
Staff Attack Engineer, AI/LLM
Horizon3 AI5 months ago
Remote, United StatesStaff+
Base Salary
$223k - $275k/yr
Responsibilities
- Research and break AI and agentic systems, translating findings into automated, repeatable attack modules for NodeZero.
- Design prompt-injection, defense-evasion, tool-use exploitation, model, supply-chain, and AI-infrastructure attacks.
- Exploit agent access to code, file systems, APIs, and databases to produce attacker-realistic outcomes such as context poisoning, remote code execution, data exfiltration, and privilege escalation.
- Threat-model agentic systems by mapping trust boundaries and attack surfaces into concrete attack paths.
- Productize manual offensive techniques into safe, reliable, and scalable automated tooling.
- Build and extend LLM-powered applications using prompting, structured output, and agentic workflows.
- Design and extend microservices that orchestrate LLM tasks and integrate with NodeZero and offensive workflows.
- Provide technical leadership for AI/LLM offensive capabilities and set strategy for complex, high-risk programs.
Requirements
- Expert-level Python and software engineering skills.
- Solid penetration-testing fundamentals and knowledge of common attack chains.
- Experience breaking AI/LLM and agentic systems and systematically testing their trust boundaries, data sources, and permissions.
- Familiarity with AI/LLM security frameworks such as OWASP Top 10 for LLMs and MITRE ATLAS.
- Experience in a security product or offensive security team, ideally with shipped offensive capabilities or tooling.
- Ability to drive high-complexity, high-risk programs and set strategy.
- Experience with cloud AI services such as Azure OpenAI or GCP Vertex AI is preferred.
- Experience with AWS Bedrock, AWS Agent Core, graph databases such as Neo4j, exploit development, vulnerability research, or AI/ML-focused CTFs is preferred.
- Contributions to AI security research through blog posts, conference talks, CVEs, or open-source tools are preferred.
Benefits
- 100% remote work arrangement.
- Health, vision, and dental insurance for employees and families.
- Flexible vacation policy.
- Generous parental leave.
- Equity package in the form of stock options for full-time roles.
- Inclusive culture and career development opportunities.
Tech Stack
Neo4jPython
Categories
About Horizon3 AI
Horizon3 AI builds NodeZero, a proactive security platform that autonomously performs penetration testing and validates attack paths across on‑prem, cloud, and hybrid environments. The company sells its software by subscription to security and IT teams at enterprises and government agencies, helping prioritize and verify fixes. Founded in 2019 and headquartered in San Francisco, it is privately held and serves customers across regulated industries and the public sector.