28 Sep
|
Ayurak AI
|
India
Red Team Analyst (AI-Augmented Investigation & Social Engineering)
Company: Ayurak Department: Corporate Resilience / Offensive Operations
Role Summary - As a Red Team Analyst, you are a tactical specialist responsible for identifying and exploiting non-technical vulnerabilities within Ayurak’s corporate infrastructure, anticipating the tactics of modern, AI-empowered adversaries. Your primary objective is to investigate high-value targets (personnel and data flows) and execute controlled social engineering campaigns leveraging next-generation tools—such as generative text, voice cloning, and synthetic media. You will verify that our proprietary medical device data, internal AI models, and NIH-related protocols cannot be compromised by human error, algorithmic manipulation, or deceptive practices.
Key Responsibilities
1. AI-Driven Investigation & Reconnaissance
- Algorithmic OSINT: Utilize Large Language Models (LLMs) and automated data-scraping pipelines to process massive, unstructured public datasets, building comprehensive psychological and qualified profiles of staff with access to "The Synapse."
- Metadata & Log Exploitation: Analyze system outputs (like the index-DO0uon Im.js logs) to find patterns in user behavior, alert fatigue, or recurring API errors that can be weaponized as a highly credible "hook" for an AI-generated social engineering pretext.
- Target Profiling: Build dynamic dossiers on internal departments, analyzing their standard operating procedures for "Medical Devices" and "Procedures" to ensure your automated or live impersonations bypass both human scrutiny and biometric/behavioral security filters.
2. Next-Gen Social Engineering Execution (The "Sabotage")
- Synthetic Pretexting: Execute hyper-personalized Spear-Phishing,
"Deep-Vishing" (AI voice cloning), and Smishing campaigns to manipulate staff into bypassing security prompts during simulated "Web Socket connection drops."
- Adversarial AI Infiltration: Deploy dynamically generated, sabotaged internal documents—such as a heavily hallucinated but highly credible "NIH Compliance Update"—to track credential harvesting and test resilience against LLM-crafted lures.
- Physical/Digital Blending: Exploit systemic "distractions," such as triggering a 422 Unprocessable Entity error on the booking platform, while simultaneously deploying a synthetic video or audio persona to bypass secure digital sessions or physical access controls.
3. Data Analysis & Vulnerability Mapping
- Kill-Chain Documentation: Map out the exact steps taken to achieve a "successful sabotage," detailing the interplay between AI tools (e.g., automated reconnaissance) and human vulnerabilities.
- Human-Machine Failure Analysis: Report on which "Human API" elements failed, alongside evaluations of where internal AI defenses (like automated spam filters or sentiment-analysis threat detectors) were successfully bypassed.
Technical Stack & Competencies
Skill Set - Tools & Tactics
- Investigation: Automated OSINT frameworks, custom LLM scripting for data synthesis, Maltego, Spider Foot, and advanced Google Dorks for NIH/Medical registries.
- Deception & Synthetic Media: AI Voice Cloning (e.g., Eleven Labs), Deepfake generation, Generative AI for payload and script crafting (fraud-GPT concepts), Social-Engineer Toolkit (SET), and GoPhish.
- Analysis: Proficiency in reading browser console logs, understanding API response codes (4xx/5xx), and executing basic Prompt Injection to test internal chatbots.
- Communication: Elite-level psychological manipulation techniques (NLP, elicitation) adapted for both human-to-human interaction and human-to-machine prompt crafting.
Candidate Profile: "The Next-Gen Shadow Analyst"
- Hyper-Detail Oriented: You notice that a 422 error happens specifically at line 187 of the JS file and use that exact detail to sound like a "Support Tech," employing an AI-cloned voice of a real IT manager to call a target.
- Technologically Adaptable: You seamlessly switch between traditional manual elicitation and deploying automated, AI-driven phishing agents, matching your persona to the exact cognitive biases of your target.
- Methodical: You follow a strict investigative framework to ensure all advanced "sabotage," especially involving synthetic media and AI, remains controlled, highly ethical, and meticulously documented for the defense and ML engineering teams.
Why this role is critical at Ayurak Firewalls can be patched and anomaly-detection models can be retrained, but human nature remains the ultimate zero-day vulnerability. In an era where adversaries use AI to scale and perfect their deception, you simulate the apex of these threats—finding the "bugs" in our people and processes before a real adversary turns them into a catastrophic breach.
📌 Cyber Threat Investigator (India)
🏢 Ayurak AI
📍 India