Acrisure

Red Team Engineer

Acrisure$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in offensive security roles, focusing on web applications and APIs.
  • Experience with web application penetration testing methodologies and tools.
  • Proficient in source code analysis and exploitation techniques.
  • Familiarity with cloud security principles in AWS and Azure environments.
  • Knowledgeable about AI technologies and how to leverage them for security assessments.
  • Strong understanding of authentication and authorization frameworks.

Responsibilities

  • Conduct manual penetration testing of web applications, APIs, and microservices.
  • Perform source-code-assisted testing to uncover vulnerabilities missed by black-box testing.
  • Test isolation boundaries in multi-tenant SaaS environments for security validation.
  • Assess complex authentication architectures and session management effectiveness.
  • Run targeted security assessments during the development of high-risk features and changes.
  • Utilize AI tools to enhance vulnerability discovery and reporting processes.
  • Create and maintain automated security testing workflows and custom offensive tools.

Benefits

  • Collaborative work environment with a strong focus on AI-driven security.
  • Opportunity to work directly with engineering teams on security improvements.
  • Engagement in cutting-edge security practices and methodologies.
  • Involvement in purple team exercises and bug bounty programs to enhance skills.
  • Access to resources for continuous learning and professional development.
Full Job Description
Job Summary:

You will be a hands-on offensive security engineer who finds and proves exploitable vulnerabilities in web applications, APIs, and cloud-hosted services before adversaries do. Your primary focus is web application and API penetration testing across a large, multi-tenant SaaS portfolio; including payroll, benefits, and financial platforms that process sensitive PII and financial data at scale.

You'll conduct manual and automated security assessments, build repeatable attack tooling, and work directly with engineering teams to validate fixes. You will also leverage AI tools to accelerate reconnaissance, vulnerability discovery, exploit development, and reporting; and assess AI-integrated features within our applications for prompt injection, model manipulation, and agentic abuse risks.

We are an AI-first security organization. We build with AI, secure AI, and expect this role to actively leverage AI tooling to accelerate offensive security outcomes.

Success in this role means finding the vulnerabilities that scanners miss, proving exploitability with evidence that drives action, and helping engineering teams ship more secure code.

Responsibilities:

Web Application & API Penetration Testing
  • Conduct deep manual penetration tests against web applications, REST/GraphQL APIs, and microservices - focusing on authentication, authorization (IDOR/BOLA), session management, injection, and business logic flaws.
  • Perform source-code-assisted testing (grey-box/white-box) using access to application repositories to identify vulnerabilities that black-box testing misses.
  • Test multi-tenant isolation boundaries - proving or disproving cross-tenant data access, privilege escalation, and tenant-escape scenarios in SaaS platforms.
  • Assess authentication and session architectures: OAuth/OIDC flows, JWT handling, MFA bypass, token lifecycle, and session revocation effectiveness.
  • Validate authorization models end-to-end - from API gateway to data layer - identifying gaps where opt-in security filters can be bypassed or omitted.
  • Execute targeted assessments of high-risk application changes, new features, and integrations as part of the secure development lifecycle.


AI-Augmented Offensive Security
  • Use AI tools (LLMs, copilots, agentic frameworks) to accelerate vulnerability discovery, payload generation, reconnaissance, and report writing.
  • Build and maintain AI-assisted attack workflows - automated recon pipelines, intelligent fuzzing, pattern-based code review, and exploit chain analysis.
  • Assess AI-integrated application features for prompt injection, training data leakage, model manipulation, excessive agency, and insecure output handling (OWASP LLM Top 10).
  • Contribute to AI red-teaming exercises targeting LLM-powered features, chatbots, and agentic systems deployed across the enterprise.
  • Stay current on AI-driven offensive techniques and defensive evasion - and translate emerging research into practical testing methodologies.


Cloud & Infrastructure Testing
  • Conduct penetration tests against cloud-hosted applications and services in AWS and Azure - including serverless functions, container workloads, and managed services.
  • Test cloud identity and access configurations - IAM policies, role assumptions, cross-account access, service principal permissions, and privilege escalation paths.
  • Assess API gateway configurations, WAF effectiveness, and network segmentation controls.
  • Identify attack paths from application-layer compromise to cloud infrastructure pivot - demonstrating real-world impact chains.


Tooling, Automation & Reporting
  • Build and maintain custom offensive tooling - scanners, exploit scripts, and validation frameworks tailored to the organization's technology stack.
  • Develop repeatable, automated security validation tests that can be integrated into CI/CD pipelines for continuous assurance.
  • Produce clear, evidence-based penetration test reports with proof-of-concept exploits, risk ratings, and actionable remediation guidance.
  • Track and retest findings through remediation - validating fixes are effective and complete.
  • Contribute to the organization's attack playbooks, TTPs documentation, and knowledge base.


Collaboration & Enablement
  • Partner with AppSec engineers to translate offensive findings into defensive tooling improvements (SAST/DAST rules, ASPM policies).
  • Work with development teams during and after assessments - explaining vulnerabilities, demonstrating impact, and advising on secure design patterns.
  • Support bug bounty program triage and validation when external researchers report findings.
  • Participate in purple team exercises - working with detection engineering and SOC to validate monitoring coverage against real attack techniques.


#LI-CH1

Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.

About Acrisure

Acrisure is an insurance brokerage firm that provides a range of insurance products and services to businesses and individuals. The company was founded in 2005 and is headquartered in Caledonia, Michigan. Acrisure offers a wide range of insurance products, including property and casualty, employee benefits, and personal lines insurance. The company has grown rapidly through a series of acquisitions, and now has over 500 offices in the United States and around the world. Acrisure has been recognized as one of the fastest-growing companies in the United States, and has won numerous awards for its innovative insurance products and services.
Learn more about Acrisure
Size
7,000 employees
Industry
Founded
2006

Similar Jobs

More Jobs at Acrisure

More Information Technology Jobs

Find similar Red Team Engineer jobs: