Staff Security Researcher / Developer
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The Opportunity
We are looking for a Staff Security Researcher / Developer to join our Detection & Deception (DnD) Team to help build Horizon3’s deception capabilities. The team works across product, design, and engineering to deliver features such as Tripwires and Rapid Response.
This role will focus initially on evolving Tripwires — a threat detection and deception capability within the NodeZero platform that uses autonomous pentests to place decoys (honeytokens) along high-risk attack paths. When an attacker interacts with a tripwire, the system generates an alert so defenders can investigate and respond.
It's a great fit for someone who thrives in an agile, fast-paced environment and is excited to ship high-quality work that has a real impact on the cybersecurity landscape.
What You’ll Do
As a Security Engineer on the Tripwires team, you'll combine deep security domain expertise with hands-on full-stack development to design, prototype, and ship new security capabilities within NodeZero. You'll partner with product managers and designers to identify high-impact opportunities, and work alongside product engineers to quickly turn those ideas into MVPs and production features. Day-to-day work spans product research, threat-informed design, and feature development — with a particular focus on honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response. By building these capabilities, you'll deepen customer engagement with our platform and deliver novel solutions that measurably improve their security posture.
What You’ll Bring
Technical Leadership: Owns the end-to-end technical vision for the workstream and rallies the team around it — from blank doc through shipping, iterating, and deprecating.
Software Engineering: Production code contributions at Lead/Staff level in a modern backend language (Go, Rust, Python, or similar) in a service-oriented environment.
Self-Motivation: The ability to work independently with minimal supervision, demonstrating initiative and a high level of energy.
Collaboration: Work closely with other cross-functional partners to build and improve our product portfolio.
Communication: Strong technical writing and documentation skills, with the ability to convey findings and methodologies to both technical and non-technical stakeholders.
Technical Design: Proficiency in designing, presenting, and evaluating technical solutions, ensuring high-quality software and secure development practices.
Team Leadership:
- Sets and raises the technical bar (design reviews, code quality, operational discipline) by example rather than by mandate.
- Mentors and enhances the engineers around them; Build the frameworks and architecture for others to do the best work of their careers.
- Holds the team accountable to outcomes rather than activity; surfaces risks and tradeoffs early and in writing.
Product-Minded Technical Leadership:
- Translates ambiguous product goals into concrete technical roadmaps.
- Partners closely with PM — comfortable in PRD reviews, not just sprint planning.
- Sequences an MVP without painting the team into a corner.
Required Qualifications
Python: Expert-level proficiency in large-scale Python software development.
Network Security: Deep experience with network security topics such as reconnaissance and lateral movement.
Windows Experience: Proficiency with Active Directory, Windows authentication, and other Windows internals.
Network Protocols: Strong understanding of network protocols such as SMB and WMI and their intricacies, including their role in exploitation vectors.
Database Experience: Experience with relational (Postgres) or graph (Neo4j) database systems.
Security Experience: Minimum of 4 years of experience in building offensive or defensive security solutions, ideally in endpoint, threat detection, or low-level systems.
Education: Bachelor's Degree in Computer Science, Computer Engineering or related field.
Equivalent experience may be considered if demonstrable through proof-of-concept write-ups, published vulnerability research, or similar achievements.
Preferred Qualifications
OSCP (Offensive Security Certified Professional), GCWN (GIAC Certified Windows Security Administrator) or equivalent certifications.
Previous experience in red teaming or penetration testing, incident response, detection engineering, deception technologies, or other deeply technical roles with relevant skill sets.
Previous experience working on large-scale software projects.
Experience administering, attacking, or defending cloud environments.
Knowledge of and experience with Docker and containerization technologies.
Familiarity with identity and directory services such as Active Directory, Entra ID, or Okta.
Familiarity with cloud authentication and authorization technologies such as Azure Service Principals or AWS IAM.
Travel Required: We are a fully remote company, and this job may require up to 5% of travel to be successful.
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.