×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead, Offensive Security

Job in Concord, Merrimack County, New Hampshire, 03302, USA
Listing for: Humana
Full Time position
Listed on 2026-07-30
Job specializations:
  • Security
    Cybersecurity
Job Description & How to Apply Below
** Become a part of our caring community*
* We're hiring the technical leader of our red team, a hands-on Lead who runs our hardest adversary-emulation campaigns, sets how the team operates, owns the rules of engagement, and moves us into AI-augmented red teaming. You will own the craft: the tradecraft, the standards, the objective-based operations, and the safe, authorized conduct of offensive work.

Red teaming here is not vulnerability coverage and not automated control validation, it's objective-based adversary emulation: we measure whether the enterprise can detect, resist, and respond to a realistic adversary pursuing a mission objective, across network, social engineering, physical, and assumed-breach domains, mapped to MITRE ATT&CK and validated with our defenders through purple teaming.

This is a remote role on a specialized offensive-security team, red teaming shoulder-to-shoulder with Penetration Testing, Breach & Attack Simulation, and Bug Bounty. Fridays are for research and development. You'll have Hack The Box Pro Labs and role-based paths, discretionary certification funding, and a conference/training budget.

** What you'll own*
* +  
** The red-team tradecraft and standards.
** You set the methods, playbooks, and quality bar the team operates to. These are adversary emulation, C2 tradecraft, initial access, privilege escalation, lateral movement, defense evasion, and assumed-breach methodology - and keep them current as adversaries and defenses evolve.

+  
** The hardest campaigns.
** You scope, lead, and land the most complex objective-based operations end-to-end, and you're the technical escalation point when an operation hits a wall.

+  
** Rules of engagement and safe conduct.
** You own the authorization, scoping, deconfliction, and rules-of-engagement governance that keep offensive operations legal, in-scope, and safe.

+  
** AI-augmented red teaming, on two fronts.
** You drive how the team _operates and matures_ agentic AI offensive tooling to sharpen planning, tradecraft research, evidence synthesis, reporting, and you lead adversarial testing of the enterprise's own production AI systems as targets.

+  
** Defensive impact and functional influence.
** You turn campaigns into executive-consumable risk narratives, advise leadership on the direction of the red-team function, and partner with detection engineering and the SOC to close the loop on what we found.

** What you'll do*
* + Set and govern the team's adversary-emulation methodology, C2 tradecraft standards, and evidence-quality bar; standardize how objective-based operations are scoped, executed, and reported.

+ Lead the most complex red-team campaigns, external/internal network, social engineering, assumed-breach, and full-scope objective operations, with full autonomy, and mentor Senior red teamers on tradecraft without being their manager.

+  
** Own rules of engagement:
** define authorization, scope, deconfliction, and safe-conduct standards for every operation, in partnership with the Associate Director and stakeholders.

+  
** Operate and mature agentic AI red-team tooling:
** apply it to improve campaign planning, adversary research, and reporting quality; evaluate AI-assisted output for accuracy and operational fit; and feed practitioner requirements back to the Offensive AI Engineering team who build the platform.

+  
** Test AI systems as targets:
** lead adversarial assessments of production AI-enabled systems, prompt injection (direct/indirect), agent/tool abuse, RAG/training-data poisoning, sensitive-data exposure, and guardrail/control bypass, including abusing an internal AI agent as a step toward a mission objective within a broader adversary-emulation campaign, mapped to the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.

+ Run purple-team engagements: measure detection and response (dwell time, alert fidelity, ATT&CK coverage) and drive detection-engineering improvements from what the campaign surfaced.

+ Advise leadership on the direction of the red-team function; identify gaps in coverage and defensive controls; propose new adversary-emulation approaches for emerging threats.

** Your first 6-12 months*
* +  
** By 90 days:
** you've learned about our most complex prior campaigns and have had input on the planning/strategy for the next set, mapped the current state of our tradecraft and rules-of-engagement standards, and identified the first standards to raise.

+  
** By 6 months:
** the team operates to methodology and RoE standards you've set; agentic AI tooling is integrated into at least one core red-team workflow, and you've led at least one adversarial assessment of a production AI system.

+  
** By 12 months:
** AI-augmented red teaming and AI-system testing are a normal part of how the team works; you're advising leadership on the multi-quarter direction of the red-team function.

** Use your skills to make an impact*
* ** Why this role, and why here*
* +  
** Real authority over the craft.
** You set…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary