Lead, Offensive Security

HumanaTampa, FL
$142,300 - $195,700Remote

About The Position

We're standing up a new AI & Offensive Tooling capability inside our Offensive Security organization, and we're looking for its founding engineer. As Lead, Offensive Security (AI & Tooling), you will own the in-house AI agent platform that powers our penetration testing and red team operations, and build the AI-driven tooling that makes every offensive service line faster, broader, and more autonomous. This is a hands-on building role with the scope of a technical lead: you set the technical direction for offensive AI at the company, and you ship the software that proves it. It's a rare chance to build autonomous offensive security capabilities from the ground up, responsibly, inside a program that helps protect the health data of millions of people. Join a 100% remote, highly specialized offensive security team where you will have access to Hack The Box Pro Labs, all HTB role-based training paths and certifications, discretionary certification funding, and conference/training budgets. These resources will enable you to continuously advance your expertise while working on industry-leading Offensive Security challenges at scale. You will be part of the Offensive Security organization, collaborating with Red Team, Penetration Testing, and Breach and Attack Simulation (BAS) professionals, highly specialized experts who identify vulnerabilities so the business can address them proactively. Fridays are dedicated to research and development, allowing the team to pursue training in emerging offensive security methodologies, tools, agents, large language models (LLMs), artificial intelligence, and other bleeding edge topics. AI that attacks traditional systems. Build autonomous and semi-autonomous agents that perform real offensive operations against networks, web applications, and infrastructure, LLM-driven planning loops that reason through reconnaissance, exploitation, privilege escalation, and lateral movement, multi-agent orchestration for breadth, and tool/function-calling that drives real offensive tooling. This is the emerging class of LLM-driven penetration-testing agents, built for production use by a professional red team. Offense applied to AI itself. Red-team the enterprise's own AI—LLM-powered products, agents, RAG pipelines, and ML applications, against prompt injection, jailbreaks, model extraction and inversion, membership inference, data and supply-chain poisoning, evasion, and agent tool/sandbox abuse, and validate that guardrails and classifiers actually hold. You'll operate this as a production, event-driven cloud platform at real scale, dozens of serverless functions, change-stream data pipelines, hundreds of operational alarms, and integrated LLM inference. This requires a production software engineering mindset, not proof-of-concept scripting. First 90 days: ramp on the agent platform and the three service lines (Red Team, BAS, Penetration Testing); take operational ownership; ship one meaningful improvement to the agent's autonomous capability or reliability, measured against real engagements. By 6 months: deliver at least one AI-driven tool that a service line adopts into its live workflow, with metrics showing coverage or turnaround gains; establish the evaluation harness that tracks the agent's autonomous success rate against representative targets. By 12 months: publish the multi-quarter offensive-AI roadmap and KPIs; stand up repeatable adversarial testing for the enterprise's own AI systems; mentor 1–3 engineers as the capability grows toward its own function. Real scope, real authority. You own the platform's architecture, roadmap, and day-to-day operation—and you advise Offensive Security leadership on strategy. This is the founding technical role of a capability that grows into its own team. A program that's already serious about AI. Fridays are dedicated to R&D. You'll have Hack The Box Pro Labs, all HTB role-based paths and certifications, discretionary certification funding, and conference/training budgets. Mission that matters. Offensive Security identifies weaknesses so the business can fix them before adversaries exploit them—protecting the data and care of millions of people. AI is entering both our adversaries' tradecraft and our own operations faster than traditional tooling keeps up; you keep us ahead.

Requirements

  • 6+ years in roles such as Red Team or Penetration Testing, including team- or program-level leadership.
  • Instinct to think like an attacker against systems that don't behave deterministically.
  • Strong track record of building and operating production-quality software and tooling (not just scripts).
  • Hands-on designing, building, or operating AI agents or LLM applications: agentic workflows, tool/function-calling, and orchestration.
  • Hands-on testing of AI/ML systems: prompt injection, jailbreaking, and adversarial techniques.
  • Production experience with at least one major Cloud Service Provider (AWS, GCP, or Azure).
  • Ability to provide a high speed DSL or cable modem for a home office.
  • Minimum standard speed for optimal performance of 25x10 (25mbps download x 10mbps upload) is required.
  • A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information.

Nice To Haves

  • Built autonomous or semi-autonomous offensive agents, LLM-driven penetration-testing agents, or reinforcement-learning exploit and attack-path planners.
  • Hands-on with AI red-teaming frameworks such as PyRIT or Garak.
  • Fluent in MITRE ATLAS, the OWASP Top 10 for LLM Applications, and the NIST AI Risk Management Framework.
  • Building clients/servers for Model Context Protocol (MCP), or testing them and RAG pipelines for tool/prompt-injection abuse.
  • Demonstrated ability to test endpoints protected by modern EDR/XDR.
  • Experience across multiple cloud providers.
  • Threat-intelligence-driven operations.
  • Depth in an advanced offensive specialty: malware development, advanced Red Team operations and threat simulation, or adversarial ML research.
  • Experience building and breaking LLMs, ML models, and AI infrastructure.
  • Published research, open-source contributions, or talks at DEF CON, BSides, x33fcon, or Black Hat.
  • Expert-level certifications (e.g. OSEE, OSED, OSCE3, CRTL, CWEE, CAPE).

Responsibilities

  • Own the in-house AI agent platform that powers penetration testing and red team operations.
  • Build AI-driven tooling to make offensive service lines faster, broader, and more autonomous.
  • Set the technical direction for offensive AI at the company.
  • Ship software that proves the effectiveness of offensive AI.
  • Build autonomous and semi-autonomous agents for offensive operations against networks, web applications, and infrastructure.
  • Develop LLM-driven planning loops for reconnaissance, exploitation, privilege escalation, and lateral movement.
  • Implement multi-agent orchestration for breadth.
  • Drive real offensive tooling through tool/function-calling.
  • Red-team the enterprise's own AI systems (LLM-powered products, agents, RAG pipelines, ML applications).
  • Test AI systems against prompt injection, jailbreaks, model extraction and inversion, membership inference, data and supply-chain poisoning, evasion, and agent tool/sandbox abuse.
  • Validate guardrails and classifiers for AI systems.
  • Operate the AI platform as a production, event-driven cloud platform at scale.
  • Take operational ownership of the agent platform within the first 90 days.
  • Ship one meaningful improvement to the agent's autonomous capability or reliability within the first 90 days.
  • Deliver at least one AI-driven tool that a service line adopts into its live workflow by 6 months.
  • Establish the evaluation harness that tracks the agent's autonomous success rate against representative targets by 6 months.
  • Publish the multi-quarter offensive-AI roadmap and KPIs by 12 months.
  • Stand up repeatable adversarial testing for the enterprise's own AI systems by 12 months.
  • Mentor 1-3 engineers as the capability grows toward its own function by 12 months.
  • Embed with each service line rather than build in isolation.
  • Ship production-grade software with engineering rigor (reproducibility, evaluation, safety guardrails, human-in-the-loop where offensive operations demand it).
  • Deliver findings and tooling with reproduction steps, severity, business impact, and remediation.
  • Track risk in the enterprise risk platform.
  • Operate within the organization's acceptable-use-of-AI policies and offensive security rules of engagement.

Benefits

  • Hack The Box Pro Labs
  • All HTB role-based training paths and certifications
  • Discretionary certification funding
  • Conference/training budgets
  • Medical benefits
  • Dental benefits
  • Vision benefits
  • 401(k) retirement savings plan
  • Time off (including paid time off, company and personal holidays, paid parental and caregiver leave)
  • Short-term disability
  • Long-term disability
  • Life insurance
  • Bonus incentive plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service