Principal Security Engineer

🏢 HealthEquity · all HealthEquity jobs (33)
📍 United States
💰 USD 133,000 - 173,000 / annual
📅 Posted 2026-09-07 · via Himalayas
🏷 Security-Engineering,AI-Security,Offensive-Security,Application-Security,Cloud-Security,Principal-Security-Engineer,Senior-Principal-Security-Engineer,Principal-Information-Security-Engineer,Principal-Cybersecurity-Engineer,Principal-Security-Software-Engineer,Principal-Network-Security-Engineer,Cloud-Security-Engineer,Principal-Security-Architect
Apply on original site ↗

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS.  Come be part of remarkable.
Overview
How you can make a difference

As a Principal Security Engineer, AI Offensive Security, you build and operate agentic systems that discover, validate, and help remediate vulnerabilities across HealthEquity . You combine strong software engineering skills with offensive security expertise to automate security testing and vulnerability workflows across web applications and modern cloud environments.

You are an experienced builder who translates offensive security techniques into scalable automation. Working within established architectural patterns and security standards, you develop and enhance agentic capabilities that improve the speed, consistency, and coverage of vulnerability discovery and remediation.

The systems you build help move validated findings from identification through remediation while reducing manual effort and increasing the effectiveness of the security program.
What you'll be doing

- Build and maintain offensive security agents that automate reconnaissance, enumeration, vulnerability validation, and other security testing activities across web and cloud environments.

- Develop agentic workflows that support attack surface management and vulnerability management programs.

- Implement automation that combines deterministic components (APIs, infrastructure-as-code, data pipelines) with non-deterministic, LLM-driven steps, choosing the right approach for each.

- Build integrations between security tooling, ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.

- Apply established architectural patterns, governance requirements, and human-in-the-loop controls when developing AI-enabled security capabilities.

- Validate findings generated by automated systems, reproduce vulnerabilities, and assist with risk assessment and prioritization.

- Develop monitoring, testing, and evaluation capabilities that improve the reliability and effectiveness of agentic systems.

- Support penetration testing and purple-team activities focused on validating vulnerabilities, controls, and remediation efforts.

- Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to improve detection and response capabilities.

- Raise technical concerns, recommend improvements, and contribute to the evolution of team tools, practices, and automation capabilities.

What you will need to be successful

This role requires hands-on experience building and operating AI-enabled automation combined with practical offensive security expertise in modern web application and cloud environments.
Engineering & AI Expertise

- Experience building and operating production software, automation platforms, or security tooling.

- Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.

- Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and evaluation approaches.

- Ability to document technical processes and automate repetitive workflows through software and AI-enabled solutions.

- Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.

- Experience using AI-assisted development tools and LLM technologies to accelerate engineering and automation outcomes.

- Understanding of the strengths, limitations, and operational considerations associated with production AI systems.

Offensive Security Expertise

- Hands-on experience testing modern web applications, APIs, and cloud environments.

- Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, and exploit validation techniques.

- Experience assessing cloud environments including identity, access management, configuration risks, and common cloud attack paths.

← All remote jobs

Get remote developer jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you