Security Engineer
$196k - $242kGrabJobs
Get to Know Us Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results. Summary We're looking for a Webapp Offensive Security Engineer with deep, hands-on web application penetration testing experience to push our autonomous testing beyond what it can do today. You'll be testing real customer web applications — not just labs and benchmarks — using NodeZero as your starting point and then going further as the human expert: hunting the edge cases, novel attack chains, and business-logic flaws that automated testing doesn't yet handle, proving them out safely against live targets, and working shoulder-to-shoulder with our software engineers to turn each discovery into durable product coverage that benefits every customer. This is a pentesting-first role. You won't be expected to architect platform internals or ship production features yourself — you'll be the offensive expert who tests live customer applications, finds the gaps NodeZero doesn't yet cover, demonstrates them, defines what "good" looks like, and partners with engineering to close them. If you love breaking real web apps by hand, get satisfaction from finding what scanners miss, and want your tradecraft to scale to thousands of customers through the product, this role is for you. Essential Functions Perform hands-on, full-scope web application penetration tests against real customer applications, alongside benchmark and lab targets, to surface vulnerabilities and attack paths. Review NodeZero results on live customer engagements to identify coverage gaps, blind spots, and missed opportunities — the edge cases and corner-case attack scenarios that autonomous testing doesn't yet handle. Manually reproduce and validate those edge cases, building reliable, production-safe proof-of-concept exploits and clear test cases that demonstrate the gap end to end — including against live customer environments without disrupting them. Partner closely with software engineers to translate your findings into product improvements — defining detection logic, attack content, expected behavior, and remediation so NodeZero handles those cases going forward. Build and maintain a library of regression and benchmark test cases so newly added coverage doesn't silently regress over time. Monitor production pentests for missed findings and false positives; create and triage Jira tickets to drive issues to resolution. Work directly with customers and internal teams to investigate findings, explain attack paths, and address questions about web application coverage and results. Author technical blog posts and research write-ups showcasing new exploits, edge cases, and attack methodologies. Mentor teammates and contribute to continuous improvement of team processes, methodology, and testing standards. Competencies/Requirements Extensive hands-on experience conducting full-scope web application penetration tests. Deep, practical knowledge of common and not-so-common web vulnerability classes — SQL injection, XSS (reflected, stored, and DOM-based), SSRF, SSTI/CSTI, IDOR/BOLA, authentication and authorization bypass, path traversal, LFI, and similar — including how to chain them to demonstrate impact. A talent for finding and exploiting business-logic and edge-case flaws that automated scanners routinely miss. Strong command of proxy tools like Burp Suite and browser developer tools. Comfort scripting to reproduce findings and build proof-of-concept exploits (e.g., Python or similar) — you don't need to be a professional software engineer, but you should be able to write and read code well enough to demonstrate an exploit and collaborate effectively with engineers. Ability to clearly communicate attack steps, impact, and remediation guidance to both engineers and non-technical stakeholders. Curiosity about emerging AI technologies and comfort using AI-assisted tools in your testing and research workflow. Strong written and verbal communication, including technical documentation. Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels. Quick to learn and adopt new technologies, frameworks, and target stacks as needed. History of recognized security research, including documented CVE discoveries and responsible disclosure. Track record of successful bug bounty contributions. Desired/Nice to Have Familiarity with how autonomous, agentic, or AI-driven pentesting tools work — and a sharp instinct for where and why they fail. Experience writing detection or attack content (e.g., Nuclei templates, sqlmap tamper scripts, custom Burp extensions). Enough software development background to collaborate fluently with engineers on remediation and product coverage. Familiarity with relational and graph databases, particularly Postgres and Neo4j. Experience with AI/LLM tools for building agentic workflows (e.g., LangChain, LangFlow) and integrating contextual data using protocols like Model Context Protocol (MCP). Expectations: Outstanding problem-solving aptitude and a relentless curiosity for how things break. Self-motivated and highly energetic, with the ability to operate effectively with limited supervision and guidance. Work with our engineers and security researchers to turn manual discoveries into reliable, production-safe product capabilities. Strong technical documentation and communication skills. Document findings, methodologies, and recommendations for both technical and non-technical stakeholders. What makes you stand out: A portfolio of novel web application research, exploits, or edge-case findings you can walk us through. Demonstrated examples of using AI to enhance or accelerate your testing and exploit development. OSCP, OSWE, or comparable offensive security certifications. Perks of Horizon3.ai Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive. Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities. Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking. Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence. Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave. Compensation and Values At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations. In accordance with various State’s transparency regulations, we provide the following salary range information for this position: Base salary range: $196,000 - $242,000. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills. Additional compensation: All full-time roles are eligible for an equity package in the form of stock options. You Belong Here Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, or any other legally protected status by law. Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth. We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless. Other Duties Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
- ...all. Toll Brothers, America's leading luxury home builder, seeks a Security Engineerto join our team at our Corporate office in Fort Washington, Pennsylvania.What is the opportunity?The Security Engineer is a technical resource on the Cyber & Information Security team....SuggestedFull timeWork at officeLocal area
$104k - $156k
Posting Type Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational backbone of the enterprise security function. Operating within a layered defense-in-depth program, this engineer owns the design...SuggestedRemote work- ...us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Security Engineer- Hybrid to join our team in Fort Washington, Pennsylvania (US-PA), United States (US).The Security Engineer is a hands-on...SuggestedWork at officeLocal areaRemote workFlexible hours
- ...exceptional place to work that is inclusive to all. Toll Brothers , America's leading luxury home builder, seeks a Security Engineer to join our team at our Corporate office in Fort Washington, Pennsylvania. What is the opportunity? The Security Engineer...SuggestedWork at officeLocal area
- ...an accredited college or university. At least a secret level security clearance that is current and activeAbility to work onsite in... ...2005. We provide full life cycle system development, systems engineering, cybersecurity, and supporting analytical and logistics support...Suggested
$90k - $130k
Taxable EntityRED PEAK TECHNICAL SERVICES LLCJob TitleInformation Systems Security Engineer ILocationPA Philadelphia NSWC - Philadelphia, PA 19112 US (Primary)CategoryIT and Computer RelatedJob TypeFull-timeTypical Pay/Range$90,000 to $130,000 AnnuallyEducationBachelor'...Contract workLocal area- ...NYSE: TIC) is a leading provider of compliance, technology, and engineering consulting solutions. Professional Systems Engineering (PSE)... ...across a broad spectrum of disciplines, including electronic security, audiovisual, IT/tele/data communications, and fire systems. PSE...Full timeFor contractorsWork at officeLocal areaFlexible hoursNight shift
- ...Pennsylvania100% RemoteFull Time$140k - $150kJoin a leading organization at the forefront of industrial cybersecurity as an OT Security Engineer. This full-time opportunity is ideal for security professionals who are passionate about protecting critical infrastructure...Full timeRemote workFlexible hours
$117.17k - $175.76k
...SummaryThis job is responsible for executing and advancing the security posture of Comcast’s core network platforms through secure... ...assigned network environments, partnering with architecture, engineering, cybersecurity, compliance, operations, and vendor teams to validate...Full timeWork at officeRemote workWorldwide- ...Job Title: Information System Security Engineer (ISSE) III Location: Philadelphia, PA Clearance: Secret Company/ Program Description: Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions...Full timeInterim role
$105.4k - $207.8k
Position Summary Cisco Network Security Engineer/ Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a creative...Work experience placementLocal areaVisa sponsorship$91.4k - $155k
...structures, we’re helping our clients innovate and grow by designing, engineering, and executing the construction of their state-of-the-art... ...sustainable.Become part of our team as a Telecommunications & Security Systems Engineer in PA, OH, IN, NC, TX, VA excited about...Full timeRemote work$77k - $202k
...SectorNot ApplicableSpecialismManaged ServicesManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs an AWS Security Engineer - Senior Associate, you will play a crucial role in designing and implementing secure IT systems that support business...Full timeH1b$85k - $100k
...Description Information System Security Engineer The GBS Group has an exciting opportunity for an ISSE. You will work both independently and with a team of Engineering and technical professionals at NAVSEA on Information Systems projects related to Naval ship systems...Temporary workImmediate start- ...Lead Information Assurance Systems Engineer-Systems Security Job Code: 23664 Job Location: Camden, NJ Schedule: 9/80 reg, with every other Friday off Job Description: L3Harris Technologies – Integrated C5 Systems (IC5S) is a recognized global leader in the design...
$82.6k - $162.8k
Position Summary Cyber Oracle Cloud Security - Consultant / Security Engineer IIDeloitte’s Cyber team helps organizations address complex cybersecurity challenges while supporting resilient, secure growth. In this role, you will support Oracle Cloud security engagements...Local areaVisa sponsorship- ...Information Technology and Communications consulting, system engineering, integration, deployment and operation of state of the art command... ...Job Summary We are seeking an Information System Security Engineer II (ISSE II) to support a Navy cybersecurity program....Full timeContract workTemporary workWork at officeShift work
$116.1k - $158.2k
...subscription design, governance, and onboarding standardsEstablish engineering standards for identity, networking, monitoring, resiliency,... ...with architecture, infrastructure, networking, and security teams to deliver scalable cloud solutionsEnable and integrate...Full timeContract workLocal areaFlexible hours$82.6k - $162.8k
...with resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental... ...Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer II on the Deloitte Cyber Identity & Access Management team, you...Local areaVisa sponsorship$160k - $240k
...build, operate, and scale onchain infrastructure. The platform secures over €100B in assets and powers critical operations—including key... ...institutions. Our client is seeking a Principal Security Engineer to lead product security across the entire ecosystem. In this role...Full timeLocal areaRemote workFlexible hours$71.6k - $119.4k
...looking to work for a mission driven global organization?About the role - This role supports the offensive security function within Elsevier's Security Engineering team. You will perform hands-on security testing and peer review activities, validate vulnerabilities and...Full timeLocal areaWork from home$82.6k - $162.8k
...our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be responsible for:Supporting the design and...Local areaVisa sponsorship$126.23k - $210.38k
...you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a Lead Security Engineer to join our team in Fort Washington, Pennsylvania (US-PA), United States (US).The Security Engineer is a hands-on technical role...Temporary workWork at officeLocal areaRemote workFlexible hours$134.5k - $265.1k
...remediation outcomes across enterprise environments. You’ll help bridge security findings with operational action by translating exposure data... ...for this role ends on 12/31/2026.Work you'll doAs a Senior Engineering Management Specialist on the Cyber Defense & Resilience...Local area- ...Senior Cloud Security Engineer Location: Whitehouse Station, NJ or Philly - Hybrid Duration: 6 months Job description We are looking for a Senior Cloud Security Engineer with 7+ years of experience and knowledge in engineering security solutions. Essential functions...
- ...Description Job Description Description: US CITIZENSHIP, DoD SECRET SECURITY CLEARANCE IS REQUIRED. If your resume does not clearly state... ...your application. EXPERIENCE for Senior Security Network Engineer position: Eight (8) years’ experience in network security,...
- ...and help us improve the lives of people and animals everywhere. Apply today!Job DetailsThe Principal Engineer, provides strategic and technical leadership for securing Cencora’s operational technology, industrial control systems, distribution center technologies, building...Full timeWork experience placementWork at officeLocal areaRemote work
$82.6k - $162.8k
...growth environment to build your career. In this role, you will support organizations as they modernize security operations through advanced analytics, cyber data engineering, and AI-enabled capabilities. You will work with leading technologies and help clients strengthen...Local areaVisa sponsorship$105.4k - $207.8k
...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ...engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to...Local areaVisa sponsorship$105.4k - $207.8k
...certifications such as Certified Business Continuity Professional, Member of the Business Continuity Institute, Certified Information Systems Security Professional, or Certified Information Security Manager The wage range for this role takes into account the wide range of factors...Local areaVisa sponsorship
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!
- network security engineer Philadelphia, PA
- senior application security engineer Philadelphia, PA
- sr security engineer Philadelphia, PA
- security infrastructure engineer Philadelphia, PA
- entry level security engineer Philadelphia, PA
- senior security operations engineer Philadelphia, PA
- cloud security engineer Philadelphia, PA
- information technology security engineer Philadelphia, PA
- senior cloud security engineer Philadelphia, PA
- information system security engineer Philadelphia, PA


