Lead, Offensive Security

Humana
$142,300 - $195,700Remote

About The Position

We're hiring the technical leader of our red team, a hands-on Lead who runs our hardest adversary-emulation campaigns, sets how the team operates, owns the rules of engagement, and moves us into AI-augmented red teaming. You will own the craft: the tradecraft, the standards, the objective-based operations, and the safe, authorized conduct of offensive work. Red teaming here is not vulnerability coverage and not automated control validation, it's objective-based adversary emulation: we measure whether the enterprise can detect, resist, and respond to a realistic adversary pursuing a mission objective, across network, social engineering, physical, and assumed-breach domains, mapped to MITRE ATT&CK and validated with our defenders through purple teaming. This is a remote role on a specialized offensive-security team, red teaming shoulder-to-shoulder with Penetration Testing, Breach & Attack Simulation, and Bug Bounty. Fridays are for research and development. You'll have Hack The Box Pro Labs and role-based paths, discretionary certification funding, and a conference/training budget.

Requirements

  • 7+ years in red team, adversary emulation, or offensive security operations, with ~2 years leading complex operations or technical workstreams, setting the tradecraft and standards other operators follow.
  • Deep adversary-emulation tradecraft. Objective-based operations across the full attack lifecycle (initial access, privilege escalation, lateral movement, defense evasion), hands-on C2 (e.g. Cobalt Strike, Brute Ratel, Nighthawk, and Mythic), and Active Directory / Entra ID attack paths, with a track record leading the most complex campaigns autonomously.
  • Rules-of-engagement discipline. You've owned the authorization, scoping, deconfliction, and safe-conduct standards that keep offensive operations legal and in-scope, and you can represent the red team's risk to security leadership.
  • You've attacked AI. Hands-on adversarial testing of AI/LLM-powered systems (prompt injection, agent/tool abuse, jailbreaks), demonstrated ability to red-team emerging AI systems, or a strong red-team operator ready to build AI-attack capability and lead the team into it. We care about what you've done, not years on a framework that's only a few years old.
  • You operate agentic AI tooling. You've used modern AI-assisted or agentic offensive tooling in real operations and can judge where it helps, or you're a strong operator ready to adopt it and lead a team's move toward it.
  • You script. Advanced proficiency in Python, PowerShell, Bash, or Ruby for automation and custom red-team tooling.
  • You translate operations into defensive impact. Purple-team debriefs, detection-engineering feedback, and executive-consumable risk narratives that change what the business does next.

Nice To Haves

  • Certifications are a plus, not a gate (e.g. OSCP, OSEP, OSED, OSCE3, CRTO, CRTL, or equivalent advanced credentials.)
  • Contributing practitioner requirements to, or extending, agentic AI offensive tooling (multi-agent orchestration, MCP servers, LLM-as-judge) built by an AI-engineering team.
  • Deeper adversarial ML, model extraction/inversion, membership inference, data/supply-chain poisoning, and hands-on with PyRIT or Garak.
  • Malware development, custom tooling/implant development, or novel attack-chain research; published research or conference talks (DEF CON, Black Hat, BSides, x33fcon).
  • Threat-intelligence-driven emulation (mapping APT/eCrime TTPs to campaigns) and detection-engineering collaboration.

Responsibilities

  • Set and govern the team's adversary-emulation methodology, C2 tradecraft standards, and evidence-quality bar; standardize how objective-based operations are scoped, executed, and reported.
  • Lead the most complex red-team campaigns, external/internal network, social engineering, assumed-breach, and full-scope objective operations, with full autonomy, and mentor Senior red teamers on tradecraft without being their manager.
  • Own rules of engagement: define authorization, scope, deconfliction, and safe-conduct standards for every operation, in partnership with the Associate Director and stakeholders.
  • Operate and mature agentic AI red-team tooling: apply it to improve campaign planning, adversary research, and reporting quality; evaluate AI-assisted output for accuracy and operational fit; and feed practitioner requirements back to the Offensive AI Engineering team who build the platform.
  • Test AI systems as targets: lead adversarial assessments of production AI-enabled systems, prompt injection (direct/indirect), agent/tool abuse, RAG/training-data poisoning, sensitive-data exposure, and guardrail/control bypass, including abusing an internal AI agent as a step toward a mission objective within a broader adversary-emulation campaign, mapped to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
  • Run purple-team engagements: measure detection and response (dwell time, alert fidelity, ATT&CK coverage) and drive detection-engineering improvements from what the campaign surfaced.
  • Advise leadership on the direction of the red-team function; identify gaps in coverage and defensive controls; propose new adversary-emulation approaches for emerging threats.

Benefits

  • Hack The Box Pro Labs
  • discretionary certification funding
  • conference/training budget
  • medical
  • dental
  • vision
  • 401(k) retirement savings plan
  • time off (including paid time off, company and personal holidays, paid parental and caregiver leave)
  • short-term and long-term disability
  • life insurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service