Jobs · Engineering

Manager, Attack Engineering

Horizon3.ai · United States · 2 days ago
RemoteRemoteEngineering$235k–$280k/yrFull-time

About the role

We are seeking an experienced Engineering Manager to lead our External Attack Engineering team. This role involves overseeing a team responsible for designing, validating, and scaling offensive capabilities within the NodeZero platform targeting the modern external attack surface, including public-facing infrastructure, SaaS platforms, and externally-facing enterprise commercial software.

Responsibilities

  • Lead and grow a team of Attack and Full-Stack Engineers specializing in the External Attack Surface, including Commercial and SaaS platform.

  • Set technical direction, priorities, and quality standards for external offensive capabilities.

  • Mentor engineers and raise the bar for offensive rigor, delivery quality, and customer-facing clarity.

  • Drive hiring and organizational scaling as the External Attack team expands.

  • Own offensive strategy across: External and Public-facing platforms and infrastructure, Enterprise SaaS and externally-facing enterprise commercial software, Identity, SaaS providers, and enterprise platform layers.

  • Guide development of end-to-end attack methodologies (Discovery → verification):

    • Drive continuous, at-scale discovery of public-facing external assets.

    • Evaluate identity-centric threats by leveraging dark web and open-source intelligence to simulate credential compromise and phishing consequences.

    • Implement stealth-oriented authentication and password testing methodologies reflecting modern attacker tradecraft.

    • Simulate access abuse and data exfiltration across critical SaaS-based knowledge and information management ecosystems.

  • Ensure NodeZero capabilities are realistic, production-safe, and aligned with modern attacker tradecraft.

  • Partner with Product and Design to translate field insights into prioritized roadmap input and productized capabilities.

  • Create tight feedback loops between real-world attack findings and platform evolution.

  • Own the UI/UX and product design for the external attack surface and perimeter breach scenarios, including simplifying the configuration of attack operations and developing visualizations that translate complex attack paths into clear, actionable storytelling regarding customer risk, exploitability, and findings.

  • Oversee high-impact customer engagements and technical briefings.

  • Ensure clear articulation of exploitability, business impact, and remediation.

  • Contribute to external content such as blogs, demos, and thought leadership where appropriate.

Requirements

  • 5+ years leading offensive security, red team, or attack engineering teams.

  • Experience managing teams of 6–10+ engineers and scaling organizations.

  • Proven ability to balance hands-on technical depth with strategic leadership.

  • Strong expertise in one or more: External/Public-facing infrastructure attack surfaces, Enterprise SaaS platforms and externally-facing enterprise commercial software, Identity and access abuse across diverse ecosystems.

  • Deep understanding of: Common misconfigurations and exploitation paths in external platforms, System-level compromise and lateral movement in externally-facing enterprise commercial software, Complex multi-platform attack scenarios.

  • Strong background in software engineering (Python preferred).

  • Experience with APIs, cloud automation, and infrastructure tooling.

  • Familiarity with CI/CD and infrastructure-as-code (Terraform, CloudFormation, etc.).

  • Comfortable working with Git, MR workflows, and product development cycles.

  • Experience translating offensive findings into product capabilities.

  • Strong communication skills across technical and non-technical audiences.

  • Customer-first mindset with focus on real-world impact.

Competencies / Requirements

  • Leadership: Ability to lead and grow a team, set technical direction, and mentor engineers.

  • Technical / Engineering Fluency: Strong background in software engineering, familiarity with APIs, cloud automation, and infrastructure tooling.

  • Product + Customer Orientation: Experience translating offensive findings into product capabilities, strong communication skills across technical and non-technical audiences.

  • Desired Skills: Experience across diverse environments, familiarity with AI/LLM systems and associated attack surfaces, experience in security tooling, red teaming, or offensive engineering products, relevant security certifications (e.g., OSCP, cloud or SaaS security).

  • Travel: Up to 10% travel required.

Perks of Horizon3

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.

  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.

  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.

  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.

  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.

Compensation And Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.

Similar jobs