AI Evaluation & Red Team Specialist
You find out what a model does wrong before its users do, and measure it rather than guessing.
No degree needed Moderate to hard, and unusually dependent on adversarial imagination.
Probe models you are authorised to test — your own deployments, systems you have permission for, or programmes that invite it. Providers publish usage policies and many run disclosure or bug-bounty routes; use them. Publishing a working attack against a live third-party service without going through disclosure can breach both the provider's terms and computer-misuse law.
Can I actually do this?
One of the newest roles on this site, and genuinely open — the field is young enough that few people have long experience in it, which cuts both ways. Open without a degree. Domain expertise outside computing (medicine, law, languages, a lived perspective the training data underrepresents) is a real asset here, more than in most technical roles.
Who it suits. People who instinctively look for the input nobody anticipated, and who will then quantify how often it works.
Runway. Months to a year if you can already program; the craft is newer than the people in it.
Coming from QA or security testing? The mindset is the thing, and it transfers better than any specific tooling. QA / Test Automation Engineer Penetration Tester AI Safety Researcher
Also advertised as
The route
Four stations, in order. Each one is a thing you finish before the next matters.
-
Station one
Learn it free
Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.
OWASP Top 10 for LLM Applications
Free to learn · no certificate
The catalogue of ways these systems fail — prompt injection, data leakage, insecure output handling. Free and open.
Verified 2026-07-28
Prompt engineering overview (Anthropic)
Free to learn · no certificate
You cannot probe a system's limits without knowing how it is meant to be driven. Free documentation.
Verified 2026-07-28
NIST AI Risk Management Framework
Free to learn · no certificate
Your findings have to land somewhere. This is the frame organisations use to act on them. Free.
Verified 2026-07-28
-
Station two
Attest strategically
Nothing to buy, and nothing established enough to be worth buying. This field is too new for a meaningful certification market, which is a genuine advantage: a published evaluation with a reproducible method is the credential, and it costs nothing but the work.
Nothing here is worth paying for
No credential needed
Nothing to buy, and nothing established enough to be worth buying. This field is too new for a meaningful certification market, which is a genuine advantage: a published evaluation with a reproducible method is the credential, and it costs nothing but the work.
Checked 2026-07-28
-
Station three
Prove it
A certificate says you passed a test. These say you can do the job.
An evaluation with a reproducible method
Not 'I found a jailbreak' — a measured failure rate on a defined set of inputs, that someone else could run and get your numbers.
A failure mode nobody had catalogued
Something specific to a domain you know well. This is where outside expertise beats general ability.
A negative result reported honestly
A hypothesis about a weakness that turned out not to hold. Publishing that is the mark of an evaluator rather than a demonstrator.
-
Station four
Get hired
Search these exact titles
Who hires for this. Model developers, AI safety institutes, large companies deploying models, and specialist evaluation consultancies.
Published evaluations are reproducible by definition, which makes this one of the easiest specialisms to evidence publicly. That is our reasoning about what is inspectable, not a verified hiring statistic.
On salaryWe don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.
Where this route continues
- AI Safety Researcher — the research side
- AI Security Engineer — the security side
- AI Safety Researcher — sideways move
- AI Security Engineer — sideways move
- Penetration Tester — sideways move
This page last verified 2026-07-28 · How we verify
OWASP LLM Top 10, Anthropic prompt engineering overview and NIST AI RMF fetched and READ 2026-07-28.