> Markdown version of [/jobs/ext/2722514-software-engineer](https://www.wearedevelopers.com/jobs/ext/2722514-software-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Engineer - **Company:** HORIZON 3, LLC - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Expert - **Salary:** $169,000.0 - $208,000.0 - **Contract:** Permanent contract - **Skills:** JavaScript (Programming Language), Artificial Intelligence, Neo4j, Parsing, Web Application Security, Selenium, SQL Injection, TypeScript, Web Applications, WebSocket, Data Logging, Large Language Models, Browserstack, Puppeteer (Software), Cross-Site Scripting (XSS), Playwright - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-software-engineer-browser-automation-horizon3-ai-8400258 ## About the Role * Experience building production software, with deep, hands-on experience in browser automation (Playwright, Puppeteer, or Selenium) against real, non-trivial web applications. * Strong TypeScript / Node.js skills and comfort living inside the headless-browser stack, including Chromium internals, the Chrome DevTools Protocol, network interception, the DOM, and JS execution contexts. * A track record of taming flaky, stateful, JavaScript-heavy apps. You've fought SPA timing, authentication, and anti-automation defenses and won. * Solid instincts for distributed/concurrent systems: queues, backpressure, retries, idempotency, and running many browser sessions reliably at scale. * A bias toward determinism and debuggability, and the judgment to reach for an LLM only when a deterministic approach genuinely can't do the job. * Ownership mentality: you are comfortable taking a critical subsystem from "works" to "works unattended, at scale, against someone else's production environment." Desired/Nice to Have * Experience with agentic browser frameworks (Stagehand, Browser Use, or similar) or building LLM-in-the-loop automation. * Background in web application security or offensive tooling - familiarity with broken access control, IDOR/BOLA, SQLi, XSS, SSRF, or SSTI in the wild. * Familiarity with graph data models (e.g., Neo4j) for representing application structure. * Experience with large-scale crawling, endpoint discovery (e.g., parsing/analyzing client-side JS), or session/credential management for automated access. * Comfort working in an environment where correctness against a live customer system is a hard, non-negotiable constraint. ## Description We're building an autonomous, black-box web application penetration tester. It crawls and attacks real production websites the way a skilled human pentester would, finding broken access control, injection, XSS, and more, under a strict production-safe, no-false-positives mandate. The hardest part of that job isn't the exploitation. The hardest part is reliably driving a real browser through messy, modern web apps at scale: logging in, navigating SPAs, surviving anti-bot defenses, and mapping every reachable surface without getting stuck or causing harm. That's the engine you'd own., * Help us grow and harden our browser automation and crawling engine, which is the layer that discovers, navigates, and interacts with target applications before and during an autonomous pentest. * Advance our browser-driven crawler using Playwright and Stagehand. * Tackle the gnarly realities of modern web apps: SPA routing and hydration timing, authenticated sessions, multi-step flows, file uploads, WebSocket/Socket.IO traffic, infinite scroll, and crawler traps. * Extend our agentic login and authentication capabilities, including complex auth flows, MFA/TOTP, and credentialed access reliable enough to run unattended against customer environments. * Improve crawl coverage, determinism, and throughput. This involves endpoint and parameter discovery, dedupe, queueing, and state management, while keeping everything production-safe and side-effect-aware. * Help draw the line between deterministic automation and LLM-driven navigation, applying models surgically rather than as a default, and keeping the system fast, debuggable, and cheap to run. * Collaborate with the attack-team engineers who consume your crawl output, and help shape the graph-backed application map the rest of the pipeline depends on., * You've gone beyond using tools like Playwright or Puppeteer to actually hacking on their internals or contributing to the core. * You've built browser automation at extreme scale, handling thousands of sessions against hostile, heavily-defended targets. You know exactly how systems break under pressure and have the war stories to prove it. * You've successfully outmaneuvered sophisticated WAFs, anti-bot defenses, and fingerprinting mechanisms in production environments. * You have an offensive security mindset: you don't just navigate a web app; you actively map its attack surface and hunt for unreachable paths. * You have battle-tested experience with LLMs in production. You understand the engineering trade-offs: knowing when AI is an asset and when it introduces unacceptable latency or nondeterminism compared to a deterministic script. Perks of Horizon3.ai * Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive. * Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities. * Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking. * Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence. ## Related Videos - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Putting the Graph In GraphQL With The Neo4j GraphQL Library](https://www.wearedevelopers.com/videos/257-putting-the-graph-in-graphql-with-the-neo4j-graphql-library) - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [Proactive monitoring and smoke testing in your production environment](https://www.wearedevelopers.com/videos/139-proactive-monitoring-and-smoke-testing-in-your-production-environment) - [But, you're not Facebook](https://www.wearedevelopers.com/videos/378-but-you-re-not-facebook) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 113 - Debugging above the cloud](https://www.wearedevelopers.com/magazine/422-dev-digest-113-debugging-above-the-cloud) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 106 - DHH in HD](https://www.wearedevelopers.com/magazine/394-dev-digest-106-dhh-in-hd)