Confidential mandate
AI Red-Team Governance Adviser — Consumer Decision Systems
Planned Hiring / New
AI Red-Team Governance Adviser mandate in Paris, France · Consumer AI Platforms
A Paris consumer-platform board seeks independent counsel to govern adversarial AI testing, translate model failures into release decisions and establish credible executive challenge over nine months.
The mandate
The board cannot tell whether red-team findings represent realistic product harm, speculative model weakness or test artefacts. Teams report attack success rates without connecting prompts, tool access, user populations and mitigations to a release decision. The unresolved question is what evidence should stop, narrow or monitor a launch when a behaviour is reproducible only under privileged access or sustained adaptive attack.
The adviser reserves four days monthly, works remotely and attends quarterly Paris meetings plus two London reviews. A monthly private session with the committee chair is included to examine disputed findings before management papers are finalised. Significant launch questions receive an initial view within forty-eight hours and a written challenge within four working days, including confidence, missing evidence and a recommended decision route.
The nine-month appointment may renew once for three months after an independent committee review of influence, independence and management adoption. Renewal must name the standing question that still requires external judgment. Product delay, an expanding test backlog or a desire for continuing vulnerability review is not a renewal basis.
The adviser has no line authority, model access entitlement or release veto. Management owns testing and launch; the committee owns risk appetite, while advice shapes evidence and escalation. The adviser cannot direct researchers, approve mitigations, retain exploit details outside the agreed repository or speak publicly about model behaviour.
Conflicts include competing AI platforms, red-team vendors, model providers and safety evaluators. Relevant clients, investments and benchmark access must be disclosed before appointment and on change. Paid access to unpublished evaluations, safety institutes or researchers also requires disclosure because it may constrain impartial use of findings.
Why the board wants this voice
Engineering, product and safety leaders interpret the same findings through different incentives. Directors lack repeated experience converting adversarial evidence into bounded operating decisions. Independent counsel can challenge both theatrical testing and premature reassurance.
What you will own
- Challenge threat models for user intent, tool permissions, data sensitivity, persistence and plausible attacker resources across actual product tiers.
- Test whether evaluation sets cover multilingual, multimodal, persistent and adaptive abuse rather than prompt tricks.
- Press teams to distinguish exploitability, reproducibility, reach, harm severity and mitigation durability.
- Shape release thresholds and compensating controls for unresolved high-impact model behaviours.
- Review independence, access and evidence retention for internal and external red teams.
- Examine post-mitigation retests for benchmark leakage, overfitting and shifted attack surfaces.
- Equip the board with trend, recurrence, mitigation-decay and residual-risk views tied to named product and launch decisions.
Candidate qualifications
- Governed adversarial testing for deployed foundation-model or high-impact AI products with direct release or risk-committee exposure.
- Can evidence a release decision materially changed by a reproducible red-team finding.
- Designed tests spanning model, retrieval, agents, tools, identity and human escalation.
- Distinguished benchmark performance from real-world abuse exposure before executives by examining access, reproducibility, scale and plausible harm.
- Advised boards without selling the testing or model technology under review, preserving independence during contested release decisions.
- Maintained confidential vulnerability handling across researchers, vendors and product teams.
Non-negotiables
- Can meet remote cadence and every Paris and London session.
- Will disclose AI platform, laboratory, evaluator and vendor conflicts.
- Accepts no executive authority or undisclosed access to production models.
- Has board-level AI assurance judgment beyond research publication.
- 49 words maximum. Which current relationship could conflict with this AI assurance mandate?
- 49 words maximum. Describe a red-team result that changed a production release decision.
- 49 words maximum. What evidence distinguishes a realistic exploit from an impressive demonstration?
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.