Red teaming stopped being an annual audit and became a standing job, and there is a specific technical reason why.

Key takeaways

  • A 2026 replication found that single-turn, translation-based jailbreaks had been largely closed, but multi-turn conversational jailbreaks in low-resource languages remained highly.
  • 72 live listings in this category publish a rate, at a median top-of-range of $52 an hour and a ceiling of $190.
  • The work is remote contract work, asynchronous, with no set hours and no guaranteed volume.
  • Applications screen on a short skills assessment rather than a resume or interview.

What was reported

The finding

A 2026 replication found that single-turn, translation-based jailbreaks had been largely closed, but multi-turn conversational jailbreaks in low-resource languages remained highly effective, with harmful-response rates ranging from roughly 42% to 71%. Research also documents a safety-by-failure pattern where harmful instructions are missed rather than refused.

The obvious attacks got fixed. Single-turn translated jailbreaks have largely been closed. What replaced them is harder to automate away: multi-turn conversations that walk a model somewhere it would refuse to go in one step. Reported success rates for those in low-resource languages still run between 42% and 71%.

What the listings pay

You cannot patch that with a filter, because no individual message in the conversation looks like an attack. You need people who think adversarially, in volume, continuously.

Source: 72 live listings on this board that publish a rate, read directly from each posting on 2026-09-06. Listings without a published rate are excluded rather than estimated.

Single-Turn Jailbreaks Got Patched. Multi-Turn Ones Still Work

How this compares across the board

A rate only means something next to the alternatives. This is every category we track with at least five listings publishing a rate, ranked by median top-of-range, so you can see where this work sits rather than taking a single number on trust.

CategoryListingsMedian lowMedian topHighest
Legal95$100$140$400
Medical68$77$120$400
Consulting45$80$120$280
Finance94$80$110$280
Engineering114$70$100$300
Research/PhD132$70$90$280
Writing36$40$80$280
Bilingual78$44$52$120
Annotation25$12$24$120

Same source and date as above. Categories are matched on listing title, so a role can appear in more than one.

What it means for you

Across 72 live safety and red teaming listings that publish a rate, the median top-of-range is $52 an hour, reaching $190. If you have penetration testing instincts, the mindset transfers directly. The target is language rather than infrastructure.

Who should apply

Two checks before you spend time on an application. Confirm the role accepts applicants from your country with the eligibility checker, since a meaningful share of listings carry location requirements. Then run the advertised rate through the take-home calculator, because this is contract work and the headline figure is before self-employment tax.

Applications complete on the hiring platform and usually take a few minutes, with a short skills assessment in place of an interview. Fill in every credential, language and professional background field on your profile. Those are what route you to the better paid listings, and most applicants leave them blank.

Frequently asked questions

Is AI red teaming the same as penetration testing?

The mindset transfers directly but the target differs. You probe model behaviour rather than systems, so the techniques are linguistic rather than technical.

What does it pay?

Across 72 live safety listings with published rates, the median top-of-range is $52 an hour, reaching $190.

Do I need security certifications?

Usually not. Demonstrated adversarial thinking matters more, and many listings are open to people without formal security credentials.

Is the work uncomfortable?

It can be. You spend time deliberately eliciting harmful output so it can be fixed. Most people doing it think finding failures before deployment is worthwhile, but it is not for everyone.

Why are bilingual red teamers in demand?

Because safety behaviour does not transfer reliably across languages, and multi-turn attacks in under-resourced languages remain effective.

Sources

  1. arXiv, Adversarial Robustness and Safety Alignment in Multilingual Multi-Modal LLMs
  2. arXiv, Multilingual Refusal Alignment for Safer Large Language Models

See every live role

The full board updates several times a week, with the advertised rate on each listing and closed roles removed.

Browse all AI jobs