Senior Engineer, Offensive Security
Posted 5hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior offensive security engineer building AI-driven red-team tooling for Humana's healthcare and health-data systems. Running penetration tests, purple-team exercises, and adversarial assessments of enterprise AI.
Responsibilities:
- Build production-quality AI agents and offensive security tooling, including LLM-driven planning loops, multi-agent orchestration, and tool/function-calling
- Contribute to the in-house agent platform powering penetration testing and red-team operations
- Operate the tooling as a production, event-driven cloud platform with serverless functions, change-stream pipelines, alarms, and integrated LLM inference
- Run network, web-application, cloud, and infrastructure penetration tests from reconnaissance through exploitation, privilege escalation, and lateral movement
- Run purple-team exercises validating EDR/XDR, NDR, DLP, and firewall countermeasures
- Partner with detection engineering to close gaps identified through offensive testing
- Conduct objective-driven red-team operations and adversarial assessments of internal LLM products, agents, RAG pipelines, and ML applications
- Test prompt injection, jailbreaks, model extraction and inversion, membership inference, poisoning, evasion, and agent tool/sandbox abuse
- Deliver penetration tests and purple-team exercises during the first 90 days and ship improvements to agentic tooling
- Ship AI-driven tools adopted into live workflows, run an end-to-end red-team operation, and establish repeatable adversarial testing and evaluation approaches
- Embed with service lines and the AI & Tooling Lead while influencing technical direction
- Deliver findings and tooling with reproduction steps, severity, business impact, and remediation
- Track risk in the enterprise risk platform and follow acceptable-use-of-AI policies and rules of engagement
Requirements:
- 4+ years of offensive operations experience in red team, penetration testing, purple team/control validation, or bug bounty roles
- Track record delivering engagements end to end, including scoping, execution, and clear written findings
- Production Python engineering experience building and operating real tooling
- Hands-on experience designing, building, or operating AI agents or LLM applications
- Experience with agentic workflows, tool/function-calling, and orchestration
- Hands-on testing of AI/ML systems, including prompt injection, jailbreaking, and adversarial techniques
- Production experience with at least one major cloud service provider: AWS, GCP, or Azure
- Ability to work with considerable autonomy on moderately complex engagements
- Ability to produce reproducible software with evaluation, safety guardrails, and human-in-the-loop controls where required
- Ability to deliver findings with reproduction steps, severity, business impact, and remediation
- Ability to track risk in an enterprise risk platform and follow AI acceptable-use policies and offensive security rules of engagement
- Selected candidate must reside within approximately 60 minutes driving distance of an eligible location
- Home internet must provide at least 25 Mbps download and 10 Mbps upload
- Must work from a dedicated space without ongoing interruptions to protect PHI/HIPAA information
- Preferred: autonomous offensive agents, C2 frameworks, evasion/OPSEC, EDR/XDR, MITRE ATT&CK, VECTR, Atomic Red Team, PyRIT, Garak, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI Risk Management Framework, MCP, RAG pipelines, cloud penetration testing, threat intelligence, advanced offensive specialties, research/open-source/talk experience, and relevant certifications
Benefits:
- Bonus incentive plan
- Fridays dedicated to R&D
- Hack The Box Pro Labs
- All HTB role-based paths and certifications
- Discretionary certification funding
- Conference/training budgets
- Medical benefits
- Dental benefits
- Vision benefits
- 401(k) retirement savings plan
- Paid time off
- Company holidays
- Personal holidays
- Paid parental leave
- Paid caregiver leave
- Short-term disability
- Long-term disability
- Life insurance
- Other whole-person wellness and healthcare benefits















