How to apply for Cybersecurity Engineer

10a Labs

About 10a Labs

10a Labs provides adversarial red teaming, model evaluations, and intelligence collection to companies deploying AI systems. Its clients include frontier AI labs, AI unicorns, Fortune 10 companies, and global technology platforms. The company sits at the intersection of AI safety and security, so engineers here work on problems that are new and not well documented elsewhere.

About the role

This cybersecurity engineer builds secure, reproducible infrastructure and tooling for AI security evaluations. The work spans cloud infrastructure, security automation, internal tooling, and controlled offensive security testing. The goal is to identify and measure emerging AI-enabled cyber risks for clients who deploy AI systems.

A typical day

A typical day may involve writing Terraform to stand up or modify a security test environment, building automation for an attack simulation, and meeting with red teamers to reproduce a vulnerability. You might also investigate a finding, write up remediation steps, or improve internal tooling for AI security evaluations. The exact routine is not stated in the job details, so ask about team structure and daily workflows during interviews.

Who 10a Labs is looking for

  • Has hands-on experience building and maintaining cloud infrastructure with Terraform or similar infrastructure-as-code tools.
  • Can write automation and tooling that supports scalable adversarial testing of AI systems and applications.
  • Is comfortable with controlled offensive security testing, including developing and automating attack simulations.
  • Can collaborate with red teamers and engineers to reproduce, investigate, and remediate vulnerabilities found during AI security assessments.

Tips for this application

  • Show concrete examples of reproducible cloud environments you built with Terraform, including what security controls you tested in them.
  • Describe any automation you wrote for attack simulations or security control validation, and name the tools and languages used.
  • Mention any work with AI systems, model evaluations, or adversarial testing, even if it was internal or research-focused.
  • Explain how you have collaborated with red teams or security researchers to reproduce and fix vulnerabilities.
  • Since this is a remote role, state clearly how you have worked effectively with distributed engineering and security teams.

What to cover in your cover letter

Describe a specific security test environment you built from scratch with Terraform and what it was used to validate. Explain how you automated an attack simulation or security control check. Give an example of reproducing and remediating a vulnerability with a red team or engineering team. State why you want to work on AI security evaluations specifically, not security in general.

Draft a cover letter

Research before applying

  • Read the 10a Labs website, especially any public material on adversarial red teaming, model evaluations, and intelligence collection.
  • Look up public examples of AI red teaming and model evaluation work to understand the methods and terminology.
  • Check whether 10a Labs has published research, blog posts, or talks, and note the specific threats they focus on.
  • Find out who their clients are (frontier AI labs, AI unicorns, Fortune 10 companies) and what security problems those clients typically face.
10a Labs website

Likely interview topics

Based on the job description, expect questions about:

  • How you design and maintain reproducible cloud test environments using Terraform.
  • How you automate attack simulations and validate security controls.
  • Your approach to reproducing and investigating a vulnerability found during an assessment.
  • How you would build tooling for scalable adversarial testing of AI systems.
  • How you handle the differences between testing traditional software and testing AI systems.
Practise interview questions

Common mistakes to avoid

  • Applying with only general security experience and no evidence of cloud infrastructure or Terraform work.
  • Describing offensive security testing without showing how you kept it controlled, documented, and reproducible.
  • Claiming AI security expertise without concrete examples of testing, evaluating, or attacking AI systems.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.