Sofia Almeida
AI Red Teamer & Security Engineer
Lisbon, Portugal
Summary
Security engineer turned AI red teamer. 8 years in offensive security, 3 breaking language models — prompt injection, jailbreaks, tool-use abuse and agent exfiltration. Found the indirect injection chain that changed how a client handles retrieved content, and built the adversarial suite run on every release.
Experience
Lead AI Red Teamer · Arclight Security
Feb 2024 – Present
- Lead adversarial testing of LLM products for financial and healthcare clients, covering injection, jailbreaks, tool abuse and data extraction.
- Discovered an indirect prompt-injection chain enabling exfiltration via an agent’s tool calls; drove the client’s redesign of untrusted-content handling.
- Built an automated adversarial suite of 300+ attack patterns, run on every model release.
- Write client-facing reports and brief engineering teams on fixes — most findings need a design change, not a filter.
Senior Penetration Tester · Arclight Security
May 2020 – Jan 2024
- Led web, API and cloud penetration tests for regulated clients and ran internal training on emerging attack surfaces.
- Built the tooling that became the basis for the AI red-team practice.
Education
MSc Information Security
Instituto Superior Técnico · 2015 – 2017
BSc Computer Engineering
University of Porto · 2012 – 2015
Certifications
- OSCP — Offensive Security Certified Professional
- CISSP
Skills
AI Security: Prompt Injection · Jailbreaks · Agent Security · Tool-Use Abuse · Data Exfiltration
Offensive Security: Penetration Testing · Threat Modelling · OWASP LLM Top 10 · API Security
Frameworks: MITRE ATLAS · NIST AI RMF · Responsible Disclosure