WebApp Offensive Security Software Engineer

Horizon3.ai
United States
Workplace: RemoteFull timeUSD 196,000 - 242,000 annuallyFunction: CybersecuritySkills: ["Communication","Problem-solving","Mentorship","Leadership","Teamwork"]

Hands-on web application penetration tester focusing on real customer applications, identifying edge cases and business-logic flaws that automated scanners miss, and partnering with engineers to turn findings into durable product coverage for the NodeZero platform.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Horizon3.ai
Horizon3.ai
3 months ago

WebApp Offensive Security Software Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live
Reposted: similar role first listed 4 months ago

Job Summary

Hands-on web application penetration tester focusing on real customer applications, identifying edge cases and business-logic flaws that automated scanners miss, and partnering with engineers to turn findings into durable product coverage for the NodeZero platform.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Perform hands-on, full-scope web application penetration tests against real customer applications, surface vulnerabilities and attack paths.
  • •Review NodeZero results on live engagements to identify coverage gaps and edge-case attack scenarios that autonomous testing doesn’t yet handle.
  • •Manually reproduce and validate edge cases with production-safe proof-of-concept exploits and clear test cases.
  • •Collaborate with software engineers to translate findings into product improvements, defining detection logic, attack content, and remediation.
  • •Build and maintain a library of regression and benchmark test cases to prevent silent regressions.

Pay and Benefits

Salary: USD 196,000 - 242,000 annually
Equity and Bonus:Equity
Perks:Health InsuranceVisionDentalRemote WorkEquity

Key Requirements

  • •Extensive hands-on experience conducting full-scope web application penetration tests.
  • •Deep, practical knowledge of common and not-so-common web vulnerability classes (e.g., SQL injection, XSS, SSRF, SSTI/CSTI, IDOR/BOLA, authentication/authorization bypass, path traversal, LFI).
  • •Ability to find and exploit business-logic and edge-case flaws that automated scanners routinely miss.
  • •Strong command of proxy tools (e.g., Burp Suite) and browser developer tools; comfortable scripting (Python or similar).
  • •Clear communication of attack steps, impact, and remediation guidance to engineers and non-technical stakeholders
Experience:CybersecurityPentestingWeb security
Skills:CommunicationProblem-solvingMentorshipLeadershipTeamwork
Certifications:OSCPOSWE
Languages:English
Tech Stack:Burp SuitePythonSQLJavaScriptWeb technologiesXSSSSRFLFI

Company Brief

Horizon3.ai
Builds NodeZero®, an autonomous penetration-testing platform that continuously finds, prioritizes, and verifies exploitable vulnerabilities across on-premises, cloud, and hybrid environments to help organizations reduce security risk.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2019
Glassdoor
Glassdoor: 4.9
WebsiteLinkedInGlassdoor