HealthEquity, Inc.

Principal Security Engineer

HealthEquity, Inc.
Apply
4 days ago
Remote, United StatesStaff+

Base Salary

$133k - $173k/yr

Responsibilities

  • Build and maintain offensive security agents for reconnaissance, enumeration, vulnerability validation, and security testing across web and cloud environments.
  • Develop agentic workflows supporting attack surface management and vulnerability management programs.
  • Combine APIs, infrastructure-as-code, data pipelines, and LLM-driven steps in automated security workflows.
  • Integrate security tooling with ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.
  • Apply architectural patterns, governance requirements, and human-in-the-loop controls to AI-enabled security capabilities.
  • Validate automated findings, reproduce vulnerabilities, and assist with risk assessment and prioritization.
  • Develop monitoring, testing, and evaluation capabilities for agentic systems.
  • Support penetration testing and purple-team activities focused on vulnerabilities, controls, and remediation.
  • Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to improve detection and response.
  • Document processes, automate repetitive workflows, and contribute to team tools and automation practices.

Requirements

  • 10+ years of experience in software engineering, offensive security, penetration testing, application security, or a closely related discipline.
  • Experience building and operating production software, automation platforms, or security tooling.
  • Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
  • Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and evaluation approaches.
  • Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.
  • Hands-on experience testing modern web applications, APIs, and cloud environments.
  • Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, and exploit validation techniques.
  • Experience assessing cloud identity, access management, configuration risks, and common cloud attack paths.
  • Familiarity with application security testing, vulnerability analysis, remediation workflows, and offensive security tools.
  • Experience working within cross-functional engineering or security teams and communicating technical risks to technical and non-technical audiences.
  • Bachelor's degree in computer science, security, or another technical concentration preferred; master's degree preferred.
  • Experience integrating security capabilities into CI/CD pipelines and developer workflows preferred.
  • Healthcare, financial-services, or other regulated-industry experience preferred.
  • Working knowledge of HIPAA, SOC 2, NIST Cybersecurity Framework, or similar frameworks preferred.
  • Relevant certifications such as OSCP, OSWE, cloud security certifications, or comparable offensive security credentials preferred.

Benefits

  • Remote work arrangement with mandatory in-person Trailhead onboarding held onsite at headquarters once per quarter; required travel and accommodations are covered.
  • Medical, dental, and vision coverage.
  • HSA contribution and match.
  • Dependent care FSA match.
  • Uncapped paid time off.
  • Paid parental leave.
  • 401(k) match.
  • Personal and healthcare financial literacy programs.
  • Ongoing education and tuition assistance.
  • Gym and fitness reimbursement.
  • Wellness program incentives.
  • Performance-based incentives are available as part of the total compensation package.
HealthEquity, Inc.

About HealthEquity, Inc.

1,001-5,000 employees
Contact me