singapore, you will be employed via an EOR organisation on behalf of FAR.AI.

  • Location: Remote globally. We can sponsor US or Singapore visas.
  • Hours: Full‑time. Expect up to one trip per month for convenings, government meetings, or team gatherings.
  • Compensation: USD 170,000–250,000, depending on experience. Exceptional candidates may be offered more.

We know these roles are rare and the skill combination is unusual. If you’re uncertain whether your background fits but are excited by the mission and challenges, we encourage you to apply – we’re looking for excellence and potential, not a perfect resume match.

#J-18808-Ljbffr