Horizon3.ai logo
Horizon3.ai

Continuous, autonomous pentesting, powered by NodeZero. Are your systems secure? Don't wait for a breach to find out!

Webapp Offensive Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200Since 2019H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

23 days ago

Salary

$185K - $240K / year

Seniority

Senior

Bachelor DegreeEnglishNeo4jPostgreSQL

Job Description

Webapp Offensive Security Engineer

Horizon3.ai

• Design, develop, and integrate web application offensive security content into the NodeZero platform • Design, develop, and integrate novel attack capabilities into the NodeZero platform, including offensive security tooling and AI-enhanced techniques. • Research and implement AI-driven methods for vulnerability detection, exploitation, and workflow automation. • Extend and maintain platform architecture, data models, and system design to support new product features. • Monitor production for issues or missed opportunities and create or resolve Jira tickets as needed. • Investigate, own, and resolve bugs in developed content. • Collaborate cross-functionally to address customer and prospect concerns related to attack content. • Author technical blog posts showcasing new research, exploits, or attack methodologies. • Mentor junior engineers and contribute to continuous improvement of team processes and standards

Job Requirements

  • Experience conducting full scope web application pentests
  • Experience with proxy tools like Burp and with browser developer tools
  • Proficient in object-oriented programming and test-driven development, with strong analytical and problem-solving skills.
  • Experience applying AI-assisted development tools to security research and automation tasks
  • Curiosity about emerging AI technologies.
  • Familiarity with relational and graph databases, particularly Postgres and Neo4j.
  • Strong written and verbal communication, including technical documentation.
  • Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels.
  • Quick to learn and adopt new technologies as needed.
  • Track record of successful bug bounty contributions.

Benefits

  • Health, vision & dental insurance for you and your family
  • Flexible vacation policy
  • Generous parental leave

Related Categories

Related Job Pages

More Security Engineer Jobs

CyberSheath logo

Cloud Security Engineer

CyberSheath

Assess, Implement, Manage (AIM™)

Full TimeRemoteTeam 51-200Since 2012H1B No Sponsor

• Architect, establish and maintain best practices of implementation for our products/services. • Configure, implement, and support all production security tools and technologies. • Maintain excellent documentation (SOPs) for all security tooling implementation, support, troubleshooting, etc. • Troubleshoot issues with security toolsets within client environments. • Execute projects related to client onboarding – portal configuration, agent deployment, best practices configuration, systems auditing. • Actively work with other team members on security events that require urgent response, containment and remediation. • Provide ongoing recommendations on toolset tuning and best practices. • Ability to discuss security posture with multiple clients and make recommendations to better their holistic security approach. • Triage incoming support tickets and requests related to security tools managed by CyberSheath. • Take part in daily shift changeover meetings at the beginning and end of shifts. • Provide support for cloud-based SIEM, EDR, and Anti-Spam/Phishing products. • Provide support for additional security tools such as, but not limited to: SOAR, MFA, Encryption, and Vulnerability Management platforms. • Assist with triage of alerts as necessary.

United States
$85K - $100K / year
Full TimeRemoteTeam 501-1,000Since 1998H1B No Sponsor

• Teil des Kernteams zur Weiterentwicklung der Cybersecurity-Präsenz in Stuttgart • Beratung zu Governance-, Compliance- und regulatorischen Anforderungen • Planung und Durchführung von Penetration Tests • Schwachstellenmanagement und Durchführung von Re-Tests innerhalb der EU • Begleitung von Projekten mit Architektur-Reviews, Secure-Coding-Coachings und Security-Checks • Erstellung von Methoden, Templates und Best Practices für effiziente Arbeitsweise • Unterstützung im PreSales bei Angebotserstellung und Kundenpräsentationen

Germany
Derq logo

Senior Security Engineer – Edge, Cloud

Derq

Intelligent transportation systems for smarter, safer roads

Full TimeRemoteTeam 11-50Since 2016H1B No Sponsor

• Secure the end-to-end platform, from Linux-based edge devices to cloud infrastructure, APIs, and data pipelines. • Identify, assess, and remediate security risks across applications, backend services, and deployed devices. • Conduct threat modeling across edge-to-cloud data flows, including video, sensor data, and metadata pipelines. • Harden edge devices, including OS security, SSH access, credential management, and patching practices, especially in physically accessible environments. • Secure cloud environments (AWS preferred), including IAM, network security, encryption, secrets management, and logging. • Support secure design and architecture reviews for new features and deployments. • Implement and improve **CI/CD security**, vulnerability scanning, and monitoring practices. • Monitor and respond to security incidents, including compromised devices or unauthorized access, and lead post-incident reviews. • Define and improve security policies, standards, and controls aligned with practical engineering needs. • Support compliance efforts such as ISO 27001, SOC 2, and customer security reviews. • Work closely with Engineering and Product to embed security into development without slowing delivery. • Contribute to internal security awareness, documentation, and best practices.

Mexico
Infatica.io logo

AV Whitelisting, Endpoint Security Compatibility Engineer

Infatica.io

Global data intelligence partner offering advanced web scraping & ethical proxies. 🌎 Worldwide IP locations since 2019

Full TimeRemoteTeam 11-50Since 2019H1B No Sponsor

• Analyze antivirus and EDR detections affecting our applications • Investigate false positives across: - Microsoft Defender - CrowdStrike - SentinelOne - Sophos - Bitdefender - ESET - Kaspersky • Work with engineering teams to identify behaviors triggering detections • Improve software trust and reputation mechanisms • Manage AV vendor submissions and whitelisting processes • Review: - installers - auto-update systems - drivers/services - network behavior - persistence mechanisms • Recommend improvements for: - code signing - EV certificates - Windows SmartScreen reputation - binary integrity - release pipelines • Perform static and dynamic analysis of binaries when needed • Communicate directly with antivirus vendors and security teams

Spain