Skip to content
Nairobi · KenyaFree to read
Technology

AI Red Teamer

AI red teamers deliberately try to break AI systems before attackers or embarrassing edge cases do: crafting adversarial prompts to bypass safety filters, testing for data leakage, probing whether a customer-service bot can be tricked into giving unauthorized refunds or discount codes, and documenting exploitable weaknesses for engineering teams to fix. It's penetration testing adapted to the specific, weird failure modes of language models.

As Kenyan banks, telcos, and insurers deploy customer-facing AI assistants handling real money and sensitive data, regulators and internal risk teams increasingly require this kind of adversarial testing before launch — making AI red teaming a natural extension of the country's already-established cybersecurity industry rather than a totally new field.

AI exposure
28 of 100, low exposure
Hiring trend
Growing
Hiring rate
48%
Minimum education
Bachelor

The role

What the work is, what it pays, and what it costs you.

At a glance

Remote friendly
Yes
Freelance potential
High
Freelance rate
Ksh 6,000
Time to senior
5 years

A day in the role

"I spend my day trying to convince a bank's chatbot to do something it shouldn't — then writing it up so calmly that engineers don't panic, just fix it."

What it pays

Kenyan market, per month
Entry
KES 120,000–180,000
Mid
KES 220,000–350,000
Senior
KES 380,000–600,000

The trade offs

In its favour

  • Builds directly on Kenya's already-strong cybersecurity talent base and industry.
  • High-impact, intellectually engaging work with growing regulatory backing.

Against it

  • Still a very small, niche specialisation locally with limited senior mentorship available.
  • Requires constantly tracking new attack techniques as models and defenses evolve.

In practice

If you have any penetration-testing background, the fastest entry is running the OWASP LLM Top 10 checklist against a few open-source chatbots and documenting your findings publicly to build a portfolio.

Progression runs cybersecurity analyst/pentester → AI red teamer → AI security lead/consultant, often moving into independent consulting once a strong reputation and case-study portfolio are built.

Banks and telcos already running mature cybersecurity programs are extending them to cover AI systems, making this a natural specialisation for existing security professionals rather than a from-scratch career.

Days alternate between hands-on adversarial testing sessions and writing clear, prioritised vulnerability reports for engineering and compliance teams.

Exposure

How much of this a machine can already do, and how that was worked out.

Where this rating sits

1,516 rated careers
28
lowmoderatehigh
020406080100

Rated above 24% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.

What the rating is made of

Share of recorded tasks
Machine does it
25%Software can already complete this work end to end.
Machine assists
40%A person still decides, but the drafting is done for them.
Person does it
35%Judgement, relationships and accountability that do not transfer.

Named task by task

Already automated

  • Generating candidate adversarial prompt variations
  • Drafting vulnerability report summaries

Still human

  • Designing novel jailbreak/prompt-injection attack strategies
  • Assessing business impact/severity of a discovered vulnerability
  • Coordinating responsible disclosure with engineering teams
  • Building repeatable adversarial test suites for regression testing
  • Presenting risk findings to non-technical stakeholders and regulators

Task counts

Tasks recorded
10
Automatable now
2
Still human
7
Augmenting
Attack-prompt generation,Report drafting
Creating
AI-specific security tooling,Adversarial test-suite frameworks

Sources

Behind the rating
  • OWASP LLM Top 10
  • WEF Future of Jobs Report 2025

Getting in

The routes into the role and what each one asks for.

What to study

8 courses

How people get in

  • Cybersecurity/penetration testing background + AI specialisation

    6-12 monthsLow cost

    Fastest route — existing offensive security mindset transfers directly, add LLM-specific attack techniques.

  • Computer Science degree + AI safety self-study

    4 years + 6 monthsMedium cost

    Standard degree route through cybersecurity or AI coursework.

Certifications

  • Offensive Security Certified Professional (OSCP)

    OffSecKsh 150,0003 months

  • Certified AI Security Professional

    Various (emerging)Ksh 60,0002 months

Tools of the trade

  • Garak

    AI SecurityRequiredFree

  • PyRIT

    AI SecurityNice to haveFree

  • Burp Suite

    SecurityRequiredPaid

  • Python

    ProgrammingRequiredFree

Who hires

Interview preparation

4 questions
  • How would you test whether a banking chatbot can be manipulated into disclosing another customer's account information?

    TechnicalSenior

    Look for structured testing of prompt injection, context-boundary confusion attacks, and clear escalation of severity/impact.

  • What's the difference between prompt injection and jailbreaking?

    TechnicalMid

    Prompt injection manipulates the model via untrusted input data; jailbreaking bypasses the model's own safety training directly through crafted instructions. Candidates should distinguish these clearly.

  • Describe how you'd responsibly disclose a critical vulnerability you found in a client's production AI system.

    SituationalMid

    Look for a calm, structured disclosure process: immediate private notification, clear severity/impact framing, and follow-up verification after the fix.

  • Why can't a single red-team assessment guarantee a model is 'safe' going forward?

    BehavioralEntry

    Should discuss model updates, new attack technique discovery, and the need for ongoing/continuous testing rather than one-time certification.

Common misconceptions

  • It's the same as regular penetration testing.

    AI red teaming targets model behaviour specifically — prompt injection, jailbreaks, data extraction — which requires different techniques from traditional network/application pentesting, even though the mindset is similar.

  • Once a model passes red-teaming once, it's safe.

    Models get updated and new attack techniques are discovered constantly, so red teaming is an ongoing practice, not a one-time certification.

What happens next

How the role changes from here, and where it leads.

The near term

Emerging as a required compliance step, not just a best practice

  • Regulators beginning to require AI risk assessments before deployment in financial services
  • Standardised frameworks (OWASP LLM Top 10) maturing into audit checklists
What to do
Pair existing or new penetration-testing fundamentals with hands-on practice using LLM-specific attack frameworks like Garak and PyRIT.

Where pay is heading

2024 to 2030
20242030
Entry110kMid210kSenior360k
+73%190k+76%370k+78%640k

Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.

Growth outlook

Net demand change
30
Over
2025-2028
Drivers
Regulatory pressure for AI risk assessment before deployment,High-profile AI security incidents raising awareness
Headwinds
Small talent pool, slow to scale hiring

Supply and demand

Demand
60
Supply pressure
25
Balance
High demand

What to learn

  • Prompt injection techniques
  • AI safety evaluation frameworks
  • Regulatory/compliance awareness for AI systems

Tools worth knowing

  • Garak

    Priority: Recommended

    Automated LLM vulnerability scanning

  • PyRIT

    Priority: Recommended

    Microsoft's AI red-teaming toolkit

Where people move next

3 recorded moves

Line length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.

  • Penetration Tester

    Easy70% skill overlapLateral

    Direct lateral move given the shared adversarial-testing mindset.

  • Ai Safety Researcher

    Moderate45% skill overlapPromotion

    Shifts from finding vulnerabilities to researching systemic model safety.

  • Security Architect

    Moderate40% skill overlapPromotion

    Moves from testing to designing secure systems from the ground up.

Related careers

Kenyan market notes

Kenya's existing, mature cybersecurity/penetration-testing industry (banks, telcos already run regular pentests) is the natural feeder pool — most current AI red teamers are pentesters who added LLM attack techniques to their toolkit.

Further reading

Keep this

This role is rated 28 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.