Horizon3 AI

WebApp Offensive Security Engineer

Horizon3 AI
Apply
3 months ago
Remote, United StatesSenior

Base Salary

$196k - $242k/yr

Responsibilities

  • Conduct full-scope web application penetration tests against live customer applications, benchmark targets, and lab environments.
  • Review NodeZero results to identify coverage gaps, blind spots, missed findings, and edge-case attack scenarios.
  • Reproduce and validate vulnerabilities by building reliable, production-safe proof-of-concept exploits and end-to-end test cases.
  • Partner with software engineers to define detection logic, attack content, expected behavior, remediation, and product improvements.
  • Build and maintain regression and benchmark test cases to prevent coverage regressions.
  • Monitor production penetration tests for missed findings and false positives and create and triage Jira tickets.
  • Work with customers and internal teams to investigate findings, explain attack paths, and answer web application coverage questions.
  • Author technical blog posts and research write-ups about exploits, edge cases, and attack methodologies.
  • Mentor teammates and improve testing standards, methodologies, and team processes.

Requirements

  • Extensive hands-on experience conducting full-scope web application penetration tests.
  • Deep practical knowledge of SQL injection, XSS, SSRF, SSTI/CSTI, IDOR/BOLA, authentication and authorization bypass, path traversal, LFI, vulnerability chaining, and related web vulnerability classes.
  • Ability to identify and exploit business-logic and edge-case flaws that automated scanners miss.
  • Strong command of Burp Suite and browser developer tools.
  • Ability to script proof-of-concept exploits and read and write code well enough to collaborate with engineers, such as using Python.
  • Strong written and verbal communication, including technical documentation for technical and non-technical stakeholders.
  • Ability to manage multiple priorities, work independently, learn new technologies and frameworks, and mentor teammates.
  • History of recognized security research, including documented CVE discoveries and responsible disclosure.
  • Track record of successful bug-bounty contributions.
  • Familiarity with autonomous, agentic, or AI-driven penetration-testing tools and their limitations.
  • Experience writing detection or attack content, such as Nuclei templates, sqlmap tamper scripts, or custom Burp extensions.
  • Enough software development experience to collaborate fluently with engineers on remediation and product coverage.
  • Familiarity with relational and graph databases, particularly Postgres and Neo4j.
  • Experience with AI/LLM tools for agentic workflows, such as LangChain and LangFlow, and contextual-data protocols such as Model Context Protocol.
  • OSCP, OSWE, or comparable offensive security certification is a differentiator.
  • A portfolio of novel web application research, exploits, or edge-case findings and demonstrated use of AI to enhance testing or exploit development are differentiators.

Benefits

  • Remote and hybrid work models depending on role and location, including a Chicago office where some roles require regular in-office presence.
  • Health, vision, and dental insurance for employees and families.
  • Flexible vacation policy.
  • Generous parental leave.
  • Equity package in the form of stock options for full-time roles.
  • Inclusive culture, growth opportunities, and collaborative innovative work environment.

Tech Stack

Categories

Horizon3 AI

About Horizon3 AI

501-1,000 employees

Horizon3 AI builds NodeZero, a proactive security platform that autonomously performs penetration testing and validates attack paths across on‑prem, cloud, and hybrid environments. The company sells its software by subscription to security and IT teams at enterprises and government agencies, helping prioritize and verify fixes. Founded in 2019 and headquartered in San Francisco, it is privately held and serves customers across regulated industries and the public sector.

Contact me