Horizon3 uses real-world attacks to safely show what attackers can actually do in your environment—so you can fix and prove what matters. Backed by NEA.
About the role
We're looking for a Staff Attack Engineer to be the technical lead for internal network and Active Directory attack capabilities in NodeZero, our autonomous pentesting platform.
What they're looking for
- Deep, hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold through domain and enterprise compromise
- Command of current AD tradecraft: credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, and lateral movement and persistence
- Demonstrated experience attacking modern, hardened environments (NTLM deprecation and enforced signing, Kerberos-only, tiered administration)
- Strong software engineering fundamentals with expert-level Python, and a track record of shipping and maintaining production-quality code, not just scripts and proofs of concept
- Ability to independently research unfamiliar systems and technologies and rapidly become the team's expert
- A track record of technical leadership: setting direction, driving high-complexity and high-risk work, and mentoring other engineers
More about this role
Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.
We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.
We're looking for a...
Browse similar: AI jobs · AI startup jobs · Startup jobs · Remote jobs