Principal Security Engineer
HealthEquity, Inc.4 days ago
Remote, United StatesStaff+
Base Salary
$133k - $173k/yr
Responsibilities
- Build and maintain offensive security agents that automate reconnaissance, enumeration, vulnerability validation, and security testing across web and cloud environments.
- Develop agentic workflows for attack surface management and vulnerability management programs.
- Combine APIs, infrastructure-as-code, data pipelines, and other deterministic components with LLM-driven automation.
- Integrate security tooling with ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.
- Apply architectural patterns, governance requirements, and human-in-the-loop controls to AI-enabled security capabilities.
- Validate automated findings, reproduce vulnerabilities, and support risk assessment and prioritization.
- Develop monitoring, testing, and evaluation capabilities for agentic systems.
- Support penetration testing and purple-team activities and partner with threat intelligence, security engineering, and vulnerability management teams.
Requirements
- At least 10 years of experience in software engineering, offensive security, penetration testing, application security, or a closely related discipline.
- Experience building and operating production software, automation platforms, or security tooling.
- Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
- Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.
- Hands-on experience testing modern web applications, APIs, and cloud environments.
- Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, exploit validation, cloud identity and access management, configuration risks, and common cloud attack paths.
- Experience with vulnerability analysis, remediation workflows, offensive security tools, and application security testing.
- Preferred bachelor's degree in computer science, security, or another technical field; master's degree preferred.
- Preferred experience integrating security capabilities into CI/CD pipelines and developer workflows and working in healthcare, financial services, or another regulated industry.
- Preferred knowledge of HIPAA, SOC 2, NIST Cybersecurity Framework, or similar frameworks and certifications such as OSCP, OSWE, or cloud security credentials.
Benefits
- Remote position with an in-person onboarding component.
- Quarterly onsite Trailhead onboarding; HealthEquity covers required travel and accommodations.
- Medical, dental, and vision coverage.
- HSA contribution and match and dependent care FSA match.
- Uncapped paid time off and paid parental leave.
- 401(k) match.
- Personal and healthcare financial literacy programs.
- Ongoing education and tuition assistance.
- Gym and fitness reimbursement and wellness program incentives.
- Performance-based incentives are available in addition to the benefits package.