Horizon3 AI

Staff Attack Engineer, Internal/AD

Horizon3 AI
Apply
4 hours ago
Remote, United StatesStaff+

Base Salary

$247k - $275k/yr

Responsibilities

  • Lead internal-network and Active Directory attack capabilities across the NodeZero platform as the primary technical subject matter expert.
  • Research emerging Active Directory and internal-network attack techniques and turn them into safe, production-ready attack content.
  • Design, build, and maintain production-grade Python for autonomous attacks at enterprise scale.
  • Develop attacks for hardened environments involving NTLM deprecation, SMB signing, Kerberos-only configurations, tiered administration, LAPS, and managed service accounts.
  • Configure and exploit representative Active Directory test environments for validation, demonstration, and regression testing.
  • Extend attack-path modeling and graph data models for identity, privilege-escalation, and lateral-movement paths.
  • Set research priorities and coverage roadmaps using customer environments, threat intelligence, and emerging techniques.
  • Mentor attack engineers and improve code quality, research rigor, and operational safety.
  • Collaborate with engineering, product management, and customer-facing teams and write technical documentation, blog posts, and external research.

Requirements

  • Deep hands-on offensive experience against Active Directory and internal enterprise networks from initial foothold through domain and enterprise compromise.
  • Expert knowledge of Active Directory tradecraft, including credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, lateral movement, and persistence.
  • Experience attacking modern hardened environments with NTLM deprecation, enforced signing, Kerberos-only configurations, and tiered administration.
  • Expert-level Python and strong software engineering fundamentals with a history of shipping and maintaining production-quality code.
  • Ability to independently research unfamiliar systems and become a subject matter expert.
  • Demonstrated technical leadership in setting direction, driving complex and high-risk work, and mentoring engineers.
  • Strong written and verbal communication skills, including technical documentation.
  • Passion for building offensive security products rather than only identifying vulnerabilities.
  • At least 8 years of combined offensive security and/or software engineering experience, including significant Active Directory and internal-network attack experience.
  • Preferred: OSCP, OSEP, CRTO, or an equivalent offensive security certification.
  • Preferred: experience with SCCM, Windows Admin Center, hybrid identity attacks, Entra ID, Entra Connect, primary refresh tokens, seamless SSO, and on-premises-to-cloud pivots.
  • Preferred: contributions to BloodHound, Impacket, netexec, or similar offensive tooling.
  • Preferred: familiarity with Neo4j and attack-path analysis.
  • Preferred: experience integrating security research into production multi-tenant SaaS or building production-safe autonomous offensive tooling.
  • Preferred: public contributions through open-source tools, technical articles, conference talks, or published CVEs.

Benefits

  • Fully remote work arrangement, with up to 10% travel required.
  • Health, vision, and dental insurance for employees and their families.
  • Flexible vacation policy and generous parental leave.
  • Equity package in the form of stock options for full-time roles.
  • Inclusive, collaborative culture with career development opportunities.
  • Hybrid and remote work models may vary by role and location, including possible regular in-office presence in Chicago.

Tech Stack

Neo4jPython

Categories

Horizon3 AI

About Horizon3 AI

201-500 employees

Horizon3.ai answers the two most important questions in cybersecurity: If someone tried to compromise us, would we hold up? And, how do we withstand the onslaught of AI-powered attacks? Horizon3.ai’s NodeZero® shifts the advantage from attackers to defenders by giving organizations the power to fight AI with AI. The Proactive Security Platform autonomously tests your defenses at machine speed, safely finds and prioritizes exploitable attack paths, instantly verifies fixes, and drives a continuous loop so you can prove you’re resilient, not just hope you are. NodeZero, the World’s Best AI Hacker™, was built by an elite team of U.S. cyber veterans and has honed its skills over 225K production-safe tests, more than all manual pentests in history. More than 5,000 organizations including the NSA, CISA, Fortune 100 giants, and major healthcare providers trust Horizon3.ai to prioritize what matters and prove they’re ready for what’s next. Horizon3.ai has been recognized by Fast Company as one of the World’s Most Innovative Companies in 2026. The company ranked #3 overall on the 2025 Deloitte Technology Fast 500 and was named the #1 cybersecurity company on the Inc. 5000 in 2025. It has also been named to the Fortune Cyber 60 in both 2023 and 2025 and is a two-time Black Unicorn Award winner.

Contact me