AI Red Teamer
AI red teamers deliberately try to break AI systems before attackers or embarrassing edge cases do: crafting adversarial prompts to bypass safety filters, testing for data leakage, probing whether a customer-service bot can be tricked into giving unauthorized refunds or discount codes, and documenting exploitable weaknesses for engineering teams to fix. It's penetration testing adapted to the specific, weird failure modes of language models.
As Kenyan banks, telcos, and insurers deploy customer-facing AI assistants handling real money and sensitive data, regulators and internal risk teams increasingly require this kind of adversarial testing before launch — making AI red teaming a natural extension of the country's already-established cybersecurity industry rather than a totally new field.
- AI exposure
- 28 of 100, low exposure
- Hiring trend
- Growing
- Hiring rate
- 48%
- Minimum education
- Bachelor
The role
What the work is, what it pays, and what it costs you.
At a glance
- Remote friendly
- Yes
- Freelance potential
- High
- Freelance rate
- Ksh 6,000
- Time to senior
- 5 years
A day in the role
"I spend my day trying to convince a bank's chatbot to do something it shouldn't — then writing it up so calmly that engineers don't panic, just fix it."
What it pays
Kenyan market, per month- Entry
- KES 120,000–180,000
- Mid
- KES 220,000–350,000
- Senior
- KES 380,000–600,000
The trade offs
In its favour
- Builds directly on Kenya's already-strong cybersecurity talent base and industry.
- High-impact, intellectually engaging work with growing regulatory backing.
Against it
- Still a very small, niche specialisation locally with limited senior mentorship available.
- Requires constantly tracking new attack techniques as models and defenses evolve.
In practice
If you have any penetration-testing background, the fastest entry is running the OWASP LLM Top 10 checklist against a few open-source chatbots and documenting your findings publicly to build a portfolio.
Progression runs cybersecurity analyst/pentester → AI red teamer → AI security lead/consultant, often moving into independent consulting once a strong reputation and case-study portfolio are built.
Banks and telcos already running mature cybersecurity programs are extending them to cover AI systems, making this a natural specialisation for existing security professionals rather than a from-scratch career.
Days alternate between hands-on adversarial testing sessions and writing clear, prioritised vulnerability reports for engineering and compliance teams.
Exposure
How much of this a machine can already do, and how that was worked out.
Where this rating sits
1,516 rated careersRated above 24% of the 1,516 careers in the catalogue, which averages 43. Inside technology the mean is 62, across 125 careers.
What the rating is made of
Share of recorded tasks- Machine does it
- 25%Software can already complete this work end to end.
- Machine assists
- 40%A person still decides, but the drafting is done for them.
- Person does it
- 35%Judgement, relationships and accountability that do not transfer.
Named task by task
Already automated
- Generating candidate adversarial prompt variations
- Drafting vulnerability report summaries
Still human
- Designing novel jailbreak/prompt-injection attack strategies
- Assessing business impact/severity of a discovered vulnerability
- Coordinating responsible disclosure with engineering teams
- Building repeatable adversarial test suites for regression testing
- Presenting risk findings to non-technical stakeholders and regulators
Task counts
- Tasks recorded
- 10
- Automatable now
- 2
- Still human
- 7
- Augmenting
- Attack-prompt generation,Report drafting
- Creating
- AI-specific security tooling,Adversarial test-suite frameworks
Sources
Behind the rating- OWASP LLM Top 10
- WEF Future of Jobs Report 2025
Getting in
The routes into the role and what each one asks for.
What to study
8 courses- Certificate in Fashion Design and Textile TechnologyKsh 37,320a year
- Certificate in Desktop PublisherKsh 50,000a year
- Certificate in Mobile Applications and TechnologyKsh 56,420a year
- Certificate in Data Science and Artificial IntelligenceKsh 57,050a year
- Diploma in Photogrammetry and Remote SensingKsh 66,270a year
- Artisan in ICTKsh 67,189a year
- Certificate in Artificial Intelligence & CybersecurityKsh 67,189a year
- Certificate in Big DataKsh 67,189a year
How people get in
Cybersecurity/penetration testing background + AI specialisation
6-12 monthsLow cost
Fastest route — existing offensive security mindset transfers directly, add LLM-specific attack techniques.
Computer Science degree + AI safety self-study
4 years + 6 monthsMedium cost
Standard degree route through cybersecurity or AI coursework.
Certifications
Offensive Security Certified Professional (OSCP)
OffSecKsh 150,0003 months
Certified AI Security Professional
Various (emerging)Ksh 60,0002 months
Tools of the trade
Garak
AI SecurityRequiredFree
PyRIT
AI SecurityNice to haveFree
Burp Suite
SecurityRequiredPaid
Python
ProgrammingRequiredFree
Who hires
Interview preparation
4 questionsHow would you test whether a banking chatbot can be manipulated into disclosing another customer's account information?
TechnicalSenior
Look for structured testing of prompt injection, context-boundary confusion attacks, and clear escalation of severity/impact.
What's the difference between prompt injection and jailbreaking?
TechnicalMid
Prompt injection manipulates the model via untrusted input data; jailbreaking bypasses the model's own safety training directly through crafted instructions. Candidates should distinguish these clearly.
Describe how you'd responsibly disclose a critical vulnerability you found in a client's production AI system.
SituationalMid
Look for a calm, structured disclosure process: immediate private notification, clear severity/impact framing, and follow-up verification after the fix.
Why can't a single red-team assessment guarantee a model is 'safe' going forward?
BehavioralEntry
Should discuss model updates, new attack technique discovery, and the need for ongoing/continuous testing rather than one-time certification.
Common misconceptions
It's the same as regular penetration testing.
AI red teaming targets model behaviour specifically — prompt injection, jailbreaks, data extraction — which requires different techniques from traditional network/application pentesting, even though the mindset is similar.
Once a model passes red-teaming once, it's safe.
Models get updated and new attack techniques are discovered constantly, so red teaming is an ongoing practice, not a one-time certification.
What happens next
How the role changes from here, and where it leads.
The near term
Emerging as a required compliance step, not just a best practice
- Regulators beginning to require AI risk assessments before deployment in financial services
- Standardised frameworks (OWASP LLM Top 10) maturing into audit checklists
- What to do
- Pair existing or new penetration-testing fundamentals with hands-on practice using LLM-specific attack frameworks like Garak and PyRIT.
Where pay is heading
2024 to 2030Monthly pay in Kenyan shillings, rounded to the nearest thousand. These are projections, not observations.
Growth outlook
- Net demand change
- 30
- Over
- 2025-2028
- Drivers
- Regulatory pressure for AI risk assessment before deployment,High-profile AI security incidents raising awareness
- Headwinds
- Small talent pool, slow to scale hiring
Supply and demand
- Demand
- 60
- Supply pressure
- 25
- Balance
- High demand
What to learn
- Prompt injection techniques
- AI safety evaluation frameworks
- Regulatory/compliance awareness for AI systems
Tools worth knowing
Garak
Priority: Recommended
Automated LLM vulnerability scanning
PyRIT
Priority: Recommended
Microsoft's AI red-teaming toolkit
Where people move next
3 recorded movesLine length under each name is the distance of the move: shorter means more of what you already do carries over. Marked lines are steps up rather than sideways.
- Penetration Tester
Easy70% skill overlapLateral
Direct lateral move given the shared adversarial-testing mindset.
- Ai Safety Researcher
Moderate45% skill overlapPromotion
Shifts from finding vulnerabilities to researching systemic model safety.
- Security Architect
Moderate40% skill overlapPromotion
Moves from testing to designing secure systems from the ground up.
Related careers
Kenyan market notes
Kenya's existing, mature cybersecurity/penetration-testing industry (banks, telcos already run regular pentests) is the natural feeder pool — most current AI red teamers are pentesters who added LLM attack techniques to their toolkit.
Further reading
This role is rated 28 out of 100 today. Save it and the app keeps that number, then tells you by how much it has moved when the record is next reviewed.