How to apply for Research Lead, AI Cyber Testing

RAND Corporation

About RAND Corporation

RAND Corporation is a nonpartisan think tank that has shaped national security policy since the Cold War, with a reputation for rigorous, objective research that directly informs White House, Pentagon, and intelligence community decisions. Working here means your analysis can influence real-world AI governance and cyber defense strategies at the highest levels of government.

About the role

As Research Lead for AI Cyber Testing, you will direct RAND's agenda on evaluating the offensive cyber capabilities of frontier AI models, from initial access to exfiltration. You'll manage budgets, lead multidisciplinary teams, and translate technical benchmarks into actionable policy recommendations for agencies like the NSA, CISA, and the White House. This role sits at the nexus of AI safety and national security, making your work critical to shaping how governments respond to emerging AI threats.

A typical day

Your day might start with a team stand-up to review progress on a benchmark for AI-driven phishing campaigns, followed by a budget meeting with RAND's finance office to reallocate funds for a new red-teaming initiative. In the afternoon, you'll brief a senior official from the Department of Homeland Security on preliminary findings, then draft a policy brief summarizing recommendations for the White House's AI Safety Institute. You'll end the day mentoring a junior researcher on how to structure a technical report for a non-expert audience.

Who RAND Corporation is looking for

  • **Proven research leadership:** Experience leading large-scale, multimillion-dollar research projects with responsibility for budgets, personnel, and cross-functional teams—ideally in a think tank, government lab, or defense contractor.
  • **Deep technical dual expertise:** Hands-on knowledge of AI/ML (e.g., LLM red-teaming, adversarial machine learning) and cybersecurity (e.g., penetration testing, malware analysis, cyber kill chain), with a track record of publishing or operationalizing benchmarks.
  • **Policy fluency:** Demonstrated ability to engage with senior government officials and industry executives, translating complex technical findings into clear policy briefs and recommendations that have influenced decision-making.
  • **Multidisciplinary team builder:** Skilled at assembling and managing teams of AI researchers, cybersecurity experts, and policy analysts, fostering collaboration across disparate fields and delivering results under tight deadlines.

Tips for this application

  • **Tailor your resume to RAND's dual mission:** Highlight projects where you bridged technical AI/cyber work with policy impact—e.g., a benchmark you developed that was used by a government agency, or a paper that informed legislation. Quantify budget and team sizes you managed.
  • **Leverage RAND's publication culture:** Include links to your peer-reviewed papers, technical reports, or policy briefs in your application. RAND values evidence of rigorous, objective analysis that reaches non-technical audiences.
  • **Name-drop relevant agencies and frameworks:** In your cover letter, explicitly mention experience with organizations like CYBERCOM, NSA, CISA, or NIST, and frameworks like MITRE ATT&CK or the AI Risk Management Framework. This shows you understand the landscape RAND operates in.
  • **Show you can lead multidisciplinary teams:** Provide concrete examples of managing teams that included both technical and policy staff, and how you handled conflicting priorities or communication gaps. RAND's projects often span multiple divisions.
  • **Address the remote aspect:** Since the role is remote (US), emphasize your ability to lead distributed teams and collaborate effectively across time zones, perhaps citing previous remote leadership experience or tools you use to maintain team cohesion.

What to cover in your cover letter

["**Your vision for AI cyber evaluation:** Articulate a clear, forward-looking approach to assessing offensive AI capabilities across the attack lifecycle, including specific metrics or methodologies you would champion. Show you've thought about gaps in current benchmarks.", '**Policy impact story:** Describe a specific instance where your research or leadership directly influenced a policy decision, ideally involving government or industry. Detail the problem, your approach, and the outcome.', "**Multidisciplinary leadership:** Highlight how you've successfully managed teams with diverse expertise (e.g., AI scientists, cybersecurity analysts, policy experts) and how you fostered collaboration to deliver a complex project on time and within budget.", "**Alignment with RAND's values:** Explain why RAND's nonpartisan, objective approach appeals to you and how you would uphold its standards of rigor and independence in a politically sensitive domain like AI cyber testing."]

Draft a cover letter

Research before applying

  • **RAND's recent AI and cyber publications:** Read reports like 'The Malicious Use of Artificial Intelligence' and any recent work from RAND's Cyber and Intelligence Policy Center to understand their current thinking and gaps you could fill.
  • **RAND's clients and sponsors:** Identify key government agencies that fund RAND's cyber work (e.g., Department of Defense, Department of Homeland Security, Office of the Director of National Intelligence) and their current AI security priorities.
  • **Key RAND personnel:** Look up researchers in RAND's Cyber and Intelligence Policy Center and Technology and Security Policy Center. Understanding their expertise will help you tailor your application and interview conversations.
  • **RAND's research methodology and culture:** Familiarize yourself with RAND's emphasis on objective analysis, peer review, and policy relevance. Read their 'Standards for High-Quality Research and Analysis' to align your application with their expectations.
RAND Corporation website

Likely interview topics

Based on the job description, expect questions about:

  • **Technical depth:** How would you design a benchmark to evaluate an LLM's ability to conduct a multi-step cyber attack, from reconnaissance to exfiltration? What metrics would you use, and how would you ensure validity and reliability?
  • **Leadership and management:** Describe a time you had to manage a research budget that was cut mid-project. How did you prioritize resources and communicate with stakeholders?
  • **Policy translation:** Give an example of how you communicated a complex technical finding to a non-technical government audience. What was the outcome, and how did you ensure accuracy without oversimplifying?
  • **Ethical and security considerations:** How would you handle the dual-use dilemma of publishing research on AI offensive capabilities that could be misused by malicious actors? What safeguards would you put in place?
  • **Collaboration across RAND:** RAND has multiple divisions (e.g., National Security Research Division, Homeland Security Research Division). How would you coordinate with other researchers to ensure your AI cyber testing agenda leverages and informs their work?
Practise interview questions

Common mistakes to avoid

  • **Overemphasizing technical skills without policy impact:** RAND is not a pure tech company; they need researchers who can translate technical work into policy recommendations. Avoid focusing solely on your coding or hacking prowess without showing how it informs decision-making.
  • **Ignoring the management aspect:** This is a lead role, not an individual contributor. If you don't highlight budget and personnel management experience, you'll appear unprepared for the leadership responsibilities.
  • **Being vague about AI and cyber expertise:** RAND expects deep, specific knowledge. Avoid generic statements like 'I know AI and cybersecurity.' Instead, cite specific models, attack techniques, or frameworks you've worked with.

Deadline

No deadline is listed. Roles without a deadline usually close once the employer has enough candidates, so apply soon if you are interested.