Sr. AI Red Team Engineer
ModernaAbout the role
The Role:
In this role, you will design, execute, and evolve advanced adversarial simulation campaigns to test Moderna’s cyber resilience across corporate, laboratory, and manufacturing environments with a focus on AI and the attack surface it exposes.
You will act as a hands-on operator, building and running end-to-end offensive campaigns — from initial reconnaissance to network exploitation and post-exploitation within high-value segments like lab, OT systems, cloud, and AI infrastructure.
This role reports to the Red Team Program Lead and works very deeply and closely with Incident Response, Threat Intelligence, and Detection Engineering to convert findings into durable defenses. The primary output of the program focuses on building defenses, detections that result in prevention of real adversarial tradecraft.
Your mission: identify, emulate, and weaponize attacker tradecraft before real adversaries do against Moderna.
Here’s What You’ll Do:
Plan, execute, and document full-spectrum red team operations targeting digital, physical, and hybrid environments.
Develop and maintain offensive toolchains and infrastructure for covert operations (C2 frameworks, payload obfuscation, cloud-based staging, and beacon management).
Conduct external-to-internal attack simulations.
Collaborate with detection and incident response teams to measure time-to-detect, time-to-contain, and overall detection efficacy.
Build and maintain custom scripts and exploits using Python, PowerShell, and other languages to simulate real adversary TTPs.
Perform adversary emulation based on threat intel tied to biotech, pharma, and critical manufacturing sectors.
Lead post-operation technical debriefs with IR and Threat Intel to derive new detection opportunities and security controls.
Contribute to the development of internal red team maturity, progressing toward a continuous red team model.
Here’s What You’ll Need (Basic Qualifications)
4+ years in cybersecurity with deep experience in red teaming, offensive security, or adversary simulation.
Proven ability to conduct end-to-end attack chains, including initial access, lateral movement, privilege escalation, and data exfiltration.
Expertise in network penetration testing, Active Directory exploitation, cloud attacks (Azure, AWS, O365), endpoint evasion, and AI systems.
Experience targeting OT or lab-connected systems is a plus.
Experience with modern AI based attacks and how to leverage them in a longer attack path.
Strong knowledge of MITRE ATT&CK, C2 frameworks, and offensive tooling.
Familiarity with purple team methodologies and integrating offensive results into defensive playbooks and detections.
OPSEC discipline and experience running stealth operations under blue team monitoring.
Solid scripting and automation skills in at least one major language (Python, PowerShell, Bash, or Go).
Here’s What You’ll Bring to the Table (Preferred Qualifications)
Preferred certifications: OSCP, OSEP, OSED, CRTO, or equivalent hands-on offensive credentials.
Ability to communicate complex offensive findings clearly to both technical engineers and executive stakeholders.
Pay & Benefits
At Moderna, we believe that when you feel your best, you can do your best work. That’s why our benefits and well-being resources are designed to support you—at work, at home, and everywhere in between.
- Competitive healthcare, plus voluntary benefit programs to support your unique needs
- A holistic approach to well-being, with access to fitness, mindfulness, and mental health support
- Family planning benefits, including fertility, adoption, and surrogacy support
- Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
- Savings and investments to help you plan for the future
- Location-specific perks and extras
The salary range for this role is $145,90
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s