waypointjobs

WellSky

Red Team - Sr Security Engineer

overland park, KS

Check who can apply and the requirements below before continuing.

About this opportunity

WellSky lists this Red Team - Sr Security Engineer opportunity in overland park, Kansas. Review the employer’s description below for duties, qualifications and application requirements.

Job description

The Red Team - Sr Security Engineer is responsible for enterprise information security systems and infrastructure platforms for WellSky. The scope of this job includes information system security administration and maintenance, vulnerability management, and configuration of other security software and solutions.

Key Responsibilities:

Design, scope, and execute red team engagements and adversary emulation exercises against WellSky systems, cloud environments, and applications, and partner with detection engineering to close the gaps those exercises expose.

Lead the implementation and enhancement of security measures across systems and software development processes, system hardening, monitoring, vulnerability assessment and remediation, incident response, disaster recovery by enforcing secure software development lifecycle practices and considering emerging cybersecurity threats.

Develop and enforce security controls in colocation and cloud environments in strategic alignment with WellSky policies.

Analyze technical requirements and recommend solutions or enhancements to provide actionable guidance for the business that align with industry standards and regulatory compliance.

Provide technical guidance to development and IT teams by fostering secure software design and deployment.

Participate in the security incident response process by aiding in detection, notification, containment, resolution, and escalation of incidents as needed.

Serve as a subject matter expert for security tools (e.g., SIEM, DLP, EDR, SAST, SCA), optimize configurations and workflows, and provide guidance to other information security teammates and assign tasks as needed.

LeverageAItools and platforms as an integral part of daily responsibilities to enhance decision-making, streamline workflows, and drive data-informed outcomes.

Perform other job duties as assigned.

Required Qualifications:

Bachelor's degree in a related field or equivalent work experience

4 - 6 years related work experience

At least 2 years of the above experience in an offensive security role: penetration testing, red teaming, adversary emulation, or purple team

Hands-on experience executing the full attack lifecycle - reconnaissance, initial access, privilege escalation, lateral movement, persistence, and exfiltration - against enterprise networks, cloud environments, and web applications

Working knowledge of the MITRE ATT&CK framework for planning engagements and mapping findings to detection coverage

Proficiency with offensive tooling such as Burp Suite, Nmap, Metasploit, BloodHound, and Impacket, and with at least one command-and-control framework such as Cobalt Strike, Sliver, or Mythic

Cloud attack and defense experience in AWS, Azure, or GCP, including IAM abuse paths, misconfiguration exploitation, and cloud-native logging and controls

Demonstrated ability to communicate findings to both engineering teams and executives, including business risk, exploitability, and prioritized remediation guidance

Demonstrated daily use of AI assistants and agentic coding tools such as Claude Code, GitHub Copilot, or Cursor to accelerate research, tooling development, log analysis, and reporting

Practical prompt engineering skill, including decomposing security tasks for large language models and critically validating AI-generated output before acting on it

Understanding of the security and privacy risks introduced by AI tooling, including safe handling of PHI and other sensitive data in prompts and adherence to responsible-use policies

Preferred Qualifications:

Offensive depth

Detection engineering and purple team collaboration, including writing or tuning SIEM detections based on emulated adversary behavior

Malware analysis, reverse engineering, or custom payload development and EDR evasion in an authorized testing context

Active Directory and Microsoft Entra ID attack path analysis and hardening

Container and Kubernetes security testing, and CI/CD pipeline or software supply chain attack techniques

Application security depth, including SAST, DAST, and SCA triage, secure code review, and threat modeling

Contributions to the security community such as open-source tooling, CVE research, CTF placement, conference talks, or published research

Scripting and automation ability in Python, PowerShell, Bash, or Go to build tooling and automate repetitive testing

AI and machine learning security

Experience testing AI and LLM-enabled applications for prompt injection, jailbreaks, insecure output handling, data leakage, and agent or tool-abuse paths

Familiarity with the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework

Experience building AI-assisted security automation, such as agents or scripts for alert triage, recon enrichment, log correlation, or evidence collectionUnderstanding of how to secure AI infrastructure, including model endpoints, MCP servers and tool integrations, RAG data stores, and API key management for AI services

Experience evaluating third-party AI tools for enterprise risk and defining safe-use guardrails

Certifications, any of the following

Offensive security: OSCP, OSEP, OSWE, CRTO, GPEN, GXPN, or PNPT

Cloud: AWS, Azure, or GCP security specialty certification

General: CISSP, GCIH, or GCIA

Healthcare and compliance

Healthcare industry experience

Working knowledge of the HIPAA Security Rule, HITRUST CSF, SOC 2, and NIST 800-53 or the NIST Cybersecurity Framework, and how they constrain offensive testing scope and evidence handling

Experience conducting authorized testing in regulated environments under formal rules of engagement and change-control processes

Job Expectations:

Willing to work additional or irregular hours as needed

Must work in accordance with applicable security policies and procedures to safeguard company and client information

Must be able to sit and view a computer screen for extended periods of time

#LI-TC1

#LI-Onsite

WellSky is where independent thinking and collaboration come together to create an authentic culture. We thrive on innovation, inclusiveness, and cohesive perspectives. At WellSky you can make a difference.

Here are some of the exciting benefits full-time teammates are eligible to receive at WellSky:

Excellent medical with Rx, dental, and vision benefits

Mental Health support through EAP

Generous paid time off, plus 13 paid holidays

100% vested 401(K) retirement plans

Educational assistance up to $2500 per year

WellSky provides equal employment opportunities to all people without regard to race, color, national origin, ancestry, citizenship, age, religion, gender, sex, sexual orientation, gender identity, gender expression, marital status, pregnancy, physical or mental disability, protected medical condition, genetic information, military service, veteran status, or any other status or characteristic protected by law. WellSky is proud to be a drug-free workplace.

Applicants for U.S.-based positions with WellSky must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Certain client-facing positions may be required to comply with applicable requirements, such as immunizations and occupational health mandates.

Data Privacy Notice for Job Applicants and Teammates

#J-18808-Ljbffr

Worksite address

overland park, KS, 66213, US

Who can apply

Review the original listing for work authorization, qualifications and employer requirements.

Ready for your next step?Apply on the official website
Apply on WhatJobs ↗

Explore related searches

Current related jobs

Elevance Health

WhatJobs

Principal Engineer - FDE

mason, OH

Salary not specified

Principal Engineer - FDE Hybrid: This role requires associates to be in-office 3 days per week, fostering collaboration and connectivity, w…

Last received from source 2026-10-06View job

Everpure, Inc.

WhatJobs

Principal Hardware Engineer

santa clara, CA

See pay details in description

Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar …

Last received from source 2026-10-06View job

Constellation Energy

WhatJobs

Engineer, Mechanical

baldwinsville, NY

See pay details in description

Who We Are As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constell…

Last received from source 2026-10-06View job

Constellation Energy

WhatJobs

Engineer, Mechanical

oswego, NY

See pay details in description

Who We Are As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constell…

Last received from source 2026-10-06View job

Constellation Energy

WhatJobs

Engineer, Electrical

wilmington, IL

See pay details in description

Who We Are As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constell…

Last received from source 2026-10-06View job

Constellation Energy

WhatJobs

Engineer, Electrical

odell, IL

See pay details in description

Who We Are As the largest private-sector power producer in the world and the nation's largest producer of clean and reliable energy, Constell…

Last received from source 2026-10-06View job