Red Team - Sr Security Engineer

WellSky Corporation

United States

On-site

USD 150,000 - 210,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Excellent benefits package
401(k) with match
Generous paid time off
Educational assistance

Job summary

WellSky seeks a Sr Security Engineer to own red team engagements across enterprise systems, cloud environments, and applications, partnering with detection engineering to close the gaps those exercises expose.

You will lead offensive assessments, implement secure coding practices, advise development and IT teams, and leverage AI tools to accelerate research, tooling development, and reporting.

Qualifications

  • Bachelor's degree in a related field or equivalent work experience.
  • 4 - 6 years related work experience.
  • At least 2 years in an offensive security role: penetration testing, red teaming, adversary emulation, or purple team.
  • Hands-on experience executing the full attack lifecycle against enterprise networks, cloud environments, and web applications.
  • Working knowledge of MITRE ATT&CK framework for planning engagements and mapping findings to detection coverage.
  • Proficiency with offensive tooling such as Burp Suite, Nmap, Metasploit, BloodHound, and Impacket, and with at least one C2 framework (Cobalt Strike, Sliver, Mythic).
  • Cloud attack and defense experience in AWS, Azure, or GCP, including IAM abuse paths and cloud-native logging and controls.
  • Ability to communicate findings to engineers and executives with risk, exploitability, and remediation guidance.
  • Experience using AI assistants for research, tooling, log analysis, and reporting.
  • Prompt engineering skills for large language models and AI safety considerations.
  • Knowledge of AI risk, PHI handling, and responsible-use policies.

Responsibilities

  • Design, scope, and execute red team engagements and adversary emulation against WellSky systems, cloud environments, and applications.
  • Lead the implementation and enhancement of security measures across systems and software development processes, including hardening and incident response.
  • Develop and enforce security controls in colocation and cloud environments aligned with WellSky policies.
  • Analyze requirements and provide solutions aligned with industry standards and regulatory compliance.
  • Provide technical guidance to development and IT teams for secure design and deployment.
  • Participate in security incident response and escalation as needed.
  • Serve as SME for security tools and optimize configurations and workflows.
  • Leverage AI tools to enhance decision-making and reporting.

Skills

Red Team engagements/ adversary emul
MITRE ATT&CK
Offensive tooling
Cloud security
AI tools & prompts
Communication to execs
Security tooling (SIEM, EDR, SAST)

Education

Bachelor's degree or equivalent

Tools

Burp Suite
Nmap
Metasploit
BloodHound
Impacket
Cobalt Strike/ Sliver/ Mythic

Job description

The Red Team – Sr Security Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes information system security administration and maintenance, vulnerability management, and configuration of other security software and solutions.


Key Responsibilities:


  • Design, scope, and execute red team engagements and adversary emulation exercises against WellSky systems, cloud environments, and applications, and partner with detection engineering to close the gaps those exercises expose.

  • Lead the implementation and enhancement of security measures across systems and software development processes, system hardening, monitoring, vulnerability assessment and remediation, incident response, disaster recovery by enforcing secure software development lifecycle practices and considering emerging cybersecurity threats.

  • Develop and enforce security controls in colocation and cloud environments in strategic alignment with WellSky policies.

  • Analyze technical requirements and recommend solutions or enhancements to provide actionable guidance for the business that align with industry standards and regulatory compliance.

  • Provide technical guidance to development and IT teams by fostering secure software design and deployment.

  • Participate in the security incident response process by aiding in detection, notification, containment, resolution, and escalation of incidents as needed.

  • Serve as a subject matter expert for security tools (e.g., SIEM, DLP, EDR, SAST, SCA), optimize configurations and workflows, and provide guidance to other information security teammates and assign tasks as needed.

  • Leverage AI tools and platforms as an integral part of daily responsibilities to enhance decision-making, streamline workflows, and drive data-informed outcomes.

  • Perform other job duties as assigned.


Required Qualifications:


  • Bachelor's degree in a related field or equivalent work experience

  • 4 - 6 years related work experience

  • At least 2 years of the above experience in an offensive security role: penetration testing, red teaming, adversary emulation, or purple team

  • Hands‑on experience executing the full attack lifecycle – reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration – against enterprise networks, cloud environments, and web applications

  • Working knowledge of the MITRE ATT&CK framework for planning engagements and mapping findings to detection coverage

  • Proficiency with offensive tooling such as Burp Suite, Nmap, Metasploit, BloodHound, and Impacket, and with at least one command-and-control framework such as Cobalt Strike, Sliver, or Mythic

  • Cloud attack and defense experience in AWS, Azure, or GCP, including IAM abuse paths, misconfiguration exploitation, and cloud-native logging and controls

  • Demonstrated ability to communicate findings to both engineering teams and executives, including business risk, exploitability, and prioritized remediation guidance

  • Demonstrated daily use of AI assistants and agentic coding tools such as Claude Code, GitHub Copilot, or Cursor to accelerate research, tooling development, log analysis, and reporting

  • Practical prompt engineering skill, including decomposing security tasks for large language models and critically validating AI-generated output before acting on it

  • Understanding of the security and privacy risks introduced by AI tooling, including safe handling of PHI and other sensitive data in prompts and adherence to responsible-use policies


Preferred Qualifications:


  • Offensive depth

  • Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior

  • Malware analysis, reverse engineering, or custom payload development and EDR evasion in an authorized testing context

  • Active Directory and Microsoft Entra ID attack path analysis and hardening

  • Container and Kubernetes security testing, and CI/CD pipeline or software supply chain attack techniques

  • Application security depth, including SAST, DAST, and SCA triage, secure code review, and threat modeling

  • Contributions to the security community such as open-source tooling, CVE research, CTF placement, conference talks, or published research

  • Scripting and automation ability in Python, PowerShell, Bash, or Go to build tooling and automate repetitive testing

  • AI and machine learning security Experience testing AI and LLM-enabled applications for prompt injection, jailbreaks, insecure output handling, data leakage, and agent or tool-abuse paths

  • Familiarity with the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework

  • Experience building AI-assisted security automation, such as agents or scripts for alert triage, recon enrichment, log correlation, or evidence collection

  • Understanding of how to secure AI infrastructure, including model endpoints, MCP servers and tool integrations, RAG data stores, and API key management for AI services

  • Experience evaluating third-party AI tools for enterprise risk and defining safe-use guardrails

  • Certifications, any of the following Offensive security: OSCP, OSEP, OSWE, CRTO, GPEN, GXPN, or PNPT

  • Cloud: AWS, Azure, or GCP security specialty certification

  • General: CISSP, GCIH, or GCIA

  • Healthcare and compliance

  • Working knowledge of the HIPAA Security Rule, HITRUST CSF, SOC 2, and NIST 800-53 or the NIST Cybersecurity Framework, and how they constrain offensive testing scope and evidence handling

  • Experience conducting authorized testing in regulated environments under formal rules of engagement and change-control processes


Job Expectations:


  • Willing to work additional or irregular hours as needed

  • Must work in accordance with applicable security policies and procedures to safeguard company and client information

  • Must be able to sit and view a computer screen for extended periods of time


#LI-TC1 #LI-Onsite


WellSky is where independent thinking and collaboration come together to create an authentic culture. We thrive on innovation, inclusiveness, and cohesive perspectives. At WellSky you can make a difference.


Benefits:


  • Excellent medical with Rx, dental, and vision benefits

  • Mental Health support through EAP

  • Generous paid time off, plus 13 paid holidays

  • 100% vested 401(K) retirement plans

  • Educational assistance up to $2500 per year


WellSky provides equal employment opportunities to all people without regard to race, color, national origin, ancestry, citizenship, age, religion, gender, sex, sexual orientation, gender identity, gender expression, marital status, pregnancy, physical or mental disability, protected medical condition, genetic information, military service, veteran status, or any other status or characteristic protected by law.


WellSky is proud to be a drug-free workplace.


Applicants for U.S.-based positions with WellSky must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Certain client-facing positions may be required to comply with applicable requirements, such as immunizations and occupational health mandates.


Data Privacy Notice for Job Applicants and Teammates


WellSky is a technology company leading the movement for intelligent, coordinated care worldwide. Our next-level software, analytics, and services power better outcomes and lower costs for stakeholders across the health and community care continuum. In today’s value-based care environment, WellSky helps providers, payers, health systems, and community organizations solve tough challenges, improve collaboration for growth, harness the power of data analytics, and achieve better outcomes by further connecting clinical and social care.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Red Team - Sr Security Engineer
Red Team - Sr Security Engineer

WellSky • Overland Park (KS)

On-site
USD 130,000 - 180,000
Excellent medical benefits
Mental Health support
Paid time off + holidays
+2
Solution Engineer III
Solution Engineer III

Wellsky • Overland Park (KS), Northern (KY)

Hybrid
USD 90,000 - 130,000
Medical benefits
Vision/Dental benefits
Paid holidays
+2
Solution Engineer III
Solution Engineer III

WellSky Corporation • United States

On-site
USD 100,000 - 150,000
Medical benefits
Mental health support
Paid time off
+2
Technical Program Manager
Technical Program Manager

WellSky Corporation • United States

On-site
USD 90,000 - 130,000
Medical benefits
Mental Health support
Paid time off
+2
Technical Program Manager
Technical Program Manager

Wellsky • Overland Park (KS), Northern (KY)

Hybrid
USD 100,000 - 140,000
Medical, dental, vision insurance
Mental Health support (EAP)
Paid time off + 13 paid holidays
+2
Associate Product Manager - Healthcare
Associate Product Manager - Healthcare

WellSky Corporation • United States

On-site
USD 90,000 - 130,000
Medical benefits
Mental Health support
Paid time off
+2
Staff Software Engineer - AI Platform Engineer
Staff Software Engineer - AI Platform Engineer

WellSky Corporation • United States

On-site
USD 140,000 - 210,000
Excellent medical benefits
401(k) retirement plans with company匹配
Educational assistance
Sr. Software Engineer (Forward Deployed Engineer)
Sr. Software Engineer (Forward Deployed Engineer)

WellSky Corporation • United States

On-site
USD 90,000 - 130,000
Excellent medical with Rx, dental, and vision benefits
Mental Health support through EAP
Generous paid time off, plus 13 paid holidays
+2
Consultant II
Consultant II

WellSky Corporation • United States

On-site
USD 80,000 - 110,000
Medical, dental, and vision benefits
Mental Health support through EAP
Generous paid time off and holidays
+3
Director, Marketing
Director, Marketing

Wellsky • Overland Park (KS), Northern (KY)

Hybrid
USD 140,000 - 210,000
Medical benefits
Dental & Vision
Paid time off + holidays
+2