
Senior/Staff Attack Engineer, Rapid Response
Horizon3 AI8 hours ago
Remote, United StatesSenior / Staff+
Base Salary
$230k - $275k/yr
Responsibilities
- Research and reproduce high-consequence vulnerabilities, including CISA KEVs, CVEs, N-Days, and Zero-Days, across enterprise and cloud environments.
- Study attacker tactics, techniques, procedures, and campaigns and convert them into automated attack capabilities.
- Build safe, repeatable proof-of-exploit capabilities, attack paths, and modules for Rapid Response and NodeZero.
- Demonstrate privilege escalation, credential access, lateral movement, persistence, and data access without unnecessary disruption.
- Safely retest vulnerabilities and security controls to validate remediation and containment.
- Improve execution speed, reliability, observability, and evidence quality while collaborating with research, product, and engineering teams.
Requirements
- Strong Python and software engineering skills, including building, testing, and operating production-quality tooling.
- Solid penetration testing, vulnerability research, and exploit-development fundamentals.
- Hands-on experience with enterprise networks, applications, identity systems, cloud environments, or endpoint security.
- Ability to reproduce vulnerabilities and convert manual techniques into reliable automation.
- Understanding of attack chains, trust boundaries, authentication and authorization, privilege escalation, and lateral movement.
- Ability to balance speed, safety, reliability, coverage, and actionable evidence.
- Experience with CISA KEVs, CVE analysis, N-Day or Zero-Day research, responsible disclosure, incident response, threat hunting, purple teaming, or security operations is preferred.
- Experience with AWS, Azure, GCP, Kubernetes, Active Directory, Entra ID, Okta, exploit development, reverse engineering, or malware analysis is preferred.
- Contributions to security research, CVEs, conference talks, open-source tools, or technical publications are preferred.
- CTF experience or equivalent hands-on offensive security practice is preferred.
- A Bachelor’s Degree in Computer Science, Computer Engineering, or a related field is preferred.
- OSCP or equivalent certification is preferred.
Benefits
- Fully remote company with up to 10% travel required.
- Remote and hybrid work models may vary by role and location, including potential regular in-office presence for some Chicago roles.
- Health, vision, and dental insurance for employees and families.
- Flexible vacation policy and generous parental leave.
- Equity package in the form of stock options for all full-time roles.
- Inclusive culture, growth opportunities, and collaborative innovation environment.
Categories
About Horizon3 AI
Horizon3 AI builds NodeZero, a proactive security platform that autonomously performs penetration testing and validates attack paths across on‑prem, cloud, and hybrid environments. The company sells its software by subscription to security and IT teams at enterprises and government agencies, helping prioritize and verify fixes. Founded in 2019 and headquartered in San Francisco, it is privately held and serves customers across regulated industries and the public sector.