Lead, Offensive Security at Humana | Washington, USA | Rezi

Lead, Offensive Security at Humana

Lead, Offensive Security

Humana · Washington, USA

5 days ago

Lead, Offensive Security

Humana · Washington, USA

6 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

We are establishing a new AI & Offensive Tooling capability within our Offensive Security organization and are seeking its founding engineer. As Lead, Offensive Security (AI & Tooling), you will be responsible for the in-house AI agent platform that supports our penetration testing and red team operations. You will also develop AI-driven tooling to enhance the speed, scope, and autonomy of all offensive service lines. This is a hands-on role with technical leadership responsibilities, where you will define the technical direction for offensive AI and deliver the software to implement it. This is a unique opportunity to build autonomous offensive security capabilities from the ground up, responsibly, within a program that safeguards the health data of millions.

Responsibilities

  • Own the in-house AI agent platform powering penetration testing and red team operations.
  • Build AI-driven tooling to make offensive service lines faster, broader, and more autonomous.
  • Set the technical direction for offensive AI within the company.
  • Ship software to prove the effectiveness of offensive AI initiatives.
  • Build autonomous and semi-autonomous agents for offensive operations against networks, web applications, and infrastructure.
  • Develop LLM-driven planning loops for reconnaissance, exploitation, privilege escalation, and lateral movement.
  • Implement multi-agent orchestration for broader coverage.
  • Develop tool/function-calling capabilities to drive offensive tooling.
  • Red-team the enterprise's own AI systems, including LLM-powered products, agents, RAG pipelines, and ML applications.
  • Test AI systems against prompt injection, jailbreaks, model extraction and inversion, membership inference, data and supply-chain poisoning, evasion, and agent tool/sandbox abuse.
  • Validate the effectiveness of guardrails and classifiers.
  • Operate the AI platform as a production, event-driven cloud platform at scale.
  • Develop dozens of serverless functions and change-stream data pipelines.
  • Implement hundreds of operational alarms and integrated LLM inference.
  • Ramp on the agent platform and service lines (Red Team, BAS, Penetration Testing) within the first 90 days.
  • Take operational ownership of the agent platform.
  • Ship one meaningful improvement to the agent's autonomous capability or reliability within the first 90 days.
  • Deliver at least one AI-driven tool adopted into a live workflow by a service line within 6 months.
  • Establish an evaluation harness to track the agent's autonomous success rate within 6 months.
  • Publish a multi-quarter offensive-AI roadmap and KPIs within 12 months.
  • Stand up repeatable adversarial testing for the enterprise's own AI systems within 12 months.
  • Mentor 1-3 engineers as the capability grows within 12 months.
  • Embed with each service line to understand their needs.
  • Ship production-grade software with engineering rigor, including reproducibility, evaluation, safety guardrails, and human-in-the-loop where necessary.
  • Deliver findings and tooling with reproduction steps, severity, business impact, and remediation.
  • Track risk in the enterprise risk platform.
  • Operate within the organization's acceptable-use-of-AI policies and offensive security rules of engagement.

Requirements

  • Reside within 60 minutes of Louisville KY, NYC Metro, Dallas Metro, Charlotte NC Metro, South Florida (Tampa/Miami/Ft Lauderdale), Washington DC metro, Chicago, Boston, Atlanta, or Nashville.
  • 6+ years in offensive security roles (e.g., Red Team, Penetration Testing), including team- or program-level leadership.
  • Ability to think like an attacker against systems that do not behave deterministically.
  • Strong track record of building and operating production-quality software and tooling (not just scripts).
  • Hands-on experience designing, building, or operating AI agents or LLM applications, including agentic workflows, tool/function-calling, and orchestration.
  • Hands-on experience testing AI/ML systems, including prompt injection, jailbreaking, and adversarial techniques.
  • Production experience with at least one major Cloud Service Provider (AWS, GCP, or Azure).
  • Ability to provide a high-speed DSL or cable modem for a home office.
  • Minimum internet speed of 25 Mbps download and 10 Mbps upload required.
  • Satellite and Wireless Internet service is not allowed.
  • A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information.
  • Occasional travel to Humana's offices for training or meetings may be required.

Skills

  • Offensive Security
  • AI Engineering
  • AI Agents
  • LLM Applications
  • Agentic Workflows
  • Tool/Function-Calling
  • Orchestration
  • Penetration Testing
  • Red Teaming
  • Breach and Attack Simulation (BAS)
  • Python Engineering
  • Cloud Service Providers (AWS, GCP, Azure)
  • Adversarial AI Testing
  • Prompt Injection
  • Jailbreaking
  • Model Extraction
  • Model Inversion
  • Membership Inference
  • Data Poisoning
  • Supply-Chain Poisoning
  • Evasion Techniques
  • Agent Tool/Sandbox Abuse
  • Serverless Functions
  • Change-Stream Data Pipelines
  • Operational Alarms
  • LLM Inference
  • PyRIT
  • Garak
  • MITRE ATLAS
  • OWASP Top 10 for LLM Applications
  • NIST AI Risk Management Framework
  • Model Context Protocol (MCP)
  • RAG Pipelines
  • EDR/XDR
  • Malware Development
  • Advanced Red Team Operations
  • Threat Simulation
  • Adversarial ML Research
  • Building and Breaking LLMs
  • ML Models
  • AI Infrastructure
  • Research and Development
  • Hack The Box Pro Labs
  • HTB Role-Based Training Paths and Certifications
  • Discretionary Certification Funding
  • Conference/Training Budgets

Location

  • Remote
  • Louisville KY
  • NYC Metro
  • Dallas Metro
  • Charlotte NC Metro
  • South Florida (Tampa/Miami/Ft Lauderdale)
  • Washington DC metro
  • Chicago
  • Boston
  • Atlanta
  • Nashville

Work Type

  • Remote
  • Full-time

Experience Level

  • Lead
  • 6+ years in offensive security roles
  • Team- or program-level leadership experience

Salary/Compensations

  • $142,300 - $195,700 per year

Benefits

  • Hack The Box Pro Labs access
  • All HTB role-based training paths and certifications
  • Discretionary certification funding
  • Conference/training budgets
  • Medical benefits
  • Dental benefits
  • Vision benefits
  • 401(k) retirement savings plan
  • Paid time off
  • Company and personal holidays
  • Paid parental leave
  • Paid caregiver leave
  • Short-term disability
  • Long-term disability
  • Life insurance
  • Bonus incentive plan
  • Internet expense reimbursement (for California residents)

About the Company

  • Humana Inc. is a leading U.S. healthcare company.
  • Through its Humana insurance services and CenterWell healthcare services, the company makes it easier for millions of people to achieve their best health.
  • The company delivers the care and service people need, when they need it.
  • These efforts improve the quality of life for people with Medicare and Medicaid, families, individuals, military service personnel, and communities.

Equal Opportunity

  • Humana does not discriminate against any employee or applicant for employment based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability, or protected veteran status.
  • Humana takes affirmative action to employ and advance in employment individuals with disabilities or protected veteran status.
  • All employment decisions are based solely on valid job requirements.
  • This policy applies to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation, and selection for training, including apprenticeship, at all levels of employment.