Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer

$196k - $242k

GrabJobs

Get to Know Us Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results. Summary We're looking for a Webapp Offensive Security Engineer with deep, hands-on web application penetration testing experience to push our autonomous testing beyond what it can do today. You'll be testing real customer web applications — not just labs and benchmarks — using NodeZero as your starting point and then going further as the human expert: hunting the edge cases, novel attack chains, and business-logic flaws that automated testing doesn't yet handle, proving them out safely against live targets, and working shoulder-to-shoulder with our software engineers to turn each discovery into durable product coverage that benefits every customer. This is a pentesting-first role. You won't be expected to architect platform internals or ship production features yourself — you'll be the offensive expert who tests live customer applications, finds the gaps NodeZero doesn't yet cover, demonstrates them, defines what "good" looks like, and partners with engineering to close them. If you love breaking real web apps by hand, get satisfaction from finding what scanners miss, and want your tradecraft to scale to thousands of customers through the product, this role is for you. Essential Functions Perform hands-on, full-scope web application penetration tests against real customer applications, alongside benchmark and lab targets, to surface vulnerabilities and attack paths. Review NodeZero results on live customer engagements to identify coverage gaps, blind spots, and missed opportunities — the edge cases and corner-case attack scenarios that autonomous testing doesn't yet handle. Manually reproduce and validate those edge cases, building reliable, production-safe proof-of-concept exploits and clear test cases that demonstrate the gap end to end — including against live customer environments without disrupting them. Partner closely with software engineers to translate your findings into product improvements — defining detection logic, attack content, expected behavior, and remediation so NodeZero handles those cases going forward. Build and maintain a library of regression and benchmark test cases so newly added coverage doesn't silently regress over time. Monitor production pentests for missed findings and false positives; create and triage Jira tickets to drive issues to resolution. Work directly with customers and internal teams to investigate findings, explain attack paths, and address questions about web application coverage and results. Author technical blog posts and research write-ups showcasing new exploits, edge cases, and attack methodologies. Mentor teammates and contribute to continuous improvement of team processes, methodology, and testing standards. Competencies/Requirements Extensive hands-on experience conducting full-scope web application penetration tests. Deep, practical knowledge of common and not-so-common web vulnerability classes — SQL injection, XSS (reflected, stored, and DOM-based), SSRF, SSTI/CSTI, IDOR/BOLA, authentication and authorization bypass, path traversal, LFI, and similar — including how to chain them to demonstrate impact. A talent for finding and exploiting business-logic and edge-case flaws that automated scanners routinely miss. Strong command of proxy tools like Burp Suite and browser developer tools. Comfort scripting to reproduce findings and build proof-of-concept exploits (e.g., Python or similar) — you don't need to be a professional software engineer, but you should be able to write and read code well enough to demonstrate an exploit and collaborate effectively with engineers. Ability to clearly communicate attack steps, impact, and remediation guidance to both engineers and non-technical stakeholders. Curiosity about emerging AI technologies and comfort using AI-assisted tools in your testing and research workflow. Strong written and verbal communication, including technical documentation. Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels. Quick to learn and adopt new technologies, frameworks, and target stacks as needed. History of recognized security research, including documented CVE discoveries and responsible disclosure. Track record of successful bug bounty contributions. Desired/Nice to Have Familiarity with how autonomous, agentic, or AI-driven pentesting tools work — and a sharp instinct for where and why they fail. Experience writing detection or attack content (e.g., Nuclei templates, sqlmap tamper scripts, custom Burp extensions). Enough software development background to collaborate fluently with engineers on remediation and product coverage. Familiarity with relational and graph databases, particularly Postgres and Neo4j. Experience with AI/LLM tools for building agentic workflows (e.g., LangChain, LangFlow) and integrating contextual data using protocols like Model Context Protocol (MCP). Expectations: Outstanding problem-solving aptitude and a relentless curiosity for how things break. Self-motivated and highly energetic, with the ability to operate effectively with limited supervision and guidance. Work with our engineers and security researchers to turn manual discoveries into reliable, production-safe product capabilities. Strong technical documentation and communication skills. Document findings, methodologies, and recommendations for both technical and non-technical stakeholders. What makes you stand out: A portfolio of novel web application research, exploits, or edge-case findings you can walk us through. Demonstrated examples of using AI to enhance or accelerate your testing and exploit development. OSCP, OSWE, or comparable offensive security certifications. Perks of Horizon3.ai Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive. Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities. Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking. Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence. Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave. Compensation and Values At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations. In accordance with various State’s transparency regulations, we provide the following salary range information for this position: Base salary range: $196,000 - $242,000. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills. Additional compensation: All full-time roles are eligible for an equity package in the form of stock options. You Belong Here Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law. Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth. We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless. Other Duties Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Security Engineer in San Francisco, CA vacancy
  • $200k - $220k

     ...employees, their laptops, their identities, and the SaaS apps they rely on every day.We are looking for a hands-on Corporate Security Engineer to own and improve the technical controls that keep our workforce and corporate environment safe. This is a security engineering... 
    Suggested
    Work at office
    Local area

    Notion Labs

    San Francisco, CA
    4 days ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleThis is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll be building the security foundations that protect the AI systems... 
    Suggested
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    3 days ago
  • $234.4k - $385k

     ...artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are...  ...engaging a robust security culture. About the RoleAs a Security Engineer, Application Security you will be responsible for identifying and... 
    Suggested
    Work at office
    Remote work
    Relocation package
    Flexible hours

    OpenAI

    San Francisco, CA
    3 days ago
  • $237.6k - $297k

    We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Suggested
    Full time

    Scale AI

    San Francisco, CA
    3 days ago
  • $230k - $385k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...security culture.About the RoleOpenAI is seeking a Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec protects... 
    Suggested
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    4 days ago
  • $165k - $200k

     ...single API, Merge Agent Handler, which empowers AI agents with secure access to thousands of third-party tools, and Merge Gateway,...  ...product development, unblock sales, reduce customer churn, and save engineering resources—allowing them to focus on their core product.Merge... 
    Full time
    Work at office
    Home office

    Merge API

    San Francisco, CA
    7 hours ago
  •  ...offices in New York, Washington D.C., London and Amsterdam.The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s...  ..., and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code... 
    Work experience placement
    Work at office
    Local area
    Shift work

    Plaid Financial

    San Francisco, CA
    2 days ago
  • $237.6k - $297k

    We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering — you won't just investigate incidents, you'll build the... 
    Full time

    Scale AI

    San Francisco, CA
    1 day ago
  • $180k - $258k

     ...today!Curious to learn more about our story? Check out this blog post written by our founders. The RoleWe're looking for a Senior Security Engineer who is ready to elevate the safety and security of our systems and networks. You will serve as our guardian, ensuring our... 
    Flexible hours

    Candid Health

    San Francisco, CA
    4 days ago
  • $153k - $376k

     ...together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us!As a Security Engineer you will identify and drive impactful projects to improve the security of Figma’s product, platform, and IT systems. We are... 
    Minimum wage
    Full time
    Local area
    Remote work
    Flexible hours

    Figma

    San Francisco, CA
    4 days ago
  •  ...Modernisation, and Industry-Specific Software Solutions, DXC modernises, secures, and operates some of the world’s most complex technology...  ...and New Zealand market, we are enhancing the Security Engineering Team who work within the Secured Infrastructure capacity to deliver... 
    Full time
    Local area

    DXC Technology

    Brisbane, CA
    2 days ago
  • $208k - $312k

     ...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering...  ...what comes next.About the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will be... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours
    Shift work

    Vercel

    San Francisco, CA
    1 day ago
  • $122.5k - $165k

     ...everyone is a stakeholder.What you’ll be responsible for:The Circle Security Team works to protect Circle; our customers, clients, and...  ...:2+ years of experience in detection, response, or security engineering.Experience working security incidents, especially those involving... 
    Work experience placement
    Flexible hours
    Shift work
    Night shift

    Circle

    San Francisco, CA
    7 hours ago
  • $146.3k - $257.7k

     ...scalers to join us on our journey to create a better future of work with AI. About the roleJoin WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated... 
    Full time
    Work at office
    Local area

    Writer

    San Francisco, CA
    2 days ago
  • Factory is seeking a talented Security Engineer to join our team. In this role, you will play a critical role in developing and maintaining the security foundation of our platform. You will conduct in-depth code reviews, implement security best practices, and influence... 
    Work at office

    The San Francisco AI Factory

    San Francisco, CA
    4 days ago
  • $200k - $330k

     ...product and design teams for Google Workspace. What you'll doLead Security for Our Platform. Take charge of application, cloud, network,...  ...Collaborate with Cross-Functional Teams. Partner closely with engineering, product, and GRC to embed security throughout the software... 
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    4 days ago
  •  ...Persona builds identity verification infrastructure where security isn't a layer we add later, it's core to everything we ship. When...  ...generalist security team. You'll work alongside experienced security engineers to defend Persona's people, devices, and systems against... 
    Full time
    For contractors
    Internship
    Work at office
    Work from home
    Relocation package
    Monday to Friday
    Flexible hours

    Persona Identities, Inc

    San Francisco, CA
    4 days ago
  • $347k

     ...that artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products. We are...  ...culture.About the RoleOpenAI is seeking a Principal Security Engineer to join our Infrastructure Security (InfraSec) team. InfraSec... 
    Work at office
    Local area
    Flexible hours

    OpenAI

    San Francisco, CA
    1 day ago
  • $148.5k - $260.1k

     ...! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceSalesforce Enterprise Security is hiring a Senior and Lead Security Engineer for our Secure AI team to help assess and maintain the security of using AI tooling securely.In this role,... 
    Full time

    Salesforce

    San Francisco, CA
    3 days ago
  • $188.75k - $242.68k

     ...Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Security Engineering is the engineering function inside the Plaid security org that focuses on developing the industry-leading security systems... 
    Work experience placement
    Local area

    Plaid Financial

    San Francisco, CA
    7 hours ago
  • $175k - $220k

    About the RoleWe are looking for a highly technical Senior Security Engineer who is passionate about protecting data across modern SaaS, cloud, endpoint, and analytics environments.This role is ideal for someone who enjoys solving complex data security challenges through... 
    Full time
    Work at office

    Sigma Computing

    San Francisco, CA
    2 days ago
  •  ...Giga Security Engineer Opportunity Giga has recently raised a $61M Series A and has several paying customers, including DoorDash. We're building the next generation of customer experience — real-time AI agents that can understand emotion, resolve issues instantly, and... 

    Giga AI, Inc.

    San Francisco, CA
    1 day ago
  •  ...Security Engineering @ Clay We're building a modern security organization from the ground up. We're hiring senior or staff-level security engineers who are strong software engineers first, with deep expertise in either Cloud Security or Application Security and working... 
    Flexible hours

    clay.global

    San Francisco, CA
    3 days ago
  •  ...on most by unifying people, spaces, and communications in one secure, integrated workplace management platform and ecosystem. More...  ...technical direction, leading large-scale initiatives, and shaping engineering strategy across organizations. About the role We are building... 
    Work at office
    Local area
    Monday to Thursday
    Shift work

    Envoy

    San Francisco, CA
    3 days ago
  •  ...Description Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical...  ...meaningful impact on our growth. We are looking for a Security Engineer to join our MDR team as the founding U.S. member of the... 
    Night shift
    Weekend work

    Upwind Security

    San Francisco, CA
    5 days ago
  •  ...captivate, and inspire audiences. Learn more at Visit our Mission and Culture doc here. Position Summary As a Security Engineer at HeyGen, you will own the security posture of one of the fastest-growing AI companies in the world. You will partner... 

    HeyGen

    San Francisco, CA
    3 days ago
  • $200k - $275k

    A leading technology firm in San Francisco is seeking a Staff Software Engineer focused on Product Security. This role involves building secure frameworks, resolving security risks, and collaborating with teams to ensure best practices in security. The ideal candidate... 

    Peregrine Technologies

    San Francisco, CA
    3 days ago
  • $100k - $150k

     ...A technology venture firm is seeking a Founding Member of Technical Staff (Security) in San Francisco. In this hybrid role, you will lead security research and vulnerability testing on real-world software. Ideal candidates should have strong skills in web application... 

    Crane Venture Partners

    San Francisco, CA
    3 days ago
  •  ...A fintech company in San Francisco is looking for a Security-Focused DevOps Engineer for a full-time, in-person position. The role involves securing payment infrastructure, building CI/CD pipelines, and conducting security audits. Candidates should have over 4 years of... 
    Full time

    EmberPay Inc.

    San Francisco, CA
    3 days ago
  •  ...on administration instead of care. If you want to help change that, apply below. About the role We are looking for a Security Engineer to help build and strengthen security foundations from the ground up in a fast-moving startup environment. This is a strong opportunity... 
    Work at office
    Immediate start
    Flexible hours
    Shift work

    Assort Health

    San Francisco, CA
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!