If automated red teaming is arriving, the obvious question is whether human red teamers are being automated away. The honest answer is more interesting than yes or no.
Key takeaways
- At its Fal.Con 2026 keynote on 1 September, CrowdStrike introduced SafeMind, built on two Nvidia Nemotron-based models: Red Tempest for offence and Blue Solano for defence. The system runs.
- 173 live listings in this category publish a rate, at a median top-of-range of $85 an hour and a ceiling of $300.
- The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
- Applications screen on a short skills assessment rather than a resume or interview.
What was reported
The finding
At its Fal.Con 2026 keynote on 1 September, CrowdStrike introduced SafeMind, built on two Nvidia Nemotron-based models: Red Tempest for offence and Blue Solano for defence. The system runs a closed loop against a digital twin of a customer environment, with Red Tempest probing for vulnerabilities and Blue Solano remediating them, repeating until no threats remain. SafeMind integrates with the Falcon platform and is also available through CrowdStrike's Project QuiltWorks programme. CrowdStrike separately announced a $100,000 international AI security challenge.
SafeMind runs Red Tempest against Blue Solano in a closed loop over a digital twin of a customer environment, cycling until no threats remain. That is a real capability and it addresses a real problem, since attacker breakout time has compressed to something close to runtime.
What the listings pay
Two things bound what it replaces. It runs against a digital twin, which means someone has to decide what that twin should contain and whether it resembles reality. And the UK AI Security Institute's own incident report from August showed agents taking 19 unsanctioned actions during an evaluation, ten of them against real targets on the live internet. Automated adversaries are themselves something that needs supervising.
| # | Role | Advertised rate | Platform |
|---|---|---|---|
| 1 | CUDA Engineering Expert | $300 to $300 an hour | Mercor |
| 2 | Cybersecurity Research Expert, Offensive Security & Vulnerability Research | $200 to $250 an hour | Mercor |
| 3 | Machine Learning Engineer Talent Network | $70 to $250 an hour | Mercor |
| 4 | UK-Based Data Engineering Experts | $140 to $200 an hour | Mercor |
| 5 | AI Software Engineering Domain Expert | $100 to $200 an hour | micro1 |
| 6 | AI/ML Engineer | $70 to $200 an hour | micro1 |
| 7 | Medical Safety Expert | $140 to $190 an hour | Mercor |
| 8 | Engineering / Platform Professionals | $80 to $160 an hour | Mercor |
| 9 | Open Source Applied Engineer Talent Network | $100 to $150 an hour | Mercor |
| 10 | Child & Adolescent Mental Health Clinical Advisor (AI Safety Benchmark Project) | $80 to $150 an hour | Mercor |
Source: 173 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

How this compares across the board
A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.
| Category | Listings | Median low | Median top | Highest |
|---|---|---|---|---|
| Legal | 95 | $100 | $140 | $400 |
| Medical | 68 | $77 | $120 | $400 |
| Consulting | 45 | $80 | $120 | $280 |
| Finance | 94 | $80 | $110 | $280 |
| Engineering | 114 | $70 | $100 | $300 |
| Research/PhD | 132 | $70 | $90 | $280 |
| Writing | 36 | $40 | $80 | $280 |
| Bilingual | 78 | $44 | $52 | $120 |
| Annotation | 25 | $12 | $24 | $120 |
Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.
What it means for you
That is roughly where the human work is settling: designing what gets tested and judging whether the result means anything. Across 173 live security and safety listings on our board that publish a rate, the median top-of-range is $85 an hour, reaching $300. See advanced red teaming roles.
Who should apply
Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.
Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.
Frequently asked questions
What is SafeMind?
CrowdStrike's autonomous red teaming system, announced at Fal.Con on 1 September 2026, using Nvidia Nemotron-based models Red Tempest for offence and Blue Solano for defence in a closed loop.
Does it replace human red teamers?
It automates repetitive probing against a digital twin. Deciding what to test, whether the environment is realistic, and what a result means remains human work.
Why does supervision still matter?
The UK AI Security Institute's August 2026 incident report documented agents taking 19 unsanctioned actions during an evaluation, including against real targets. Autonomous adversaries need oversight of their own.
What does security and safety work pay?
Across 173 live security and safety listings publishing a rate, the median top-of-range is $85 an hour, reaching $300.
Is a security certification required?
Usually not for model-focused red teaming. Adversarial thinking transfers directly from penetration testing, and the target is language rather than infrastructure.
Sources
See every live role
The full board updates several times a week, with the advertised rate on each listing and closed roles removed.