Senior AI Red Team Analyst
Eagan, Dakota County, Minnesota, USA
Listed on 2026-05-10
-
IT/Tech
Cybersecurity
About the Role
Thomson Reuters is seeking a Senior AI Red Team Analyst who supports offensive security operations by simulating realistic adversary behavior in enterprise environments. This role focuses on hands‑on execution of red team activities and close collaboration with detection, response, and threat engineering teams to improve security visibility, detection coverage, and defensive outcomes.
This role is intended for practitioners who actively perform offensive security work and want to grow deeper in adversary emulation, purple teaming, and modern enterprise attack scenarios.
- Execute scoped red team and adversary simulation activities
- Perform offensive testing across endpoint and identity environments, Active Directory and authentication flows, and Cloud and SaaS platforms (AWS, Azure, GCP, etc.)
- Use real‑world attacker techniques to validate preventive and detective controls
- Participate in purple team exercises with Detection Engineering and Blue Team partners
- Document findings and support post‑engagement reporting
- Contribute to attack playbooks and scenario development, tooling reuse, refinement, and documentation, and repeatable adversary behaviors aligned to MITRE ATT&CK
- Stay current on emerging attacker techniques, tools, and tradecraft
- 2+ years of experience in Red team/offensive security or Penetration testing
- Working knowledge of Windows systems, basic Active Directory concepts, common attacker behaviors (credential access, lateral movement, persistence)
- Familiarity with MITRE ATT&CK and common red team or offensive security tooling
- Basic scripting or automation skills (Python, Power Shell, or similar)
- Ability to collaborate with teammates and clearly communicate technical findings
- Practical experience using AI tools (e.g., ChatGPT, Claude) for security‑related tasks such as researching attacker techniques or vulnerabilities, assisting with payload generation, scripting or automation, or drafting or refining detection ideas, attack scenarios, or documentation
- Public writeups, blog posts, conference talks, or other authored security content
- Experience with purple team exercises or detection validation
- Exposure to cloud security or identity‑focused attacks or endpoint Detection & Response (EDR) platforms
- Deeper experimentation with AI‑assisted workflows
- Hybrid Work Model:
Flexible hybrid working environment (2‑3 days a week in the office depending on the role) while delivering a seamless experience that is digitally and physically connected. - Flexibility & Work‑Life Balance:
Flex My Way supportive workplace policies for personal and professional responsibilities, including work from anywhere for up to 8 weeks per year. - Career Development and Growth:
Continuous learning and skill development programs such as Grow My Way and a skills‑first approach. - Industry Competitive Benefits:
Comprehensive benefit plans including flexible vacation, two company‑wide Mental Health Days off, access to the Headspace app, retirement savings, tuition reimbursement, employee incentive programs, and resources for mental, physical, and financial wellbeing. - Culture:
Global inclusion, belonging, flexibility, work‑life balance, values such as Obsess over Customers, Compete to Win, Challenge Your Thinking, Act Fast/Learn Fast, and Stronger Together. - Social Impact:
Two paid volunteer days off annually and opportunities for pro‑bono consulting projects and ESG initiatives. - Real‑World Impact:
Support customers in pursuing justice, truth, and transparency through trusted information.
Base compensation range for eligible US locations is $94,900 USD - $176,300 USD. Base pay is influenced by experience and skills, with a comprehensive Total Reward program that includes flexible benefits and other well‑being programs. An annual bonus may also be eligible.
Thomson Reuters is an Equal Employment Opportunity Employer. We make reasonable accommodations for applicants with disabilities and other protected classifications in accordance with applicable law. For more information on accommodations, contact HR.Le
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).