Staff Attack Engineer @Horizon3
All Others
Salary usd 247,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Staff Attack Engineer @Horizon3

1mth ago - Horizon3 is hiring a remote Staff Attack Engineer. πŸ’Έ Salary: usd 247,000 - 275,000 per year πŸ“Location: USA

Role Description

We're looking for a Staff Attack Engineer to be the technical lead for internal network and Active Directory attack capabilities in NodeZero, our autonomous pentesting platform.

  • Serve as the technical lead and primary subject matter expert for internal-network and Active Directory attack capabilities across NodeZero.
  • Research emerging AD and internal tradecraft (AD Certificate Services abuse, SCCM/ConfigMgr and other management-plane attacks, Kerberos abuse and delegation including RBCD, NTLM and Kerberos coercion and relay, shadow credentials, ACL and GPO abuse, and hybrid identity pivots) and turn it into production attack content.
  • Design, build, and maintain production-grade Python that powers these capabilities safely and at enterprise scale.
  • Focus on modern, hardened environments (NTLM deprecation and SMB signing by default, Kerberos-only, Protected Users and tiered admin, LAPS and gMSA/dMSA) and build attacks that still succeed when the easy paths are closed.
  • Stand up, configure, and exploit representative AD test environments to validate, demonstrate, and regression-test attack scenarios.
  • Extend our attack-path modeling and graph data model to represent new identity, privilege-escalation, and lateral-movement paths.
  • Set priorities and the coverage roadmap based on real customer environments, threat intelligence, and emerging techniques.
  • Mentor and level up attack engineers, and raise the bar on code quality, research rigor, and operational safety.
  • Collaborate cross-functionally with engineers, product managers, and customer-facing teams, and author internal documentation and external research and blog posts.

Qualifications

  • Deep, hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold through domain and enterprise compromise.
  • Command of current AD tradecraft: credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, and lateral movement and persistence.
  • Demonstrated experience attacking modern, hardened environments (NTLM deprecation and enforced signing, Kerberos-only, tiered administration).
  • Strong software engineering fundamentals with expert-level Python, and a track record of shipping and maintaining production-quality code, not just scripts and proofs of concept.
  • Ability to independently research unfamiliar systems and technologies and rapidly become the team's expert.
  • A track record of technical leadership: setting direction, driving high-complexity and high-risk work, and mentoring other engineers.
  • Strong written and verbal communication, including clear technical documentation.
  • A passion for building products, not just finding vulnerabilities.
  • 8+ years of combined offensive security and/or software engineering experience, with significant time focused on Active Directory and internal network attacks.

Requirements

  • OSCP (or OSEP, CRTO, or equivalent offensive certifications).
  • Experience with SCCM, Windows Admin Center, and other modern Windows management-plane attack surfaces.
  • Experience with hybrid identity attacks (Entra ID and Entra Connect, primary refresh tokens, seamless SSO) and on-prem to cloud pivots.
  • Experience developing or contributing to offensive tooling like BloodHound, Impacket, netexec, etc.
  • Familiarity with graph databases (Neo4j) and attack-path analysis.
  • Experience integrating security research into production, multi-tenant SaaS.
  • Public contributions to the field: open-source tools, technical blog posts, conference talks, or published CVEs.
  • Experience building production-safe autonomous or automated offensive tooling.

Benefits

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.
  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Staff Attack Engineer @Horizon3
All Others
Salary usd 247,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,028+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later