Back to Jobs
Research Lead – AI Cyber Testing & Evaluation
RAND · USA · Full-time
IT & Cybersecurity Easy Apply Hybrid
Apply Now
Posted 3 weeks ago · Job #50
About the Role

RAND’s Center on AI, Security, and Technology (CAST) conducts advanced research on artificial intelligence, biotechnology, and other transformative technologies to inform policies that safeguard global security.

As a Research Lead, you will manage significant research budgets, oversee technical and policy analysis projects, and guide multidisciplinary teams of engineers, scientists, and policy experts. Your work will focus on evaluating how AI systems perform across the cyberattack lifecycle — from initial access to defense evasion — and developing benchmarks that shape responsible AI policy worldwide.

Key Responsibilities

Lead technical research projects and policy analysis on AI and cybersecurity.

Build evaluation systems for AI performance across attack lifecycles.

Develop benchmarks for autonomous operations, reasoning over attack graphs, and multi‑stage cyber scenarios.

Produce technical reports, evaluation frameworks, and policy briefs for government and industry stakeholders.

Manage budgets, personnel, and cross‑functional teams.

Contribute to RAND’s reputation for rigorous, objective analysis

Requirements

Required:

6+ years of technical experience in security engineering, software/hardware development, or related fields.

6+ years of management experience leading cross‑functional teams and budgets.

Proficiency in programming languages such as Python, Java, or C/C++.

Experience with red team operations or offensive cyber capabilities.

Strong communication skills and ability to work in multidisciplinary teams.

Preferred:

Background in advanced persistent threat (APT) tactics and defense strategies.

Experience in AI/ML research, model training, or deployment.

Creative thinking in offensive/defensive cyber strategies.

Graduates of CNODP, RIOT, FORGE, or equivalent programs.

Education Requirements

PhD in Computer Science, Engineering, Cybersecurity, Mathematics, Policy, or related fields with 3+ years of experience, OR

Master’s degree with 6+ years of experience, OR

Bachelor’s degree with 8+ years of experience.

Advanced degrees (Master’s or PhD) preferred.

Security Clearance

Ability to obtain and maintain a U.S. government clearance preferred but not mandatory.

About RAND
RAND
Research & Policy · 1,001–5,000 employees

RAND Corporation is a nonprofit global policy research organisation headquartered in Santa Monica, California. For more than 75 years, RAND has delivered objective, data-driven research and analysis to help governments, militaries, businesses, and communities worldwide make better decisions on complex challenges spanning defence, health, education, infrastructure, and economic policy.

🧭
Application Guide for This Role
Tailored tips to help you stand out and prepare confidently
🔒 What IT & Cybersecurity Hiring Managers Look For

Security and IT roles demand precision, documentation discipline, and a risk-first mindset. Hiring managers look for candidates who can communicate threats in business terms, not just technical ones — and who stay ahead of threat vectors without needing to be told.

How to Stand Out
  • List certifications prominently (CompTIA Security+, CISSP, CEH, AWS Security Specialty) — they're taken seriously in this field.
  • Describe a real incident you responded to: what was the threat vector, your containment steps, and the post-incident review?
  • Show experience with the tools in the job description: SIEM platforms, EDR solutions, penetration testing tools, or cloud IAM.
  • Demonstrate compliance awareness (SOC 2, ISO 27001, GDPR, HIPAA) if the company operates in a regulated industry.
Likely Interview Questions
  1. Walk me through how you'd respond to a suspected phishing breach affecting 200 employees.
  2. How do you stay current with emerging CVEs and threat intelligence?
  3. Describe how you'd perform a risk assessment for a new SaaS tool the company wants to adopt.
  4. What's the most creative social engineering attack you've seen or simulated?
Pro tip: Set up a home lab using VirtualBox or TryHackMe rooms in the specific domain (cloud, network, web app) this role covers — it gives you concrete, recent examples to discuss.
📄 About Full-Time Employment Roles

Full-time roles typically include benefits (health insurance, pension contributions, paid leave). During salary negotiation, always consider the total compensation package — benefits can be worth 20–30% on top of base salary. Ask specifically about probation period, performance review cadence, and remote/hybrid flexibility before signing.

🏠 Hybrid Work — What to Expect

Hybrid roles blend office and remote days — but the split varies widely. Always clarify the exact office days required and whether they are fixed or flexible. Ask how the team handles meeting scheduling for in-office vs. remote days, and whether the role will evolve toward more or fewer office days over time.

✅ Before You Hit Submit
📝
Tailor your CV
Remove irrelevant roles. Match your language to the job description — ATS systems score keyword alignment.
💌
Write a real cover note
One paragraph that explains why this specific company, this specific role, right now. Generic notes go unread.
🔍
Research the company
Know their product, recent news, funding stage, and competitors. Bring one insight to your interview.
🔗
Clean up your LinkedIn
Make sure your profile matches your CV and your headline reflects the role you want, not the one you are leaving.
Job Overview
Salary Competitive
Type Full-time
Location USA
Category IT & Cybersecurity
Posted May 3, 2026
Apply Now
Free Daily Digest
Stay ahead of the job market

New jobs, scholarships and career tips — delivered to your inbox daily. Unsubscribe any time.