Back to Jobs
Horizon3 ai
Cybersecurity 9h ago

Staff Attack Engineer

Horizon3 ai
United StatesUnited States
Full-time
$247,000 - $275,000 + Equity
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Python2h 41mFree Trial ✨
Start 10-Day Free Trial
CybersecurityAutomation EngineerActive DirectoryPenetration Testing

Want to know if you're a match for this job?

Calculate My Match Score

We're looking for a Staff Attack Engineer to be the technical lead for internal network and Active Directory attack capabilities in NodeZero, our autonomous pentesting platform.

Active Directory is still the beating heart of most enterprise breaches, and it is exactly where our customers most need NodeZero to find and safely prove the exploitable paths that lead to domain and enterprise compromise. This is a highly strategic role. The environments we operate in are hardening fast (NTLM deprecation, SMB signing on by default, Kerberos-only and tiered-admin designs), and at the same time the tradecraft is moving quickly across AD Certificate Services, SCCM and other management planes, delegation abuse, coercion and relay, and hybrid identity. We need someone who lives on that frontier and can keep NodeZero ahead of it.

You'll own the technical direction for our internal and AD attack domain: setting the research and content roadmap, acting as the go-to subject matter expert, and raising the bar for the engineers building alongside you.

This is not consulting or manual pentesting. The goal is to turn cutting-edge, often manual techniques into safe, reliable, repeatable attacks that run autonomously across the largest internal environments in the world. If you love both breaking Active Directory and building the software that does it, this is the seat.

What You’ll Do

  • Serve as the technical lead and primary subject matter expert for internal-network and Active Directory attack capabilities across NodeZero.
  • Research emerging AD and internal tradecraft (AD Certificate Services abuse, SCCM/ConfigMgr and other management-plane attacks, Kerberos abuse and delegation including RBCD, NTLM and Kerberos coercion and relay, shadow credentials, ACL and GPO abuse, and hybrid identity pivots) and turn it into production attack content.
  • Design, build, and maintain production-grade Python that powers these capabilities safely and at enterprise scale.
  • Focus on modern, hardened environments (NTLM deprecation and SMB signing by default, Kerberos-only, Protected Users and tiered admin, LAPS and gMSA/dMSA) and build attacks that still succeed when the easy paths are closed.
  • Stand up, configure, and exploit representative AD test environments to validate, demonstrate, and regression-test attack scenarios.
  • Extend our attack-path modeling and graph data model to represent new identity, privilege-escalation, and lateral-movement paths.
  • Set priorities and the coverage roadmap based on real customer environments, threat intelligence, and emerging techniques.
  • Mentor and level up attack engineers, and raise the bar on code quality, research rigor, and operational safety.
  • Collaborate cross-functionally with engineers, product managers, and customer-facing teams, and author internal documentation and external research and blog posts.

What You’ll Bring

Required

  • Deep, hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold through domain and enterprise compromise.
  • Command of current AD tradecraft: credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, and lateral movement and persistence.
  • Demonstrated experience attacking modern, hardened environments (NTLM deprecation and enforced signing, Kerberos-only, tiered administration).
  • Strong software engineering fundamentals with expert-level Python, and a track record of shipping and maintaining production-quality code, not just scripts and proofs of concept.
  • Ability to independently research unfamiliar systems and technologies and rapidly become the team's expert.
  • A track record of technical leadership: setting direction, driving high-complexity and high-risk work, and mentoring other engineers.
  • Strong written and verbal communication, including clear technical documentation.
  • A passion for building products, not just finding vulnerabilities.
  • 8+ years of combined offensive security and/or software engineering experience, with significant time focused on Active Directory and internal network attacks.

Preferred

  • OSCP (or OSEP, CRTO, or equivalent offensive certifications).
  • Experience with SCCM, Windows Admin Center, and other modern Windows management-plane attack surfaces.
  • Experience with hybrid identity attacks (Entra ID and Entra Connect, primary refresh tokens, seamless SSO) and on-prem to cloud pivots.
  • Experience developing or contributing to offensive tooling like BloodHound, Impacket, netexec, etc.
  • Familiarity with graph databases (Neo4j) and attack-path analysis.
  • Experience integrating security research into production, multi-tenant SaaS.
  • Public contributions to the field: open-source tools, technical blog posts, conference talks, or published CVEs.
  • Experience building production-safe autonomous or automated offensive tooling.

This job may require up to 10% of travel to be successful.

How would you rate this job post?

See what other professionals think about this role.

banner

Horizon3.ai is a leading cybersecurity firm that revolutionized the industry with NodeZero, the world's first fully autonomous penetration testing platform. Founded in 2019 by former US Special Operations and national security experts, the company shifts the paradigm from reactive defense to proactive offense. Under the hood, NodeZero acts as an automated ethical hacker, continuously discovering, exploiting, and providing remediation paths for critical vulnerabilities across on-premise, cloud, and hybrid environments. Their primary target audience includes enterprise CISOs, IT directors, and managed service providers (MSPs) who need to rigorously validate their security posture without the massive cost and infrequent cadence of traditional human pentesting. What sets Horizon3.ai apart in the crowded InfoSec market is its ability to safely execute real-world attack vectors in production environments at scale, allowing security teams to fix exploitable weaknesses before threat actors can weaponize them.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More