Skip to main content
Horizon3

Senior/Staff Offensive Security Software Engineer

RemoteUnited States only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Startup
$196k–$242k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior/Staff Offensive Security Software Engineer with extensive web application penetration testing experience and interest in AI-enhanced security. Will design, develop, and integrate web application penetration testing content into the NodeZero platform. Requires full-scope web app testing expertise, software development skills, and enthusiasm for AI in offensive security.

Core skills

web application penetration testingAI-enhanced security techniques

Required skills

proxy toolsBurpbrowser developer toolsobject-oriented programmingtest-driven developmentAI-assisted development toolssecurity researchautomationPostgreSQLNeo4j

Optional skills

software developmentautomationlarge-scale software development projectsfine-tuning language modelsretrieval-augmented generation (RAG)security-focused applicationsAI/LLM toolsagentic workflows

Required languages

English

What you'll do

  • Perform hands-on, full-scope web application penetration tests against real customer applications, alongside benchmark and lab targets, to surface vulnerabilities and attack paths.
  • Review NodeZero results on live customer engagements to identify coverage gaps, blind spots, and missed opportunities — the edge cases and corner-case attack scenarios that autonomous testing doesn't yet handle.
  • Manually reproduce and validate those edge cases, building reliable, production-safe proof-of-concept exploits and clear test cases that demonstrate the gap end to end — including against live customer environments without disrupting them.
  • Partner closely with software engineers to translate your findings into product improvements — defining detection logic, attack content, expected behavior, and remediation so NodeZero handles those cases going forward.
  • Build and maintain a library of regression and benchmark test cases so newly added coverage doesn't silently regress over time.
  • Monitor production pentests for missed findings and false positives; create and triage Jira tickets to drive issues to resolution.
  • Work directly with customers and internal teams to investigate findings, explain attack paths, and address questions about web application coverage and results.
  • Author technical blog posts and research write-ups showcasing new exploits, edge cases, and attack methodologies.
  • Mentor teammates and contribute to continuous improvement of team processes, methodology, and testing standards.

What they require

  • Experience conducting full scope web application pentests
  • Proficient in object-oriented programming and test-driven development, with strong analytical and problem-solving skills.
  • Experience applying AI-assisted development tools to security research and automation tasks
  • Curiosity about emerging AI technologies.
  • Skilled in designing, evaluating, and communicating technical solutions across systems, APIs, algorithms, and data structures.
  • Familiarity with relational and graph databases, particularly Postgres and Neo4j.
  • Strong written and verbal communication, including technical documentation.
  • Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels.
  • Quick to learn and adopt new technologies as needed.
  • History of recognized security research, including documented CVE discoveries and responsible disclosure
  • Track record of successful bug bounty contributions
  • Outstanding problem-solving aptitude.
  • Be self-motivated and highly energetic to have the ability to operate effectively with limited supervision and guidance.
  • Work with our security researchers to understand the technical aspects of reverse engineered exploits and weaponizing these exploits into the product.
  • Strong technical documentation and communication skills.
  • Document findings, methodologies, and recommendations for both technical and non-technical stakeholders.
  • Proficient in designing, presenting, and evaluating technical solutions.

Benefits

  • Competitive salary, equity and benefits.
  • health, vision & dental insurance for you and your family
  • a flexible vacation policy
  • generous parental leave
  • equity package in the form of stock options.

Horizon3 is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. Its flagship product, NodeZero, delivers production-safe autonomous pentests and assessment operations across internal, external, cloud, and hybrid cloud environments.

🇺🇸 United StatesCybersecurityStartup
$196k–$242k/yr