Senior Engineer, Offensive Security

🏢 Humana · all Humana jobs
📍 United States
💰 USD 117,600 - 161,700 / annual
📅 Posted 2026-08-15 · via Himalayas
🏷 Offensive-Security,Red-Team,Penetration-Testing,AI-Security,Security-Engineering,Senior-Offensive-Security-Specialist,Offensive-Security-Engineer,Offensive-Security-Lead,Senior-Cybersecurity-Engineer,Senior-Information-Security-Engineer,Senior-Security-Testing-Engineer,Security-Engineer
Apply on original site ↗

Become a part of our caring community

*Selected candidate must reside within approximately 60 minutes driving distance from one of the following locations: ((Louisville KY, NYC Metro, Dallas Metro, Charlotte NC Metro, South Florida(Tampa/Miami/Ft Lauderdale) , Washington DC metro, Chicago, Boston, Atlanta, Nashville))
We're building a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for a senior engineer who can both build it and use it. As Senior Offensive Security Engineer, AI-Driven Red Team & Tooling, you'll build the AI and agentic tooling that makes our offensive operations faster and broader, then prove it where it counts, on real penetration tests, purple-team exercises, and red-team operations. You'll also bring that same offensive lens to the enterprise's own AI systems.
It's one loop: build the tooling, prove it on live engagements, feed what you learn back into the tooling. And it's a rare chance to do that hands-on inside a program that helps protect the health data of millions of people. What you'll do
One integrated mission, four ways it shows up:

Build agentic offensive tooling. Write production-quality software and AI agents, LLM-driven planning loops, multi-agent orchestration, and tool/function-calling that drives real offensive tooling, and contribute to the in-house agent platform that powers our pentest and red-team operations. You'll operate this as a production, event-driven cloud platform at real scale (dozens of serverless functions, change-stream data pipelines, hundreds of operational alarms, integrated LLM inference), real software engineering, not proof-of-concept scripting.

Run penetration tests. Network, web-application, cloud, and infrastructure testing, recon through exploitation, privilege escalation, and lateral movement, accelerated by the tooling you build, with your own judgment owning scope and exploitability.

Run purple-team exercises. Validate security countermeasures (EDR/XDR, NDR, DLP, firewalls) with our defensive partners, then pair with detection engineering to close the gaps your attacks reveal.

Run red-team operations and test the enterprise's own AI. Objective-driven adversary emulation; and adversarial assessment of internal LLM-powered products, agents, RAG pipelines, and ML applications, prompt injection, jailbreaks, model extraction and inversion, membership inference, data and supply-chain poisoning, evasion, and agent tool/sandbox abuse, validating that guardrails and classifiers actually hold.
Your first 6–12 months

-
First 90 days: ramp on the agent platform and the offensive service lines; deliver your first engagements (a penetration test and a purple-team exercise) and ship one improvement to the agentic tooling that you used during them.

-
By 6 months: ship at least one AI-driven tool that a service line adopts into its live workflow, with metrics showing coverage or turnaround gains; run a red-team operation end to end.

-
By 12 months: stand up repeatable adversarial testing for at least one of the enterprise's own AI systems; establish an evaluation approach that tracks your tooling's autonomous success against representative targets; become a go-to for both building and operating across the team.

Why this role, and why here

-
Build and operate (both, for real). Most offensive roles let you build or operate. This one is explicitly both: you ship the software and you run the engagements, so your tooling is shaped by someone who actually uses it.

-
A program that's already serious about AI. Fridays are dedicated to R&D. You'll have Hack The Box Pro Labs, all HTB role-based paths and certifications, discretionary certification funding, and conference/training budgets. You'll work alongside the Lead of our new AI & Offensive Tooling capability—contributing to the platform they own while running your own engagements.

-
Mission that matters. Offensive Security identifies weaknesses so the

← All remote jobs