Webapp Offensive Security Software Engineer
Design and develop web application offensive security content for NodeZero
Design, develop, and integrate web application offensive security content into the NodeZero platform. You'll work on novel attack capabilities, including AI-enhanced techniques, and extend platform architecture to support new features. This role involves researching AI-driven methods for vulnerability detection and exploitation, and integrating open-source tools while ensuring quality through testing.
Why This Role?
Direct impact on customer value through offensive security advancements
Key Responsibilities
- Design and develop web application offensive security content for the NodeZero platform
- Research and implement AI-driven methods for vulnerability detection and exploitation
- Integrate open-source and in-house tools, ensuring quality through testing
Requirements
- Extensive web application penetration testing experience
- Proven software development skills
- Enthusiasm for leveraging emerging AI technologies
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
Keywords
View Original Description from WeWorkRemotely
Original description from WeWorkRemotely
Headquarters: US, Remote URL: http://horizon3.ai Get to Know Us Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results. Summary We're looking for an Offensive Security Software Engineer with extensive web application penetration testing experience and a growing interest in AI-enhanced security techniques. You will have a significant impact on how we deliver value to our customers by designing, developing, and integrating web application penetration testing content into the NodeZero platform. This position requires practical expertise in full-scope web application testing, proven software development skills, and enthusiasm for leveraging emerging AI technologies to advance offensive security capabilities. Essential Functions Design, develop, and integrate web application offensive security content into the NodeZero platform Design, develop, and integrate novel attack capabilities into the NodeZero platform, including offensive security tooling and AI-enhanced techniques. Research and implement AI-driven methods for vulnerability detection, exploitation, and workflow automation. Extend and maintain platform architecture, data models, and system design to support new product features. Monitor production for issues or missed opportunities and create or resolve Jira tickets as needed. Integrate open-source and in-house tools, ensuring quality through testing, code reviews, and production monitoring. Investigate, own, and resolve bugs in developed content. Collaborate cross-functionally to address customer and prospect concerns related to attack content. Author technical blog posts showcasing new research, exploits, or attack methodologies. Mentor junior engineers and contribute to continuous improvement of team processes and standards Competencies/Requirements Experience conducting full scope web application pentests Experience with proxy tools like Burp and with browser developer tools Proficient in object-oriented programming and test-driven development, with strong analytical and problem-solving skills. Experience applying AI-assisted development tools to security research and automation tasks Curiosity about emerging AI technologies. Skilled in designing, evaluating, and communicating technical solutions across systems, APIs, algorithms, and data structures. Familiarity with relational and graph databases, particularly Postgres and Neo4j. Strong written and verbal communication, including technical documentation. Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels. Quick to learn and adopt new technologies as needed. History of recognized security research, including documented CVE discoveries and responsible disclosure Track record of successful bug bounty contributions Desired/Nice to Have Experience developing software and automation to aid in web application pentestin
Hiring in only
This employer appears to hire only in the region above. Confirm you're eligible to be hired there before applying.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.