Senior Security Engineer, Application Security
Trail of Bits- Full Time
- Senior (5 to 8 years)
Employment Type: Full-time
Become a part of our caring community and help us put health first. The Lead, Offensive Security, owns the strategic roadmap for the Breach and Attack Simulation (BAS) program. This role makes complex decisions across multiple service lines, influences cross-functional teams throughout the organization, and translates technical findings into business impact. You will shape the future of our BAS program while addressing problems of substantial scope and complexity.
Join a 100% remote, highly specialized offensive security team where you will have access to Hack The Box Pro Labs, all HTB role-based training paths and certifications, discretionary certification funding, and conference/training budgets. These resources will enable you to continuously advance your expertise while working on industry-leading BAS challenges at scale. You will be part of Cyber Threat Simulation (CTS), collaborating with Red Team, Penetration Testing, and Bug Bounty professionals—highly specialized experts who identify vulnerabilities so the business can address them proactively. Fridays are dedicated to research and development, allowing the team to pursue training in emerging offensive security technologies, tools, large language models (LLMs), artificial intelligence, and other relevant topics.
Own the six-quarter roadmap to mature each BAS service line, including Threat Simulations, Pre-built Threat Simulations, Security Baselines, IOC Validation, and Synthetic Tests. Lead the expansion of our BAS platform across all cloud and on-premises segments, ensure seamless integration of reporting into our SOAR platform, and optimize the Findings-Analysis workstream to consistently deliver actionable insights with maximum efficiency.
Your week will involve collaborating with the CTI team to discuss recent threat actor campaigns, working with SRE to address requirements for deploying simulators in additional Cloud Service Provider environments, and reviewing TTP playbooks for upcoming quarterly threat simulations. You will also identify TTPs not currently included in the platform that require custom test case development, and present threat simulation results to engineering teams and their leadership. You will work directly in the console and provide mentorship to engineers as they debug issues.
Why it matters: BAS transforms security testing from point-in-time snapshots to continuous validation, ensuring that countermeasures are effective at scale before attackers have the opportunity to subvert them.
Health insurance provider for seniors and military
Humana provides health and well-being services, focusing on Medicare Advantage plans for seniors, military personnel, and communities. Their plans include HMO, PPO, and PFFS options, designed to improve health outcomes through comprehensive and flexible coverage. Humana's revenue comes from government contracts and member premiums, and they aim to maintain high renewal rates by offering quality service and competitive benefits. The company stands out by fostering a culture of inclusivity and belonging among its employees, while also ensuring accessibility for all members, including offering free language interpreter services. Humana's goal is to deliver value to its members through an extensive provider network and innovative health solutions.