Lead, Offensive Security
Humana · United States · 1 mo ago
RemoteRemoteManagement$142k–$196k/yrFull-time
About the role
We're hiring a technical leader of our red team, a hands-on Lead who runs our hardest adversary-emulation campaigns, sets how the team operates, owns the rules of engagement, and moves us into AI-augmented red teaming.
Responsibilities
- Set and govern the team's adversary-emulation methodology, C2 tradecraft standards, and evidence-quality bar; standardize how objective-based operations are scoped, executed, and reported.
- Lead the most complex red-team campaigns, external/internal network, social engineering, assumed-breach, and full-scope objective operations, with full autonomy, and mentor Senior red teamers on tradecraft without being their manager.
- Own rules of engagement: define authorization, scope, deconfliction, and safe-conduct standards for every operation, in partnership with the Associate Director and stakeholders.
- Operate and mature agentic AI red-team tooling: apply it to improve campaign planning, adversary research, and reporting quality; evaluate AI-assisted output for accuracy and operational fit; and feed practitioner requirements back to the Offensive AI Engineering team who build the platform.
- Test AI systems as targets: lead adversarial assessments of production AI-enabled systems, prompt injection (direct/indirect), agent/tool abuse, RAG/training-data poisoning, sensitive-data exposure, and guardrail/control bypass, including abusing an internal AI agent as a step toward a mission objective within a broader adversary-emulation campaign, mapped to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
- Run purple-team engagements: measure detection and response (dwell time, alert fidelity, ATT&CK coverage) and drive detection-engineering improvements from what the campaign surfaced.
- Advise leadership on the direction of the red-team function; identify gaps in coverage and defensive controls; propose new adversary-emulation approaches for emerging threats.
Requirements
You do not need to check every box below. If you're a deep red-team operator and leader who's started testing AI systems and is ready to bring AI fluency to a team, we want to talk.
- 7+ years in red team, adversary emulation, or offensive security operations, with ~2 years leading complex operations or technical workstreams, setting the tradecraft and standards other operators follow.
- Deep adversary-emulation tradecraft. Objective-based operations across the full attack lifecycle (initial access, privilege escalation, lateral movement, defense evasion), hands-on C2 (e.g. Cobalt Strike, Brute Ratel, Nighthawk, and Mythic), and Active Directory / Entra ID attack paths, with a track record leading the most complex campaigns autonomously.
- Rules-of-engagement discipline. You've owned the authorization, scoping, deconfliction, and safe-conduct standards that keep offensive operations legal and in-scope, and you can represent the red team's risk to security leadership.
- You've attacked AI. Hands-on adversarial testing of AI/LLM-powered systems (prompt injection, agent/tool abuse, jailbreaks), demonstrated ability to red-team emerging AI systems, or a strong red-team operator ready to build AI-attack capability and lead the team into it.
- You operate agentic AI tooling. You've used modern AI-assisted or agentic offensive tooling in real operations and can judge where it helps, or you're a strong operator ready to adopt it and lead a team's move toward it.
- Scripting. Advanced proficiency in Python, PowerShell, Bash, or Ruby for automation and custom red-team tooling.
- Translate operations into defensive impact. Purple-team debriefs, detection-engineering feedback, and executive-consumable risk narratives that change what the business does next.
- Certifications are a plus, not a gate (e.g. OSCP, OSEP, OSED, OSCE3, CRTO, CRTL, or equivalent advanced credentials).
- Strong pluses (any of these will make you stand out): Contributing practitioner requirements to, or extending, agentic AI offensive tooling (multi-agent orchestration, MCP servers, LLM-as-judge) built by an AI-engineering team.
- Deeper adversarial ML, model extraction/inversion, membership inference, data/supply-chain poisoning, and hands-on with PyRIT or Garak.
- Malware development, custom tooling/implant development, or novel attack-chain research; published research or conference talks (DEF CON, Black Hat, BSides, x33fcon).
- Threat-intelligence-driven emulation (mapping APT/eCrime TTPs to campaigns) and detection-engineering collaboration.
Qualifications
To succeed in this role, you should have:
- Experience with ethical hacking and red team operations.
- Knowledge of offensive security tools and techniques.
- Experience with AI and machine learning concepts.
- Ability to work independently and manage multiple projects simultaneously.
- Excellent communication and interpersonal skills.
- Strong analytical and problem-solving skills.
- Ability to work in a fast-paced environment.
- Ability to adapt to changing environments and technologies.
- Ability to work collaboratively with cross-functional teams.
- Ability to prioritize tasks and manage time effectively.
- Ability to communicate complex technical concepts to non-technical stakeholders.
Skills
The ideal candidate should possess:
- Advanced proficiency in Python, PowerShell, Bash, or Ruby for automation and custom red-team tooling.
- Experience with AI and machine learning concepts.
- Experience with offensive security tools and techniques.
- Experience with ethical hacking and red team operations.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with novel attack-chain research.
- Experience with threat intelligence and analysis.
- Experience with cybersecurity frameworks and standards.
- Experience with offensive AI tooling.
- Experience with adversarial testing of AI/LLM-powered systems.
- Experience with malware development and custom tooling/implant development.
- Experience with