WebApp Offensive Security Software Engineer
Core
Design, develop, and integrate web application penetration testing content and AI-enhanced security techniques into the NodeZero autonomous pentesting platform.
Role type
Senior/Staff Offensive Security Software Engineer (Web App & AI)
Builds
Production-safe autonomous pentesting content, detection logic, and attack exploits for the NodeZero platform
Domain
Cybersecurity, Web Application Security, AI/LLM Security
Deliverable
production ML models | product features
Required skills
Full-scope web application penetration testing, proxy tools (Burp), object-oriented programming, test-driven development, AI-assisted development, relational/graph databases (Postgres, Neo4j), technical documentation, security research (CVEs, bug bounties)
Preferred skills
Software automation for pentesting, large-scale software development, LLM fine-tuning, RAG implementation, agentic workflows (LangChain, LangFlow), Model Context Protocol (MCP)
Technologies
NodeZero, Burp Suite, Postgres, Neo4j, LangChain, LangFlow, MCP
Responsibilities
Perform hands-on web application penetration tests to surface vulnerabilities; review NodeZero results to identify coverage gaps and edge cases; build proof-of-concept exploits and test cases for missed scenarios; partner with engineers to translate findings into product detection logic; maintain regression and benchmark test case libraries; monitor production pentests and triage false positives; mentor teammates and improve testing standards
Seniority
Senior/Staff, hands-on IC with mentorship responsibilities
