Principal Security Engineer
HealthEquity, Inc.4 days ago
Remote, United StatesStaff+
Base Salary
$133k - $173k/yr
Responsibilities
- Build and maintain offensive security agents for reconnaissance, enumeration, vulnerability validation, and security testing across web and cloud environments.
- Develop agentic workflows supporting attack surface management and vulnerability management programs.
- Combine APIs, infrastructure-as-code, data pipelines, and LLM-driven steps in automated security workflows.
- Integrate security tooling with ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.
- Apply architectural patterns, governance requirements, and human-in-the-loop controls to AI-enabled security capabilities.
- Validate automated findings, reproduce vulnerabilities, and assist with risk assessment and prioritization.
- Develop monitoring, testing, and evaluation capabilities for agentic systems.
- Support penetration testing and purple-team activities focused on vulnerabilities, controls, and remediation.
- Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to improve detection and response.
- Document processes, automate repetitive workflows, and contribute to team tools and automation practices.
Requirements
- 10+ years of experience in software engineering, offensive security, penetration testing, application security, or a closely related discipline.
- Experience building and operating production software, automation platforms, or security tooling.
- Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
- Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and evaluation approaches.
- Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.
- Hands-on experience testing modern web applications, APIs, and cloud environments.
- Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, and exploit validation techniques.
- Experience assessing cloud identity, access management, configuration risks, and common cloud attack paths.
- Familiarity with application security testing, vulnerability analysis, remediation workflows, and offensive security tools.
- Experience working within cross-functional engineering or security teams and communicating technical risks to technical and non-technical audiences.
- Bachelor's degree in computer science, security, or another technical concentration preferred; master's degree preferred.
- Experience integrating security capabilities into CI/CD pipelines and developer workflows preferred.
- Healthcare, financial-services, or other regulated-industry experience preferred.
- Working knowledge of HIPAA, SOC 2, NIST Cybersecurity Framework, or similar frameworks preferred.
- Relevant certifications such as OSCP, OSWE, cloud security certifications, or comparable offensive security credentials preferred.
Benefits
- Remote work arrangement with mandatory in-person Trailhead onboarding held onsite at headquarters once per quarter; required travel and accommodations are covered.
- Medical, dental, and vision coverage.
- HSA contribution and match.
- Dependent care FSA match.
- Uncapped paid time off.
- Paid parental leave.
- 401(k) match.
- Personal and healthcare financial literacy programs.
- Ongoing education and tuition assistance.
- Gym and fitness reimbursement.
- Wellness program incentives.
- Performance-based incentives are available as part of the total compensation package.