Jobs · Engineering

Staff Defensive Security Software Engineer

Horizon3.ai · United States · 1 wk ago
RemoteRemoteEngineering$240k–$270k/yrFull-time

Horizon3 is an innovative, rapidly growing cybersecurity company on a mission to help organizations proactively identify, fix, and verify exploitable vulnerabilities before they can be leveraged by cybercriminals. Our flagship product, NodeZero™, delivers autonomous pentests and security assessments that scale across complex environments, including internal, external, cloud, and hybrid cloud infrastructures. From small educational institutions to global enterprises, our platform is trusted by IT and SecOps teams, MSSPs, MSPs, and consulting pentesters. Our team blends former U.S. Special Operations cyber operators, startup engineers, and seasoned cybersecurity professionals, tackling industry challenges like ineffective tools, false positives, alert fatigue, skills shortages, and high costs of traditional consulting.

About the role

We are looking for a Staff Security Researcher / Developer to join our Detection & Deception (DnD) Team to help build Horizon3’s deception capabilities. This role will focus initially on evolving Tripwires — a threat detection and deception capability within the NodeZero platform that uses autonomous pentests to place decoys (honeytokens) along high-risk attack paths. When an attacker interacts with a tripwire, the system generates an alert so defenders can investigate and respond. It's a great fit for someone who thrives in an agile, fast-paced environment and is excited to ship high-quality work that impacts the cybersecurity landscape.

Responsibilities

  • Combine deep security domain expertise with hands-on full-stack development to design, prototype, and ship new security capabilities within NodeZero.
  • Partner with product managers and designers to identify high-impact opportunities and work alongside product engineers to turn ideas into MVPs and production features.
  • Focus on honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response.
  • Own the end-to-end technical vision for the workstream — from concept through shipping, iterating, and deprecating.
  • Contribute production code at a Lead/Staff level in a modern backend language (Go, Rust, Python, or similar) in a service-oriented environment.
  • Set and raise the technical bar through design reviews, code quality, and operational discipline.
  • Mentor engineers and build frameworks/architecture to enable high-quality work.
  • Translate ambiguous product goals into concrete technical roadmaps and sequence MVPs without limiting future flexibility.
  • Partner closely with product managers in PRD reviews and sprint planning.
  • Hold the team accountable to outcomes, surfacing risks and tradeoffs early and in writing.

Requirements

  • Expert-level proficiency in large-scale Python software development.
  • Deep experience with network security topics such as reconnaissance and lateral movement.
  • Proficiency with Active Directory, Windows authentication, and other Windows internals.
  • Strong understanding of network protocols such as SMB and WMI, including their role in exploitation vectors.
  • Experience with relational (Postgres) or graph (Neo4j) database systems.
  • Minimum of 4 years of experience in building offensive or defensive security solutions, ideally in endpoint, threat detection, or low-level systems.
  • Bachelor's Degree in Computer Science, Computer Engineering, or related field. Equivalent experience may be considered if demonstrable through proof-of-concept write-ups, published vulnerability research, or similar achievements.

Skills

  • Technical leadership with the ability to own and rally teams around a technical vision.
  • Self-motivation and ability to work independently with minimal supervision.
  • Strong collaboration and communication skills, including technical writing and documentation for diverse stakeholders.
  • Proficiency in designing, presenting, and evaluating technical solutions with secure development practices.
  • Product-minded technical leadership, translating product goals into actionable roadmaps.

Preferred Qualifications

  • OSCP (Offensive Security Certified Professional), GCWN (GIAC Certified Windows Security Administrator), or equivalent certifications.
  • Previous experience in red teaming, penetration testing, incident response, detection engineering, or deception technologies.
  • Experience working on large-scale software projects.
  • Experience administering, attacking, or defending cloud environments.
  • Knowledge of Docker and containerization technologies.
  • Familiarity with identity and directory services such as Active Directory, Entra ID, or Okta.
  • Familiarity with cloud authentication and authorization technologies such as Azure Service Principals or AWS IAM.

Schedule

This is a fully remote position. The role may require up to 5% travel.

Pay

Base salary range: $240,000 - $270,000 annually. The exact salary will be determined based on location, qualifications, experience, and relevant skills. This role may also be eligible for an equity package in the form of stock options.

Benefits

  • Inclusive and diverse team culture.
  • Growth opportunities in a dynamic and expanding company.
  • Innovative and collaborative work environment.
  • 100% remote work with flexible arrangements.
  • Competitive compensation and benefits, including health, vision, and dental care for you and your family.
  • Flexible vacation policy and generous parental leave.

Similar jobs