Назад
Company hidden
2 месяца назад

Webapp Offensive Security Engineer (Cybersecurity)

196 000 - 242 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Webapp Offensive Security Engineer (Cybersecurity): Conducting hands-on web application penetration testing to identify complex vulnerabilities and edge cases with an accent on manual exploitation and business-logic flaws. Focus on partnering with software engineers to translate manual findings into durable, autonomous product coverage for the NodeZero platform.

Location: Must be based in the US

Salary: $196,000–$242,000

Company

hirify.global is a cybersecurity company providing autonomous pentesting solutions to help organizations proactively identify and verify exploitable attack vectors.

What you will do

  • Perform full-scope manual web application penetration tests against live customer environments.
  • Identify coverage gaps and blind spots in the autonomous NodeZero platform.
  • Develop production-safe proof-of-concept exploits to demonstrate complex attack chains.
  • Collaborate with software engineers to define detection logic and improve product coverage.
  • Maintain a library of regression and benchmark test cases to ensure long-term product quality.
  • Author technical research and blog posts regarding new exploits and attack methodologies.

Requirements

  • Must be based in the US
  • Extensive hands-on experience conducting full-scope web application penetration tests.
  • Deep practical knowledge of web vulnerability classes like SQLi, XSS, SSRF, IDOR, and auth bypass.
  • Strong proficiency with proxy tools such as Burp Suite and browser developer tools.
  • Ability to script proof-of-concept exploits using Python or similar languages.
  • Proven history of security research, CVE discoveries, or bug bounty contributions.

Nice to have

  • Experience with autonomous or AI-driven pentesting tools.
  • Background in writing detection content like Nuclei templates or custom Burp extensions.
  • Familiarity with Postgres, Neo4j, and AI/LLM agentic workflows.
  • OSCP, OSWE, or comparable offensive security certifications.

Culture & Benefits

  • Competitive salary and equity package in the form of stock options.
  • Comprehensive health, vision, and dental insurance for employees and families.
  • Flexible vacation policy and generous parental leave.
  • Inclusive, collaborative culture that values diversity and continuous learning.
  • Remote-first work model with opportunities for hybrid collaboration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →