Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

WebApp Offensive Security Engineer

$196k - $242k

Horizon3.ai

Get to Know Us

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.


We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox" security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

Summary

We're looking for a Webapp Offensive Security Engineer with deep, hands-on web application penetration testing experience to push our autonomous testing beyond what it can do today. You'll be testing real customer web applications - not just labs and benchmarks - using NodeZero as your starting point and then going further as the human expert: hunting the edge cases, novel attack chains, and business-logic flaws that automated testing doesn't yet handle, proving them out safely against live targets, and working shoulder-to-shoulder with our software engineers to turn each discovery into durable product coverage that benefits every customer.

This is a pentesting-first role. You won't be expected to architect platform internals or ship production features yourself - you'll be the offensive expert who tests live customer applications, finds the gaps NodeZero doesn't yet cover, demonstrates them, defines what "good" looks like, and partners with engineering to close them. If you love breaking real web apps by hand, get satisfaction from finding what scanners miss, and want your tradecraft to scale to thousands of customers through the product, this role is for you.

Essential Functions
  • Perform hands-on, full-scope web application penetration tests against real customer applications, alongside benchmark and lab targets, to surface vulnerabilities and attack paths.
  • Review NodeZero results on live customer engagements to identify coverage gaps, blind spots, and missed opportunities - the edge cases and corner-case attack scenarios that autonomous testing doesn't yet handle.
  • Manually reproduce and validate those edge cases, building reliable, production-safe proof-of-concept exploits and clear test cases that demonstrate the gap end to end - including against live customer environments without disrupting them.
  • Partner closely with software engineers to translate your findings into product improvements - defining detection logic, attack content, expected behavior, and remediation so NodeZero handles those cases going forward.
  • Build and maintain a library of regression and benchmark test cases so newly added coverage doesn't silently regress over time.
  • Monitor production pentests for missed findings and false positives; create and triage Jira tickets to drive issues to resolution.
  • Work directly with customers and internal teams to investigate findings, explain attack paths, and address questions about web application coverage and results.
  • Author technical blog posts and research write-ups showcasing new exploits, edge cases, and attack methodologies.
  • Mentor teammates and contribute to continuous improvement of team processes, methodology, and testing standards.
Competencies/Requirements
  • Extensive hands-on experience conducting full-scope web application penetration tests.
  • Deep, practical knowledge of common and not-so-common web vulnerability classes - SQL injection, XSS (reflected, stored, and DOM-based), SSRF, SSTI/CSTI, IDOR/BOLA, authentication and authorization bypass, path traversal, LFI, and similar - including how to chain them to demonstrate impact.
  • A talent for finding and exploiting business-logic and edge-case flaws that automated scanners routinely miss.
  • Strong command of proxy tools like Burp Suite and browser developer tools.
  • Comfort scripting to reproduce findings and build proof-of-concept exploits (e.g., Python or similar) - you don't need to be a professional software engineer, but you should be able to write and read code well enough to demonstrate an exploit and collaborate effectively with engineers.
  • Ability to clearly communicate attack steps, impact, and remediation guidance to both engineers and non-technical stakeholders.
  • Curiosity about emerging AI technologies and comfort using AI-assisted tools in your testing and research workflow.
  • Strong written and verbal communication, including technical documentation.
  • Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels.
  • Quick to learn and adopt new technologies, frameworks, and target stacks as needed.
  • History of recognized security research, including documented CVE discoveries and responsible disclosure.
  • Track record of successful bug bounty contributions.
Desired/Nice to Have
  • Familiarity with how autonomous, agentic, or AI-driven pentesting tools work - and a sharp instinct for where and why they fail.
  • Experience writing detection or attack content (e.g., Nuclei templates, sqlmap tamper scripts, custom Burp extensions).
  • Enough software development background to collaborate fluently with engineers on remediation and product coverage.
  • Familiarity with relational and graph databases, particularly Postgres and Neo4j.
  • Experience with AI/LLM tools for building agentic workflows (e.g., LangChain, LangFlow) and integrating contextual data using protocols like Model Context Protocol (MCP).
Expectations:
  • Outstanding problem-solving aptitude and a relentless curiosity for how things break.
  • Self-motivated and highly energetic, with the ability to operate effectively with limited supervision and guidance.
  • Work with our engineers and security researchers to turn manual discoveries into reliable, production-safe product capabilities.
  • Strong technical documentation and communication skills.
  • Document findings, methodologies, and recommendations for both technical and non-technical stakeholders.
What makes you stand out:
  • A portfolio of novel web application research, exploits, or edge-case findings you can walk us through.
  • Demonstrated examples of using AI to enhance or accelerate your testing and exploit development.
  • OSCP, OSWE, or comparable offensive security certifications.
Perks of Horizon3.ai
  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.
  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.
Compensation and Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

In accordance with various State's transparency regulations, we provide the following salary range information for this position:
  • Base salary range: $196,000 - $242,000. The exact salary will be determined based on the selected candidate's location, qualifications, experience, and relevant skills.
  • Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.

You Belong Here

Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law.

Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.

We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the WebApp Offensive Security Engineer in United States vacancy
  • $185k - $240k

     ...Offensive Security Software Engineer Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Horizon3.ai

    United States
    9 days ago
  •  ...About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits...  ...the Role We’re seeking an exceptional Principal-level Offensive Security Engineer to challenge and strengthen OpenAI's security posture. This... 
    Suggested

    OpenAI

    San Francisco, CA
    3 days ago
  • $195k - $240k

    Here at Datadog, we think about offensive security a little bit differently. We embrace automation and AI to run adversary simulations continuously...  ...cloud-native environment, and we expect our offensive engineers to build the tooling that makes that possible. We're looking... 
    Suggested
    Work at office

    Datadog

    New York, NY
    4 days ago
  • $145k - $155k

     ...solutions provider focusing upon Cloud, Cyber Security, Networking, Disaster Recovery and Managed Services. Our corporate culture, engineering talent, customer-centric approach, and...  ...for a security engineer to join our Offensive Security team. This team focuses on advanced... 
    Suggested
    Weekday work

    Thrive

    New York, NY
    1 day ago
  • $165k - $242k

     ...Offensive Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale... 
    Suggested
    Permanent employment
    Temporary work
    Casual work
    Work at office
    Flexible hours

    CoreWeave

    Sunnyvale, CA
    4 days ago
  •  ...development by removing traditional barriers to application creation. About the role We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence" for Replit's cloud-native platform. At Replit, security isn't just... 
    Full time
    Temporary work
    Work at office
    Worldwide
    Monday to Friday
    Flexible hours

    Replit

    Foster, CA
    17 hours ago
  •  ...your home. The Mission Praetorian is an expert-driven offensive security company. Our mission is to prevent breaches before they...  ...Looking For We are looking for an Offensive Security Engineer who operates with clear ownership. You're not just filling... 
    Internship
    Shift work

    Praetorian

    Austin, TX
    3 days ago
  • $100k - $120k

     ...building a better logistics platform - we're redefining the future of automotive transportation. About the Role: The Offensive Security Engineer is a hybrid role combining hands-on penetration testing, adversary simulation, and security engineering. This position is... 
    Temporary work
    Work at office
    Local area
    Work from home
    Home office
    3 days per week

    RunBuggy

    Tempe, AZ
    17 hours ago
  •  ...Offensive Security Engineer (Red Team) PlexTrac is a cybersecurity SaaS platform helping security teams streamline reporting, exposure management, and remediation workflows. Our platform is used by penetration testers, red teams, consultants, enterprises, and managed... 
    Remote work

    PlexTrac

    United States
    2 days ago
  •  ...infrastructure that ensure global scale, secure player experiences, and unlock bold new...  ...Location: Orlando Reports to: Sr. Director Engineering, Application Security & Red Teaming...  ...drive everything we do. As an Offensive Security Engineer, you will report to the... 
    Local area

    Electronic Arts

    Orlando, FL
    1 day ago
  •  ...solving one of the hardest problems in security: giving every human, machine, workload,...  ...cryptographically secured identity, improving engineering velocity while maintaining security. We...  ...the Role We are looking for an Offensive Security Engineer to work on Teleport's... 
    Local area
    Remote work

    Teleport Inc

    United States
    17 hours ago
  •  ...Offensive Security Engineer Responsibilities: # Perform manual penetration tests of network services, network infrastructure, IoT devices, and software # Clearly document and communicate findings and remediation recommendations to leadership and device/software... 

    Right Hire IT

    Detroit, MI
    17 hours ago
  •  ...United Wholesale Mortgageis hiring an Offensive Security Engineer for a 100% on-site position in Pontiac, MI. Duties: Perform manual penetration tests of network services, network infrastructure, IoT devices, and software. Clearly document and communicate findings and... 

    United Wholesale Mortgage

    Pontiac, MI
    3 days ago
  •  ...believe human-based cyber defense is dead and the dream of security automation is finally within reach. Staris AI is a Series...  ...advancing applications into a new era of security. As an Offensive Security Engineer at Staris AI, you'll be at the vanguard of the application... 
    Remote work

    Staris AI

    Seattle, WA
    10 days ago
  • JM Family Enterprises is looking for an Information Security Operations Analyst II to lead offensive security initiatives, including penetration testing and threat assessments. The ideal candidate will collaborate with various teams to ensure robust security practices... 

    JM Family Enterprises

    Deerfield Beach, FL
    17 hours ago
  • $186.07k - $218.9k

     ...collaboration, connection, and alignment. Attendance is expected and fully supported. The Application Security org at Coinbase is hiring for a Senior Offensive Security Engineer, Offensive Security. We are seeking a highly skilled and experienced Penetration Tester with a... 
    Local area

    Coinbase

    Lincoln, NE
    3 days ago
  • $175k - $250k

     ...What Impact You'll Have Seeking experienced offensive security professionals to conduct security assessments, red team operations,...  ...offensive security certifications Experience with reverse engineering and exploit development Background in offensive cyber operations... 
    Contract work
    Work experience placement
    Immediate start

    GRVTY

    Sterling, VA
    17 hours ago
  • A leading AI research firm in San Francisco seeks a Principal-level Offensive Security Engineer to enhance its security posture. This role involves hunting for vulnerabilities, conducting red team operations, and collaborating with defensive teams to secure AI-powered products... 

    OpenAI

    San Francisco, CA
    17 hours ago
  • $181k

     ...Senior Offensive Security Engineer San Francisco, CA, USA About the Role We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services, applications, and infrastructure to discover security... 
    Full time
    Work at office
    Local area
    Remote work
    Night shift

    Chime

    San Francisco, CA
    a month ago
  • $60 per hour

     ...Job Description Job Description FocusKPI is seeking a  Senior Offensive Security Engineer (Web & AI systems)  to join one of our clients, a high-tech SaaS company.  Team is looking for a Senior Offensive Security Engineer to proactively identify, exploit, and help... 
    Contract work
    Work at office

    FocusKPI Inc.

    Mountain View, CA
    13 days ago
  • $160k - $230k

     ...Astranis satellites provide dedicated, secure networks to highly-sophisticated customers...  ...Fidelity, and employs a team of 450 engineers and entrepreneurs. Astranis designs, builds...  ...in Northern California, USA. SENIOR OFFENSIVE SECURITY ENGINEER As a Senior... 
    Permanent employment
    Flexible hours

    Astranis

    San Francisco, CA
    2 days ago
  • $96k - $181k

     ...associated efforts are to promote and advance an information security processes, culture and must reflect compliance with best...  ...through proactive threat centric defense. The Senior Offensive Security Engineer is a key member of the Cyber Defense Cyber Adversary and Exposure... 
    Work experience placement
    Work at office
    Remote work
    Flexible hours

    Key Bank

    Brooklyn, OH
    2 days ago
  •  ...products and services as part of our ongoing commitment to democratize access to investing and financial planning. The Offensive Security Engineer scopes, designs and executes controlled cybersecurity offensive operations, penetration tests and threat adversary... 
    Work at office
    Remote work

    Charles Schwab

    Encino, CA
    17 hours ago
  •  ...backup Designing a flexible and distributed electrical grid The Role We are looking for a hands-on individual with an offensive security engineering mindset to join us as a Senior Offensive Security Engineer (Threat & Response) as part of the Security team at SPAN. In... 
    Work at office
    Flexible hours

    SPAN Inc

    San Francisco, CA
    2 days ago
  •  ...Cybersecurity Engineer webAI is pioneering the future of artificial intelligence by establishing...  ...an end-to-end platform that is secure, scalable, and fully under the control...  ...Cybersecurity Engineer who combines an offensive security mindset with deep expertise in... 
    Live out
    Work at office
    Local area
    Flexible hours

    Webai

    Austin, TX
    1 day ago
  •  ...Senior Offensive Security Engineer Singapore About BitMEX BitMEX stands as a globally leading exchange for crypto derivatives, offering traders a professional-grade trading platform. Since its inception in 2014, BitMEX has maintained an impeccable security record... 
    Permanent employment
    Remote work
    Flexible hours

    BitMEX

    United States
    17 hours ago
  • $170k - $185k

     ...Senior Offensive Security Engineer Title: Senior Offensive Security Engineer Reports to: Director, Product Security and Incident Response Location: Remote Compensation Range: $170,000.00 to $185,000.00 base plus bonus and equity What We Do: Cybercrime... 
    Full time
    Remote work
    Worldwide
    Home office

    Huntress

    United States
    1 day ago
  •  ...Information Security Professional Crane Company is seeking an Information Security professional to join its Global Information Security...  ...of system and network administration. Prior experience in offensive security is required. In this role, the successful... 
    Work experience placement
    Local area
    Remote work

    Crane Co.

    Stamford, CT
    17 hours ago
  •  ...Senior Offensive Security Engineer Are you an experienced Senior Offensive Security Engineer that wants to work with cutting-edge cybersecurity technologies and contribute to enhancing our overall security posture? At Ivanti, we work passionately and authentically,... 
    Work at office
    Remote work
    Flexible hours

    Ivanti

    United States
    1 day ago
  • £76.5k - £90k per year

     ...Senior Offensive Security Engineer Cardiff, London or Remote (UK) We're on a mission to make money work for everyone. We're waving goodbye to the complicated and confusing ways of traditional banking. After starting as a prepaid card, our product offering has... 
    Work at office
    Remote work
    Work from home
    Flexible hours

    Monzo Bank

    United States
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to WebApp Offensive Security Engineer. Be the first to apply!