Red Team Engineer

Acrisure, LLC

Atlanta (GA)

Hybrid

USD 140,000 - 210,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Acrisure, LLC is seeking a hands-on Red Team Engineer to perform web app and API penetration testing across a multi-tenant SaaS portfolio, including cloud-hosted services. You will combine manual testing with AI-augmented workflows to identify exploitable vulnerabilities, validate fixes, and collaborate closely with engineering teams.

You will also evaluate AI-integrated features for prompt injection and model abuse risks while contributing to repeatable security testing in CI/CD pipelines.

Qualifications

  • Hands-on offensive security engineer with web app and API testing experience.
  • Experience with multi-tenant SaaS security assessments.
  • Ability to use AI tools to accelerate testing and reporting.
  • Experience with cloud platforms (AWS/Azure) and IAM configurations.
  • Strong collaboration with engineering teams.

Responsibilities

  • Conduct deep manual penetration tests against web applications, REST/GraphQL APIs, and microservices focusing on authentication, authorization, session management and business logic flaws.
  • Test multi-tenant isolation boundaries and cross-tenant data access in SaaS platforms.
  • Assess and validate OAuth/OIDC, JWT handling, MFA bypass and token lifecycles.
  • Build and maintain AI-assisted attack workflows; develop repeatable validation pipelines.
  • Provide clear, evidence-based reports with remediation guidance and retest findings.

Skills

Penetration testing
Web security
Cloud security
Automation
AI tooling
Team collaboration
OAuth/OIDC
JWT handling

Tools

AWS
Azure
REST/GraphQL
CI/CD tooling
SAST/DAST

Job description

## Red Team EngineerApply: 999 Peachtree Street Northeast, Suite 2750 - ATLANTA, GA: Full time: Posted Yesterday: JR114375## **About Acrisure**A global fintech leader, Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together, we connect clients with customized solutions across insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more. In the last twelve years, Acrisure has grown in revenue from $38 million to nearly $5 billion, with over 19,000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership, accountability, and collaboration, we equip our teams to work at the highest levels possible. **Job Summary:**You will be a hands-on offensive security engineer who finds and proves exploitable vulnerabilities in web applications, APIs, and cloud-hosted services before adversaries do. Your primary focus is web application and API penetration testing across a large, multi-tenant SaaS portfolio; including payroll, benefits, and financial platforms that process sensitive PII and financial data at scale. You’ll conduct manual and automated security assessments, build repeatable attack tooling, and work directly with engineering teams to validate fixes. You will also leverage AI tools to accelerate reconnaissance, vulnerability discovery, exploit development, and reporting; and assess AI-integrated features within our applications for prompt injection, model manipulation, and agentic abuse risks. We are an AI-first security organization. We build with AI, secure AI, and expect this role to actively leverage AI tooling to accelerate offensive security outcomes. Success in this role means finding the vulnerabilities that scanners miss, proving exploitability with evidence that drives action, and helping engineering teams ship more secure code. **Responsibilities:** **Web Application & API Penetration Testing*** Conduct deep manual penetration tests against web applications, REST/GraphQL APIs, and microservices — focusing on authentication, authorization (IDOR/BOLA), session management, injection, and business logic flaws.* Perform source-code-assisted testing (grey-box/white-box) using access to application repositories to identify vulnerabilities that black-box testing misses.* Test multi-tenant isolation boundaries — proving or disproving cross-tenant data access, privilege escalation, and tenant-escape scenarios in SaaS platforms.* Assess authentication and session architectures: OAuth/OIDC flows, JWT handling, MFA bypass, token lifecycle, and session revocation effectiveness.* Validate authorization models end-to-end — from API gateway to data layer — identifying gaps where opt-in security filters can be bypassed or omitted.* Execute targeted assessments of high-risk application changes, new features, and integrations as part of the secure development lifecycle. **AI-Augmented Offensive Security*** Use AI tools (LLMs, copilots, agentic frameworks) to accelerate vulnerability discovery, payload generation, reconnaissance, and report writing.* Build and maintain AI-assisted attack workflows — automated recon pipelines, intelligent fuzzing, pattern-based code review, and exploit chain analysis.* Assess AI-integrated application features for prompt injection, training data leakage, model manipulation, excessive agency, and insecure output handling (OWASP LLM Top 10).* Contribute to AI red-teaming exercises targeting LLM-powered features, chatbots, and agentic systems deployed across the enterprise.* Stay current on AI-driven offensive techniques and defensive evasion — and translate emerging research into practical testing methodologies. **Cloud & Infrastructure Testing*** Conduct penetration tests against cloud-hosted applications and services in AWS and Azure — including serverless functions, container workloads, and managed services.* Test cloud identity and access configurations — IAM policies, role assumptions, cross-account access, service principal permissions, and privilege escalation paths.* Assess API gateway configurations, WAF effectiveness, and network segmentation controls.* Identify attack paths from application-layer compromise to cloud infrastructure pivot — demonstrating real-world impact chains. **Tooling, Automation & Reporting*** Build and maintain custom offensive tooling — scanners, exploit scripts, and validation frameworks tailored to the organization’s technology stack.* Develop repeatable, automated security validation tests that can be integrated into CI/CD pipelines for continuous assurance.* Produce clear, evidence-based penetration test reports with proof-of-concept exploits, risk ratings, and actionable remediation guidance.* Track and retest findings through remediation — validating fixes are effective and complete.* Contribute to the organization’s attack playbooks, TTPs documentation, and knowledge base. **Collaboration & Enablement*** Partner with AppSec engineers to translate offensive findings into defensive tooling improvements (SAST/DAST rules, ASPM policies).* Work with development teams during and after assessments — explaining vulnerabilities, demonstrating impact, and advising on secure design patterns.* Support bug bounty program triage and validation when external researchers report findings.* Participate in purple team exercises — working with detection engineering and SOC to validate monitoring coverage against real attack techniques. #LI-CH1**Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.****Why Join Us:**At Acrisure, we’re building more than a business, we’re building a community where people can grow, thrive, and make an impact. Our benefits are designed to support every dimension of your life, from your health and finances to your family and future.Making a lasting impact on the communities it serves, Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Children's Hospital in Grand Rapids, Michigan, UPMC Children's Hospital in Pittsburgh, Pennsylvania and Blythedale Children's Hospital in Valhalla, New York.**Employee Benefits**We also offer our employees a comprehensive suite of benefits and perks, including:* **Physical Wellness:** Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.* **Mental Wellness:** Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.* **Financial Wellness:** Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.* **Family Care:** Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.* **... and so much more!***This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.***Acrisure is an Equal Opportunity Employer.** We consider qualified applicants without regard to race, color, religion, sex, national origin, disability, or protected veteran status. Applicants may request reasonable accommodation by contacting *leaves@acrisure.com*.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Engineer
Security Incident Response Engineer

Acrisure, LLC • Atlanta (GA)

On-site
USD 110,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+4
Red Team Engineer
Red Team Engineer

Acrisure • Atlanta (GA)

On-site
USD 120,000 - 160,000
Identity & Access Management (IAM) Engineer
Identity & Access Management (IAM) Engineer

Acrisure, LLC • Atlanta (GA)

Hybrid
USD 110,000 - 160,000
Medical Insurance
Dental Insurance
Vision Insurance
+2
Software Engineer, Data (L1)
Software Engineer, Data (L1)

Acrisure, LLC • Austin (TX)

Hybrid
USD 90,000 - 120,000
Competitive compensation
Generous vacation policy
Medical, Dental, and Vision Insurance
+1
Employee Benefits Client Advisor
Employee Benefits Client Advisor

Acrisure, LLC • Atlanta (GA)

Hybrid
USD 70,000 - 90,000
Comprehensive medical insurance
Generous paid time off
401(k) plan with immediate vesting
Security Incident Response Engineer
Security Incident Response Engineer

Acrisure • Atlanta (GA)

On-site
USD 120,000 - 180,000
Employee Benefits Consultant
Employee Benefits Consultant

Acrisure, LLC • Atlanta (GA)

Hybrid
USD 90,000 - 130,000
Health insurance
401(k) plan
Employee Assistance Program (EAP)
+2
Platform Engineer - Palantir
Platform Engineer - Palantir

Acrisure, LLC • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Comprehensive medical, dental, and vision benefits
401(k) with company match
Flexible spending benefits
+1
Senior Software Engineer
Senior Software Engineer

Acrisure Technology Group, LLC • Austin (TX)

Hybrid
USD 140,000 - 210,000
Medical, dental, vision insurance
Life & disability insurance
Fertility benefits
+2
Manager Operations - Employee Benefits
Manager Operations - Employee Benefits

Acrisure, LLC • Walnut Creek (CA)

Hybrid
USD 100,000 - 170,000
Physical Wellness: medical & dental
Mental Wellness: PTO & EAP
Financial Wellness: 401(k) and HSA
+1