Acrisure

Red Team Engineer

Acrisure
Apply
1 day ago
Atlanta, GA, USASenior

Responsibilities

  • Conduct manual and automated web application, API, microservice, and cloud penetration tests.
  • Identify and demonstrate authentication, authorization, session, injection, business logic, cross-tenant, and privilege-escalation vulnerabilities.
  • Perform source-code-assisted testing and assess high-risk application changes and integrations.
  • Evaluate AI-integrated features, LLM-powered applications, chatbots, and agentic systems for offensive-security risks.
  • Build AI-assisted reconnaissance, fuzzing, code-review, exploit-analysis, and reporting workflows.
  • Test AWS and Azure identity, access, serverless, container, API gateway, WAF, and network segmentation controls.
  • Develop custom scanners, exploit scripts, validation frameworks, and automated CI/CD security tests.
  • Create evidence-based penetration test reports, track remediation, and retest fixes.
  • Partner with AppSec, development, detection engineering, and SOC teams; support bug bounty triage and purple-team exercises.

Requirements

  • Hands-on offensive security engineering experience focused on web application and API penetration testing.
  • Ability to perform manual, automated, grey-box, and white-box security assessments and prove exploitability with evidence.
  • Experience assessing authentication, authorization, OAuth/OIDC, JWT, MFA, session management, APIs, SaaS tenancy, and cloud security controls.
  • Experience with AI security risks such as prompt injection, training-data leakage, model manipulation, excessive agency, and insecure output handling.
  • Ability to build offensive-security tooling, exploit scripts, automated validation workflows, and repeatable attack methodologies.
  • Knowledge of AWS and Azure cloud environments, IAM, serverless functions, containers, managed services, API gateways, WAFs, and network segmentation.
  • Strong technical reporting, remediation validation, collaboration, and communication skills.
  • Familiarity with OWASP LLM Top 10, bug bounty validation, purple teaming, SAST/DAST, ASPM, detection engineering, and SOC operations is relevant to the role.

Benefits

  • Medical, dental, vision, life, and disability insurance; fertility benefits; wellness resources; and paid sick time.
  • Generous paid time off, holidays, an Employee Assistance Program, and a complimentary Calm app subscription.
  • Immediate 401(k) vesting, HSA and FSA options, commuter benefits, and employee discount programs.
  • Paid maternity and paternity leave, including for adoptive parents, legal plan options, and pet insurance.
  • The role expects an on-site presence to support collaboration and cross-functional partnership.
  • Benefits may vary by subsidiary entity and geographic location, and eligibility or waiting periods may apply.

Tech Stack

AssemblyAWSAzureGraphQL

Categories

Acrisure

About Acrisure

1,001-5,000 employees

Acrisure is a privately held insurance brokerage and fintech platform that serves businesses and individuals with property and casualty, employee benefits, reinsurance, payroll, and cybersecurity solutions. It operates globally from its headquarters in Grand Rapids, Michigan, and uses a mix of technology and advisory services for distribution. Founded in 2005, Acrisure is owned by ABRY Partners.

Contact me