HealthEquity, Inc.

Principal Security Engineer

HealthEquity, Inc.$133K — $173K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in software engineering or offensive security-related roles.
  • Hands-on experience with production software and automation solutions.
  • Ability to explain technical findings to diverse audiences clearly.
  • Experience within cross-functional engineering or security teams.
  • Proven ability to assess and balance security requirements with business needs.
  • Familiarity with regulatory frameworks like HIPAA and NIST Cybersecurity Framework.
  • Preferred Bachelor's or Master's Degree in a technical field.

Responsibilities

  • Build and maintain automated offensive security agents for vulnerability testing.
  • Develop workflows for attack surface and vulnerability management.
  • Implement automation combining deterministic and AI-driven components.
  • Integrate security tools with CI/CD pipelines and threat intelligence sources.
  • Apply architectural patterns and governance in AI-enabled security development.
  • Validate automated findings and assist with risk prioritization.
  • Support penetration testing and purple-team collaboration.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • HSA contribution and matching.
  • Uncapped paid time off and parental leave.
  • 401(k) match and tuition assistance programs.
  • Gym reimbursement and wellness incentives.
Full Job Description
Overview

How you can make a difference

As a Principal Security Engineer, AI Offensive Security, you build and operate agentic systems that discover, validate, and help remediate vulnerabilities across HealthEquity. You combine strong software engineering skills with offensive security expertise to automate security testing and vulnerability workflows across web applications and modern cloud environments.

You are an experienced builder who translates offensive security techniques into scalable automation. Working within established architectural patterns and security standards, you develop and enhance agentic capabilities that improve the speed, consistency, and coverage of vulnerability discovery and remediation.

The systems you build help move validated findings from identification through remediation while reducing manual effort and increasing the effectiveness of the security program.

 

What you'll be doing

  • Build and maintain offensive security agents that automate reconnaissance, enumeration, vulnerability validation, and other security testing activities across web and cloud environments.
  • Develop agentic workflows that support attack surface management and vulnerability management programs.
  • Implement automation that combines deterministic components (APIs, infrastructure-as-code, data pipelines) with non-deterministic, LLM-driven steps, choosing the right approach for each.
  • Build integrations between security tooling, ticketing platforms, asset inventories, CI/CD pipelines, and threat intelligence sources.
  • Apply established architectural patterns, governance requirements, and human-in-the-loop controls when developing AI-enabled security capabilities.
  • Validate findings generated by automated systems, reproduce vulnerabilities, and assist with risk assessment and prioritization.
  • Develop monitoring, testing, and evaluation capabilities that improve the reliability and effectiveness of agentic systems.
  • Support penetration testing and purple-team activities focused on validating vulnerabilities, controls, and remediation efforts.
  • Partner with Cyber Threat Intelligence, Security Engineering, and Vulnerability Management teams to improve detection and response capabilities.
  • Raise technical concerns, recommend improvements, and contribute to the evolution of team tools, practices, and automation capabilities.

What you will need to be successful

This role requires hands-on experience building and operating AI-enabled automation combined with practical offensive security expertise in modern web application and cloud environments.

Engineering & AI Expertise

  • Experience building and operating production software, automation platforms, or security tooling.
  • Experience developing or extending AI-enabled workflows, agentic systems, or LLM-powered automation solutions.
  • Familiarity with agent frameworks, orchestration patterns, structured context, tool integration, and evaluation approaches.
  • Ability to document technical processes and automate repetitive workflows through software and AI-enabled solutions.
  • Proficiency developing software and integrations using APIs, cloud services, automation frameworks, and data pipelines.
  • Experience using AI-assisted development tools and LLM technologies to accelerate engineering and automation outcomes.
  • Understanding of the strengths, limitations, and operational considerations associated with production AI systems.

Offensive Security Expertise

  • Hands-on experience testing modern web applications, APIs, and cloud environments.
  • Knowledge of OWASP Top 10 vulnerabilities, authentication and authorization weaknesses, business logic flaws, and exploit validation techniques.
  • Experience assessing cloud environments including identity, access management, configuration risks, and common cloud attack paths.
  • Familiarity with application security testing, vulnerability analysis, and remediation workflows.
  • Working knowledge of offensive security tools and methodologies used to identify and validate security weaknesses.

Experience & Background

  • 10+ years of experience in software engineering, offensive security, penetration testing, application security, or a closely related discipline.
  • Demonstrated experience delivering and supporting production software or automation solutions.
  • Experience working within cross-functional engineering or security teams.
  • Ability to explain technical risks and findings to both technical and non-technical audiences.
  • Sound judgment in balancing security requirements with engineering practicality and business needs.

Preferred Qualifications

  • Bachelor's Degree in computer science, security or other technical concentration; Master's Degree preferred
  • Experience integrating security capabilities into CI/CD pipelines and developer workflows.
  • Experience in healthcare, financial services, or another highly regulated industry.
  • Working knowledge of HIPAA, SOC 2, NIST Cybersecurity Framework, or similar regulatory and security frameworks.
  • Relevant industry certifications such as OSCP, OSWE, cloud security certifications, or comparable offensive security credentials.
Salary Range$133000.00 To $173000.00 / year Benefits & Perks

The actual compensation offer is determined based on job-related knowledge, education, skills, experience, and work location. This position will be eligible for performance-based incentives as part of the total compensation package, in addition to a full range of benefits including:  

  • Medical, dental, and vision 
  • HSA contribution and match 
  • Dependent care FSA match 
  • Uncapped paid time off 
  • Paid parental leave 
  • 401(k) match 
  • Personal and healthcare financial literacy programs 
  • Ongoing education & tuition assistance 
  • Gym and fitness reimbursement 
  • Wellness program incentives 

 

Onboarding & Travel

This is a remote role, with an in-person onboarding training component. New team members must participate in Trailhead, HealthEquity’s immersive onboarding experience Trailhead is designed to foster meaningful connections, support your integration into the organization, and equip you with a strong understanding of our business. Trailhead participation is a key expectation of this role. Trailhead is held onsite at our headquarters once per quarter. HealthEquity covers all required travel and accommodations. 

 

This role may begin with a virtual, self-paced onboarding experience, followed by a mandatory onsite Trailhead session at a later date.

About HealthEquity, Inc.

HealthEquity, Inc. is a leading provider of consumer-directed benefits solutions. The company's platform provides a range of tax-advantaged financial solutions for consumers to save for their healthcare and other financial goals. HealthEquity's solutions include health savings accounts (HSAs), flexible spending accounts (FSAs), health reimbursement arrangements (HRAs), and other financial wellness products. The company serves more than 12 million accounts and has over $12 billion in assets under management. HealthEquity was founded in 2002 and is headquartered in Draper, Utah.
Learn more about HealthEquity, Inc.
Size
3,688 employees
Market Cap
$5.1 billion
Industry
Net Income
$3.2 million
Founded
2002
5 Year Trend
+33.5%
Revenue
$746.6 million
NASDAQ

Similar Jobs

More Jobs at HealthEquity, Inc.

More Information Technology Jobs

Find similar Principal Security Engineer jobs: