AI Vulnerability Researcher
Pittsburgh
Full Time Senior-level / Expert Clearance required USD 83K - 155K *
SEI - Carnegie Mellon University
The Software Engineering Institute (SEI) at Carnegie Mellon University is a Federally Funded Research and Development Center (FFRDC) focused on advancing software engineering, cybersecurity, and process improvement. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Our core purpose is to help organizations improve software engineering capabilities and develop or acquire the right software, defect free, within budget and on time, every time. Artificial Intelligence (AI) engineering is a key focus area, as the SEI recently developed the AI Security Incident Response Team (AISIRT) to fill the need for a capability that can identify, analyze, and respond to threats, vulnerabilities, and incidents that emerge from ongoing advances in AI and machine learning (ML).
The SEI CERT Division is seeking applicants for the new AI Vulnerability Researcher role. The Vulnerability Analysis Team, within the Threat Analysis Directorate, is an elite team of National Security dedicated personnel that work to reduce the societal harm from vulnerable information processing systems and related processes. The Vulnerability Analysis Team has three core functions: 1) research and development (R&D) of systemic software vulnerabilities and Coordinated Vulnerability Disclosure (CVD) processes; 2) vulnerability response and management to mitigate priority vulnerabilities; and 3) vulnerability community outreach and engagement to influence software policies and standards. AI is software, and the Vulnerability Analysis Team is now applying its expertise in cybersecurity to enhance AI software engineering.
As an AI Vulnerability Researcher you will have opportunity to advance the start-of-the-art in AI software and system vulnerability research and advance the CVD operations of AI vulnerabilities on a national and global scale. You’ll also collaborate with network defenders, developers, security researchers, and policymakers, and share findings through advisories, papers, and tools. You will have the opportunity to influence upcoming technology trends leading to more secure and sustainable AI systems.
What you will do:
- Collaborate with multiple CMU and SEI teams and disciplines such as AI engineering, AI/ML and advanced computing labs, AI security, malware reverse engineering, and automated code analysis.
- Develop state of the art approaches to analyze AI software and systems in various forms.
- Apply these approaches to discover and understand systemic vulnerabilities in AI software systems and how threats evolve from these enable attacker’s tradecraft.
- Study and influence the AI software security ecosystem to address the entire vulnerability lifecycle.
- Evaluate vulnerability analysis reports submitted by world-class researchers to assess and analyze these with a strong grasp of the details.
- Employ vulnerability analysis to uncover fundamental assumptions and flaws in the current underlying AI software and system development practices.
- Conduct vulnerability response and management (CVD) to mitigate discovered or reported AI software and system vulnerabilities.
- Improve the CVD process and supporting tools to scale and address vulnerabilities in a timely fashion.
- Publish reports, technical notes, white papers, Vulnerability Notes, and blog posts to a variety of audiences.
- Conduct outreach and engagement activities across the vulnerability communities (public and private) to influence AI software security policies and standards.
Who you are:
- You are dedicated to protecting our nation’s sovereignty and ensuring the safety of our citizens.
- You have a deep interest in AI and cybersecurity, great intellectual curiosity, and a desire to create national-level impacts beyond our organization.
- You enjoy developing and communicating innovative ideas, and thinking creatively to solve tough problems.
- You relate collaboratively and diplomatically with people inside and outside the organization.
- You have a strong understanding of research methods in computer science, engineering and security, and related fields as well as of Internet fundamentals including network protocols, provider operations and governance.
- You enjoy mentoring and training others as well as sharing knowledge.
You have experience:
- Designing or developing AI systems
- Applying AI and ML within deployment environments
- Vulnerability research, discovery, assessment, analysis, disclosure, and mitigation
- Applying knowledge of technology, systems architecture, and security best practices to practical problems in enterprise security
- Advising on a range of security topics based on research, development, and expert opinion.
- Organizing, planning, and executing complex projects
- Communicating complex system designs, technical approaches and road maps to sponsors, project managers and technical staff, and the ability to distill the implications of complex research results and apply those results to large-scale operations
- Applying modern data-driven research methods to cost-effectiveness analysis, risk analysis and information security decision making and collaborating on industry and academic community projects
- Developing software in a variety of software programming languages both modern and legacy
- Mathematical programming, statistical modeling, or machine learning
- Recognizing and properly handling confidential and sensitive information
You have:
- BS in Computer Science, Statistics, Data Science, Information Science, or Analytical discipline with eight (8) years of experience; OR MS in the same fields with five (5) years of experience; OR PhD in the same fields with two (2) years of experience.
- Work at the SEI headquarters in Pittsburgh, PA, with hybrid work arrangements as required.
- Willingness to travel to various locations to support the SEI’s overall mission. This includes sponsor sites, conferences, and offsite meetings on occasion. Moderate Travel (15%)
- Are subject to a background check and obtain and maintain an active Department of Defense security clearance. Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.
Why work here?
- Join a world-class organization of National Security superheroes that have unrivaled impact on software, system, AI, and systemic vulnerabilities.
- Work with cutting edge technologies and experts to solve tough problems for the government and the nation.
- Get 8% monthly contribution for your retirement, without having to contribute yourself.
- Get tuition benefits to CMU and other institutions for you and your dependent children.
- Enjoy a healthy work/life balance with flexible work arrangements and paid parental and military leave.
- Get access to university resources including mindfulness programs, childcare and back-up care benefits, a monthly transit benefit on WMATA, free transportation on the Pittsburgh Regional Transit System.
- Enjoy annual professional development opportunities; take courses at CMU; attend conferences and training or obtain a certification and get reimbursed for membership in professional societies.
- Qualify for relocation assistance and so much more.
Location
Pittsburgh, PAJob Function
Software/Applications Development/EngineeringPosition Type
Staff – RegularFull time/Part time
Full timePay Basis
SalaryMore Information:
Please visit “Why Carnegie Mellon” to learn more about becoming part of an institution inspiring innovations that change the world.
Click here to view a listing of employee benefits
Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Artificial Intelligence CERT Clearance Code analysis Computer Science Governance Incident response Machine Learning Malware PhD R&D Reverse engineering Risk analysis Security Clearance Vulnerabilities
Perks/benefits: Career development Conferences Parental leave Relocation support Travel
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.