
Staff Attack Engineer, AI/LLM
Horizon3 AIBase Salary
$223k - $275k/yr
Responsibilities
- Research and break AI and agentic systems, translating findings into automated, repeatable attack modules for NodeZero.
- Design prompt-injection, defense-evasion, tool-use exploitation, model, supply-chain, and AI-infrastructure attacks.
- Exploit agent access to code, file systems, APIs, and databases to produce attacker-realistic outcomes such as context poisoning, remote code execution, data exfiltration, and privilege escalation.
- Threat-model agentic systems by mapping trust boundaries and attack surfaces into concrete attack paths.
- Productize manual offensive techniques into safe, reliable, and scalable automated tooling.
- Build and extend LLM-powered applications using prompting, structured output, and agentic workflows.
- Design and extend microservices that orchestrate LLM tasks and integrate with NodeZero and offensive workflows.
- Provide technical leadership for AI/LLM offensive capabilities and set strategy for complex, high-risk programs.
Requirements
- Expert-level Python and software engineering skills.
- Solid penetration-testing fundamentals and knowledge of common attack chains.
- Experience breaking AI/LLM and agentic systems and systematically testing their trust boundaries, data sources, and permissions.
- Familiarity with AI/LLM security frameworks such as OWASP Top 10 for LLMs and MITRE ATLAS.
- Experience in a security product or offensive security team, ideally with shipped offensive capabilities or tooling.
- Ability to drive high-complexity, high-risk programs and set strategy.
- Experience with cloud AI services such as Azure OpenAI or GCP Vertex AI is preferred.
- Experience with AWS Bedrock, AWS Agent Core, graph databases such as Neo4j, exploit development, vulnerability research, or AI/ML-focused CTFs is preferred.
- Contributions to AI security research through blog posts, conference talks, CVEs, or open-source tools are preferred.
Benefits
- 100% remote work arrangement.
- Health, vision, and dental insurance for employees and families.
- Flexible vacation policy.
- Generous parental leave.
- Equity package in the form of stock options for full-time roles.
- Inclusive culture and career development opportunities.
Tech Stack
Categories
About Horizon3 AI
Horizon3.ai answers the two most important questions in cybersecurity: If someone tried to compromise us, would we hold up? And, how do we withstand the onslaught of AI-powered attacks? Horizon3.ai’s NodeZero® shifts the advantage from attackers to defenders by giving organizations the power to fight AI with AI. The Proactive Security Platform autonomously tests your defenses at machine speed, safely finds and prioritizes exploitable attack paths, instantly verifies fixes, and drives a continuous loop so you can prove you’re resilient, not just hope you are. NodeZero, the World’s Best AI Hacker™, was built by an elite team of U.S. cyber veterans and has honed its skills over 225K production-safe tests, more than all manual pentests in history. More than 5,000 organizations including the NSA, CISA, Fortune 100 giants, and major healthcare providers trust Horizon3.ai to prioritize what matters and prove they’re ready for what’s next. Horizon3.ai has been recognized by Fast Company as one of the World’s Most Innovative Companies in 2026. The company ranked #3 overall on the 2025 Deloitte Technology Fast 500 and was named the #1 cybersecurity company on the Inc. 5000 in 2025. It has also been named to the Fortune Cyber 60 in both 2023 and 2025 and is a two-time Black Unicorn Award winner.