> Markdown version of [/jobs/ext/1853951-senior-engineer-offensive-security](https://www.wearedevelopers.com/jobs/ext/1853951-senior-engineer-offensive-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Engineer, Offensive Security - **Company:** Humana Inc. - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $117,600.0 - $161,700.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing, Internet Services, Python (Programming Language), Machine Learning, Open Web Application Security, Cloud Services, Red Team (Cyber Security), Large Language Models, Mitre Att&ck, Multi-Cloud, Generative AI, Bug Reporting, Machine Learning Operations, Purple Team (Cyber Security) - **Published:** July 3, 2026 - **Apply:** https://dejobs.org/x/x/CA89C1E2CD5C42E2BFAC53529B123BDD/job/ ## About the Role We're hiring for a genuinely hybrid skill set, real offensive operations and real AI engineering. You do not need to check every box below. We expect depth in one half and real credibility plus a desire to grow in the other, not day-one mastery of both. If you're a strong offensive operator who has built real AI tooling, or a strong AI/agent builder with serious hands-on offensive experience, we want to hear from you., * Offensive operations experience: 4+ years in roles such as Red Team, Penetration Testing, Purple Team / control validation, or Bug Bounty, with a track record of delivering engagements end to end: scoping, execution, and clear written findings. * Production Python engineering: you build and operate real tooling, not only one-off scripts. * You've built with agentic AI: hands-on designing, building, or operating AI agents or LLM applications: agentic workflows, tool/function-calling, and orchestration. (We care about what you've shipped and operated, not years on a particular framework-these frameworks are only a few years old.) * You've attacked AI: hands-on testing of AI/ML systems: prompt injection, jailbreaking, and adversarial techniques. * Cloud fluency: production experience with at least one major Cloud Service Provider (AWS, GCP, or Azure)., * Built autonomous or semi-autonomous offensive agents, LLM-driven penetration-testing agents, or reinforcement-learning exploit and attack-path planners. * Red-team tradecraft: C2 frameworks (e.g. Cobalt Strike , Sliver , Mythic ), evasion and OPSEC, and testing endpoints protected by modern EDR/XDR . * Purple-team and adversary-emulation fluency: MITRE ATT&CK , and platforms such as VECTR or Atomic Red Team . * Hands-on with AI red-teaming frameworks such as PyRIT or Garak , and fluent in MITRE ATLAS , the OWASP Top 10 for LLM Applications , and the NIST AI Risk Management Framework . * Model Context Protocol (MCP), building clients/servers, or testing them and RAG pipelines for tool/prompt-injection abuse. * Cloud penetration-testing depth or multi-cloud breadth; threat-intelligence-driven operations; depth in an advanced offensive specialty (malware development, advanced red-team operations, or adversarial ML research). * Published research, open-source contributions, or talks at DEF CON (incl. the AI Village / Generative Red Team), BSides, x33fcon, or Black Hat, or strong showings in AI-security competitions like HackAPrompt. * Certifications are a plus, not a gate, offensive (e.g. OSCP, OSEP, OSED, OSCE3, CRTO, CRTL, CPTS, CWES, CWEE, CAPE) and emerging AI-security (e.g. the OffSec AI Red Teamer (OSAI / AI-300), the SANS/GIAC AI security line, the HTB AI Red Teamer path). ## Description * First 90 days: ramp on the agent platform and the offensive service lines; deliver your first engagements (a penetration test and a purple-team exercise) and ship one improvement to the agentic tooling that you used during them. * By 6 months: ship at least one AI-driven tool that a service line adopts into its live workflow, with metrics showing coverage or turnaround gains; run a red-team operation end to end. * By 12 months: stand up repeatable adversarial testing for at least one of the enterprise's own AI systems; establish an evaluation approach that tracks your tooling's autonomous success against representative targets; become a go-to for both building and operating across the team. Why this role, and why here * Build and operate (both, for real). Most offensive roles let you build or operate. This one is explicitly both: you ship the software and you run the engagements, so your tooling is shaped by someone who actually uses it. * A program that's already serious about AI. Fridays are dedicated to R&D. You'll have Hack The Box Pro Labs, all HTB role-based paths and certifications, discretionary certification funding, and conference/training budgets. You'll work alongside the Lead of our new AI & Offensive Tooling capability-contributing to the platform they own while running your own engagements. * Mission that matters. Offensive Security identifies weaknesses so the business can fix them before adversaries exploit them, protecting the data and care of millions of people. AI is entering both our adversaries' tradecraft and our own operations faster than traditional tooling keeps up; you help keep us ahead., You'll work with considerable autonomy on moderately complex engagements and influence the team's technical direction through your expertise. You'll embed with each service line and the AI & Tooling Lead rather than build in isolation; ship software with engineering rigor (reproducibility, evaluation, safety guardrails, human-in-the-loop where offensive operations demand it); deliver findings and tooling with reproduction steps, severity, business impact, and remediation; track risk in the enterprise risk platform; and operate within the organization's acceptable-use-of-AI policies and offensive security rules of engagement. Work at Home Requirements To ensure Home or Hybrid Home/Office employees' ability to work effectively, the self-provided internet service of Home or Hybrid Home/Office employees must meet the following criteria: At minimum, a download speed of 25 Mbps and an upload speed of 10 Mbps is required; wireless, wired cable or DSL connection is suggested. In certain roles, the minimum recommended internet speed required by Humana may not be sufficient for business needs. Humana reserves the right to require associates to upgrade their internet service if necessary. Work from a dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information. Travel: While this is a remote position, occasional travel to Humana's offices for training or meetings may be required. Scheduled Weekly Hours 40 ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Debugging in the Dark](https://www.wearedevelopers.com/videos/1658-debugging-in-the-dark) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Open Source Is Not Just Code: Designing Communities That Actually Scale](https://www.wearedevelopers.com/videos/100204-open-source-is-not-just-code-designing-communities-that-actually-scale) - [Winning the Hybrid Cloud](https://www.wearedevelopers.com/videos/432-winning-the-hybrid-cloud) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix)