Sobre este puesto de Staff Defensive Security Software Engineer en Horizon3 AI
Get to Know Us
Horizon3.ai is an innovative, rapidly growing cybersecurity company on a mission to help organizations proactively identify, fix, and verify exploitable vulnerabilities before they can be leveraged by cybercriminals. Our flagship product, NodeZero™, delivers autonomous pentests and security assessments that scale across complex environments, including internal, external, cloud, and hybrid cloud infrastructures. From small educational institutions to global enterprises, our platform is trusted by a wide range of organizations—IT and SecOps teams, MSSPs, MSPs, and consulting pentesters.
Our team blends former U.S. Special Operations cyber operators, startup engineers, and seasoned cybersecurity professionals. Together, we’re tackling the industry's toughest challenges: ineffective tools, false positives, alert fatigue, skills shortages, and the high costs and long timelines associated with traditional consulting. We are a culture of learn-it-alls—focused on collaboration, respect, ownership, and delivering results.
As a fully remote company, we prioritize flexibility and require a minimum 25Mbps broadband connection.
The Opportunity
We are looking for a Staff Security Researcher / Developer to join our Detection & Deception (DnD) Team to help build Horizon3’s deception capabilities. The team works across product, design, and engineering to deliver features such as Tripwires and Rapid Response.
This role will focus initially on evolving Tripwires — a threat detection and deception capability within the NodeZero platform that uses autonomous pentests to place decoys (honeytokens) along high-risk attack paths. When an attacker interacts with a tripwire, the system generates an alert so defenders can investigate and respond.
It's a great fit for someone who thrives in an agile, fast-paced environment and is excited to ship high-quality work that has a real impact on the cybersecurity landscape.
What You’ll Do
As a Security Engineer on the Tripwires team, you'll combine deep security domain expertise with hands-on full-stack development to design, prototype, and ship new security capabilities within NodeZero. You'll partner with product managers and designers to identify high-impact opportunities, and work alongside product engineers to quickly turn those ideas into MVPs and production features. Day-to-day work spans product research, threat-informed design, and feature development — with a particular focus on honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response. By building these capabilities, you'll deepen customer engagement with our platform and deliver novel solutions that measurably improve their security posture.
What You’ll Bring
Technical Leadership: Owns the end-to-end technical vision for the workstream and rallies the team around it — from blank doc through shipping, iterating, and deprecating.
Software Engineering: Production code contributions at Lead/Staff level in a modern backend language (Go, Rust, Python, or similar) in a service-oriented environment.
Self-Motivation: The ability to work independently with minimal supervision, demonstrating initiative and a high level of energy.
Collaboration: Work closely with other cross-functional partners to build and improve our product portfolio
Communication: Strong technical writing and documentation skills, with the ability to convey findings and methodologies to both technical and non-technical stakeholders.
Technical Design: Proficiency in designing, presenting, and evaluating technical solutions, ensuring high-quality software and secure development practices.
Team Leadership:
Sets and raises the technical bar (design reviews, code quality, operational discipline) by example rather than by mandate.
Mentors and enhances the engineers around them; Build the frameworks and architecture for others to do the best work of their careers.
Holds the team accountable to outcomes rather than activity; surfaces risks and tradeoffs early and in writing.
Product-Minded Technical Leadership:
Translates ambiguous product goals into concrete technical roadmaps.
Partners closely with PM — comfortable in PRD reviews, not just sprint planning.
Sequences an MVP without painting the team into a corner.
Required Qualifications
Python: Expert-level proficiency in large-scale Python software development.
Network Security: Deep experience with network security topics such as reconnaissance and lateral movement.
Windows Experience: Proficiency with Active Directory, Windows authentication, and other windows internals
Network Protocols: Strong understanding of network protocols such as SMB and WMI and their intricacies, including their role in exploitation vectors.
Database Experience: Experience with relational (Postgres) or graph (Neo4j) database systems.
Security Experience: Minimum of 4 years of experience in building offensive or defensive security solutions, ideally in endpoint, threat detection, or low-level systems.
Education: Bachelor's Degree in Computer Science, Computer Engineering or related field.
Equivalent experience may be considered if demonstrable through proof-of-concept write-ups, published vulnerability research, or similar achievements.
Preferred Qualifications
OSCP (Offensive Security Certified Professional), GCWN (GIAC Certified Windows Security Administrator) or equivalent certifications.
Previous experience in red teaming or penetration testing, incident response, detection engineering, deception technologies, or other deeply technical roles with relevant skill sets.
Previous experience working on large-scale software projects.
Experience administering, attacking, or defending cloud environments.
Knowledge of and experience with Docker and containerization technologies.
Familiarity with identity and directory services such as Active Directory, Entra ID, or Okta.
Familiarity with cloud authentication and authorization technologies such as Azure Service Principals or AWS IAM.
Travel Required:
We are a fully remote company, and this job may require up to 5% of travel to be successful.
Compensation and Values:
At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.
In accordance with various State’s transparency regulations, we provide the following salary range information for this position:
Base salary range: $240,000 - $270,000 annually. The exact salary will be determined based on the selected candidate’s location, qualifications, experience, and relevant skills.
Additional compensation: This role may also be eligible for an equity package (in the form of stock options). If any other compensation benefits apply, they will be discussed during the interview process.
Perks of Horizon3.ai:
Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
Remote Work: We are a 100% remote company. Enjoy the flexibility to work in the way that supports you and brings out your best.
Competitive Compensation: We offer competitive salary and benefits which includes health, vision & dental care for you and your family, a flexible vacation policy, and generous parental leave.
You Belong Here:
Horizon3 is not just an equal opportunity employer - we are a community that values diversity, equity, and inclusion as fundamental principles of our culture and success. We are dedicated to fostering a workplace where everyone feels welcome and respected, regardless of race, color, religion, sex, national origin, age, disability, veteran status, sexual orientation, gender identity or expression, genetic information, marital status, hair length or any other legally protected status by law.
Our commitment to diversity and inclusion means we strive to attract, develop, and retain a workforce that reflects the varied communities we serve. We believe that diverse perspectives drive innovation and strengthen our ability to create cutting-edge cybersecurity solutions. At Horizon3, every team member is valued and supported in an environment that encourages personal and professional growth.
We welcome candidates from all backgrounds and experiences, and we encourage all qualified individuals to apply. Come be a part of Horizon3, where your unique contributions are recognized, and your potential is limitless.
Other Duties:
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
Application Note:
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.