An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Acrisure is seeking a hands-on offensive security engineer to identify and prove exploitable vulnerabilities across web applications, APIs, and cloud-hosted services in a large SaaS portfolio. You will conduct manual and automated assessments, build attack tooling, and collaborate with engineering teams to validate fixes.
The role emphasizes AI-powered reconnaissance, vulnerability discovery, and reporting, including prompt injection risks in AI-enabled features.
About Acrisure
A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more.
In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible.
You will be a hands‑on offensive security engineer who finds and proves exploitable vulnerabilities in web applications, APIs, and cloud-hosted services before adversaries do. Your primary focus is web application and API penetration testing across a large, multi‑tenant SaaS portfolio; including payroll, benefits, and financial platforms that process sensitive PII and financial data at scale.
You’ll conduct manual and automated security assessments, build repeatable attack tooling, and work directly with engineering teams to validate fixes. You will also leverage AI tools to accelerate reconnaissance, vulnerability discovery, exploit development, and reporting; and assess AI-integrated features within our applications for prompt injection, model manipulation, and agentic abuse risks.
We are an AI‑first security organization. We build with AI, secure AI, and expect this role to actively leverage AI tooling to accelerate offensive security outcomes.
Success in this role means finding the vulnerabilities that scanners miss, proving exploitability with evidence that drives action, and helping engineering teams ship more secure code.
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.
Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children’s Hospital in Grand Rapids, Michigan, UPMC Children’s Hospital in Pittsburgh, Pennsylvania and Blythedale Children’s Hospital in Valhalla, New York.
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting leaves@acrisure.com .
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Welcome, your new opportunity awaits you.