Lead, Offensive Security
Humana · New York, NY · 1 mo ago
RemoteRemoteManagement$142k–$196k/yrFull-time
About the role
We're standing up a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for its founding engineer. The Bigger Picture includes access to Hack The Box Pro Labs, all HTB role-based training paths and certifications, discretionary certification funding, and conference/training budgets. Fridays are dedicated to research and development, enabling the team to pursue training in emerging offensive security methodologies, tools, agents, large language models (LLMs), artificial intelligence, and other bleeding edge topics.
Responsibilities
- Own the in-house AI agent platform that powers our penetration testing and red team operations.
- Build the AI-driven tooling that makes every offensive service line faster, broader, and more autonomous.
- Set the technical direction for offensive AI at the company.
- Ship the software that proves it.
- Operate this as a production, event-driven cloud platform at real scale, dozens of serverless functions, change-stream data pipelines, hundreds of operational alarms, and integrated LLM inference.
Requirements
- 6+ years in roles such as Red Team or Penetration Testing, including team- or program-level leadership.
- Strong track record of building and operating production-quality software and tooling.
- Hands-on designing, building, or operating AI agents or LLM applications.
- Hands-on testing of AI/ML systems.
- Production experience with at least one major Cloud Service Provider (AWS, GCP, or Azure).
Qualifications
- Offensive security depth: 6+ years in roles such as Red Team or Penetration Testing, including team- or program-level leadership, and the instinct to think like an attacker against systems that don't behave deterministically.
- Production Python engineering: a strong track record of building and operating production-quality software and tooling, not only scripts.
- Hands-on with AI red-teaming frameworks such as PyRIT or Garak, and fluent in MITRE ATLAS, the OWASP Top 10 for LLM Applications, and the NIST AI Risk Management Framework.
- Model Context Protocol (MCP): building clients/servers, or testing them and RAG pipelines for tool/prompt-injection abuse.
- Demonstrated ability to test endpoints protected by modern EDR/XDR.
- Experience across multiple cloud providers.
- Threat-intelligence-driven operations.
- Depth in an advanced offensive specialty: malware development, advanced Red Team operations and threat simulation, or adversarial ML research.
- Experience building and breaking LLMs, ML models, and AI infrastructure.
- Published research, open-source contributions, or talks at DEF CON, BSides, x33fcon, or Black Hat.
- Expert-level certifications (e.g. OSEE, OSED, OSCE3, CRTL, CWEE, CAPE).
Skills
- Autonomous or semi-autonomous offensive agents.
- LLM-driven penetration-testing agents.
- Reinforcement-learning exploit and attack-path planners.
Benefits
- Medical, dental, and vision benefits.
- 401(k) retirement savings plan.
- Time off (including paid time off, company and personal holidays, paid parental and caregiver leave).
- Short-term and long-term disability.
- Life insurance.
- Many other opportunities.
Pay
- $142,300 - $195,700 per year.
Schedule
- Remote/WAH Requirements: Must have the ability to provide a high speed DSL or cable modem for a home office.
- Work from a dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information.