Hiring.Camp

Principal Security Engineer

HealthEquity

·

Today

Salary
$133k – $173k
Location
Remote, US
Workplace
Remote
Type
Full-time
Department
Engineering
Seniority
Lead
Experience
10+ years
Education
Master
Closing date
Today
Source
iCIMS

Description

Our Mission

Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable.

Overview

How you can make a difference

As a Principal Security Engineer, AI Offensive Security, you build and operate agentic systems that discover, validate, and help remediate vulnerabilities across HealthEquity. You combine strong software engineering skills with offensive security expertise to automate security testing and vulnerability workflows across web applications and modern cloud environments.

You are an experienced builder who translates offensive security techniques into scalable automation. Working within established architectural patterns and security standards, you develop and enhance agentic capabilities that improve the speed, consistency, and coverage of vulnerability discovery and remediation.

The systems you build help move validated findings from identification through remediation while reducing manual effort and increasing the effectiveness of the security program.

 

What you'll be doing

  • Build and maintain offensive security agents that automate reconnaissance, enumeration, vulnerability validation, and other security testing activities across web and cloud environments.
  • Develop agentic workflows that support attack surface management and vulnerability management programs.
  • Implement automation that combines deterministic components (APIs, infrastructure-as-code, data pipelines) with non-deterministic, LLM-driven steps, choosing the right approach for each.
  • Build integrations between security tooling, ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.
  • Apply established architectural patterns, governance requirements, and human-in-the-loop controls when developing AI-enabled security capabilities.
  • Validate findings generated by automated systems, reproduce vulnerabilities, and assist with risk assessment and prioritization.
  • Develop monitoring, testing, and evaluation capabilities that improve the reliability and effectiveness of agentic systems.
  • Support penetration testing and purple-team activities focused on validating vulnerabilities, controls, and remediation efforts.
  • Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to improve detection and response capabilities.
  • Raise technical concerns, recommend improvements, and contribute to the evolution of team tools, practices, and automation capabilities.

What you will need to be successful

This role requires hands-on experience building and operating AI-enabled automation combined with practical offensive security expertise in modern web application and cloud environments.

Engineering & AI Expertise

  • Experience building and operating production software, automation platforms, or security tooling.
  • Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
  • Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and evaluation approaches.
  • Ability to document technical processes and automate repetitive workflows through software and AI-enabled solutions.
  • Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.
  • Experience using AI-assisted development tools and LLM technologies to accelerate engineering and automation outcomes.
  • Understanding of the strengths, limitations, and operational considerations associated with production AI systems.

Offensive Security Expertise

  • Hands-on experience testing modern web applications, APIs, and cloud environments.
  • Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, and exploit validation techniques.
  • Experience assessing cloud environments including identity, access management, configuration risks, and common cloud attack paths.
  • Familiarity with application security testing, vulnerability analysis, and remediation workflows.
  • Working knowledge of offensive security tools and methodologies used to identify and validate security weaknesses.

Experience & Background

  • 10+ years of experience in software engineering, offensive security, penetration testing, application security, or a closely related discipline.
  • Demonstrated experience delivering and supporting production software or automation solutions.
  • Experience working within cross-functional engineering or security teams.
  • Ability to explain technical risks and findings to both technical and non-technical audiences.
  • Sound judgment in balancing security requirements with engineering practicality and business needs.

Preferred Qualifications

  • Bachelor's Degree in Computer Science, Security or other technical degree; Master's degree preferred
  • Experience integrating security capabilities into CI/CD pipelines and developer workflows.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Working knowledge of HIPAA, SOC 2, NIST Cybersecurity Framework, or similar regulatory and security frameworks.
  • Relevant industry certifications such as OSCP, OSWE, cloud security certifications, or comparable offensive security credentials.

#LI-Remote

This is a remote position

Salary Range

$133000.00 To $173000.00 / year

Benefits & Perks

The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:  

  • Medical, dental, and vision 
  • HSA contribution and match 
  • Dependent care FSA match 
  • Uncapped paid time off 
  • Paid parental leave 
  • 401(k) match 
  • Personal and healthcare financial literacy programs 
  • Ongoing education & tuition assistance 
  • Gym and fitness reimbursement 
  • Wellness program incentives 

 

Onboarding & Travel

This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations. 

 

This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

 

HealthEquity is committed to providing reasonable accommodations to team members with qualifying disabilities. Should you be selected for this role and require an accommodation, we will put you in touch with our Benefits Team so you can begin the accommodation request process.

Why work with HealthEquity 

HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position. Click here to learn more. 

 

You belong at HealthEquity!

HealthEquity, Inc. is an equal opportunity employer, and we are committed to being an employer where no matter your background or identity – you feel welcome and included. We ensure equal opportunity for all applicants and employees without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace. For more information about our EEO policy, or about HealthEquity’s applicant disability accommodation, drug-free-workplace, background check, and E-Verify policies, please visit our Careers page.

 

HealthEquity uses Microsoft Copilot to transcribe screening interviews between candidates and their direct Talent Partner for note taking and interview summaries. By scheduling a screening interview with us, you consent to Microsoft Copilot’s AI technology recording and transcribing your interview with your Talent Partner. This information will be reviewed for accuracy and then used by HealthEquity to summarize the interview, ensure accuracy, and facilitate our hiring process. We take privacy seriously. You have the option to opt out. If you wish to opt out of this Microsoft Copilot transcription, please notify your Talent Partner in advance of the interview. If we do not receive an opt-out request from you, we will assume that you consent to the use of Microsoft Copilot.

 

At HealthEquity, our goal is to save and improve lives by empowering healthcare consumers. This shared purpose inspires everything we do, including how we approach hiring. Our process is designed to get to know the real you: your skills, experiences, and potential to make a difference. We value honesty, originality, and the courage to do the right thing, even when it is not the easiest path. Showing up as your authentic self reflects these values and helps us build something truly remarkable together.

 

As AI is becoming a common tool throughout the application process, we want to be clear about its appropriate use at HealthEquity. Using AI to support resume writing, research, or interview preparation is perfectly acceptable, provided the content is accurate and genuinely represents your qualifications and skills.  For other key parts of our interview process, however, it is important that the ideas, communication, and work you share reflect your own voice, experiences, and thinking. We ask that you participate in our live interviews and complete any assessments without AI assistance unless instructions explicitly indicate otherwise or a specific exception is discussed and approved in advance. This approach ensures fairness, celebrates your individuality, and allows your authentic perspective to shine. Behaviors that do not align with these guidelines may result in disqualification from the hiring process or termination of employment if later discovered. We appreciate your understanding and look forward to learning about the unique contributions only you can bring to HealthEquity.

 

HealthEquity is committed to your privacy as an applicant for employment.  For information on our privacy policies and practices, please visit HealthEquity Privacy.

Skills

CI/CDCybersecurityPenetration TestingSOCSOC 2HIPAA

Similar Jobs

30

Principal Security Engineer

HealthEquity · Remote, US · Remote

Today

Principal Security Engineer

Remitly is · Seattle, Washington United States, United States of America

3 days ago

Principal Security Engineer

Wsgr · Los Angeles, United States of America +1 · Remote

1 week ago

Principal Security Engineer

Smartsheet · Bellevue, WA, USA

1 week ago

Principal Security Engineer

Travelport Candidate Experience site · LANGLEY, BERKSHIRE, United Kingdom, GB

1 week ago

Principal, Security Engineer

Coupang Internal · Seattle, USA +1

1 week ago

Principal Security Engineer

Fluke · Remote, United States, US · Remote

2 weeks ago

Principal Security Engineer

Fortive · US · Remote

2 weeks ago

Principal Security Engineer

Fanniemae · Reston Town Center, United States of America +1 · Remote, Hybrid

3 weeks ago

Principal Security Engineer

Fintech · Tampa, FL

3 weeks ago

Principal Security Engineer

Oracle · Nashville, TN, United States, US

3 weeks ago

Principal Security Engineer

Oracle · Nashville, TN, United States, US

3 weeks ago

Principal Security Engineer

Oracle · Nashville, TN, United States, US

3 weeks ago

Principal Security Engineer

Zillow · Bengaluru, India · Onsite

1 month ago

Principal Security Engineer

Bonterra · Remote-US-Georgia, United States of America · Remote

1 month ago

Principal Security Engineer

JPMorgan Chase · Seattle, WA, United States, US

1 month ago

Principal Security Engineer

JP Morgan Chase · Seattle, WA, United States, US

1 month ago

Principal Security Engineer

Citizens Financial Group · Johnston, RI, United States, US

1 month ago

Principal Security Engineer

Parloa · Berlin Office +1 · Onsite

2 months ago

Principal Security Engineer

Oracle · United States, US

2 months ago

Principal Security Engineer

Jeppesen ForeFlight · Englewood, CO +1

2 months ago

Principal Security Engineer

Navy Federal Financial Group · Vienna, VA, United States, US · Hybrid

2 months ago

Principal Security Engineer

Verizon Communications · One Verizon Way, Basking Ridge, NJ (NJ0533), United States of America +5

2 months ago

Principal Security Engineer

Ethoslife · Bangalore, India

2 months ago

Principal Security Engineer

Candidhealth · San Francisco (CA), Denver (CO), New York (NY)

2 months ago

Principal Security Engineer

Akamai · United States, US · Remote

3 months ago

Principal Security Engineer

Vay · Berlin, Germany · Onsite

3 months ago

Principal Security Engineer

Hastingsdirect · Bexhill - 37, United Kingdom +1

3 months ago

Principal Security Engineer

Pipedrive · Germany, Berlin · Hybrid

4 months ago

Principal Security Engineer

Pipedrive · Estonia, Tallinn · Hybrid

4 months ago
Remote Principal Security Engineer at HealthEquity • $133k – $173k | Hiring.Camp