WebApp Offensive Security Engineer
$196,000–$242,000 year
Remote · United States
Job Summary
WebApp Offensive Security Engineer responsible for hands-on, full-scope web application penetration testing on live customer applications, identifying coverage gaps in NodeZero autonomous testing, and providing production-ready demonstrations of edge-case attack paths. You will reproduce edge cases with reliable proof-of-concept exploits, partner with software engineers to translate findings into product improvements, build and maintain regression test content, and mentor teammates while documenting methodologies and recommendations for technical and non-technical stakeholders. The role emphasizes pentesting-first activities, collaboration with engineers to close gaps, and contributing to the evolution of testing standards and processes.
Required Qualifications
- Extensive hands-on experience conducting full-scope web application penetration tests
- Deep knowledge of web vulnerabilities (SQLi, XSS, SSRF, SSTI/CSTI, IDOR/BOLA, authentication/authorization bypass, path traversal, LFI) and chaining them to demonstrate impact
- Ability to reproduce edge cases and build proof-of-concept exploits
- Strong communication of attack steps, impact, and remediation to engineers and non-technical stakeholders
- Experience with Burp Suite and browser developer tools
- Proficiency in scripting (e.g., Python) to reproduce findings and collaborate with engineers
- Experience documenting findings, methodologies, and recommendations
- Track record of responsible disclosure and bug bounty contributions
- Curiosity about AI technologies and comfort using AI-assisted tools in testing workflow
- Experience mentoring teammates and contributing to process improvements
- Familiarity with AI/LLM tools for agentic workflows (LangChain, LangFlow) and Model Context Protocol (MCP)
Apply with one swipe on Sorce. We auto-fill applications and apply on your behalf — no cover letters, no 40-minute forms.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.