Staff Attack Engineer, Internal/AD

Horizon3 AI · Remote (US) · $247k - $275k
full-time lead Posted 20 hours ago

Before you apply

Build my evidence-backed draft — free Apply on company site →

Paste your relevant resume section or 2–4 true bullets. See supported requirements and honest gaps. No account and no application sent.

Get weekly job alerts like this →

About this role

Get to Know Us Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.  We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.   What You’ll Do We're looking for a Staff Attack Engineer to be the technical lead for internal network and Active Directory attack capabilities in NodeZero, our autonomous pentesting platform. Active Directory is still the beating heart of most enterprise breaches, and it is exactly where our customers most need NodeZero to find and safely prove the exploitable paths that lead to domain and enterprise compromise. This is a highly strategic role. The environments we operate in are hardening fast (NTLM deprecation, SMB signing on by default, Kerberos-only and tiered-admin designs), and at the same time the tradecraft is moving quickly across AD Certificate Services, SCCM and other management planes, delegation abuse, coercion and relay, and hybrid identity. We need someone who lives on that frontier and can keep NodeZero ahead of it. You'll own the technical direction for our internal and AD attack domain: setting the research and content roadmap, acting as the go-to subject matter expert, and raising the bar for the engineers building alongside you. This is not consulting or manual pentesting. The goal is to turn cutting-edge, often manual techniques into safe, reliable, repeatable attacks that run autonomously across the largest internal environments in the world. If you love both breaking Active Directory and building the software that does it, this is the seat. What You’ll Do - Serve as the technical lead and primary subject matter expert for internal-network and Active Directory attack capabilities across NodeZero. - Research emerging AD and internal tradecraft (AD Certificate Services abuse, SCCM/ConfigMgr and other management-plane attacks, Kerberos abuse and delegation including RBCD, NTLM and Kerberos coercion and relay, shadow credentials, ACL and GPO abuse, and hybrid identity pivots) and turn it into production attack content. - Design, build, and maintain production-grade Python that powers these capabilities safely and at enterprise scale. - Focus on modern, hardened environments (NTLM deprecation and SMB signing by default, Kerberos-only, Protected Users and tiered admin, LAPS and gMSA/dMSA) and build attacks that still succeed when the easy paths are closed. - Stand up, configure, and exploit representative AD test environments to validate, demonstrate, and regression-test attack scenarios. - Extend our attack-path modeling and graph data model to represent new identity, privilege-escalation, and lateral-movement paths. - Set priorities and the coverage roadmap based on real customer environments, threat intelligence, and emerging techniques. - Mentor and level up attack engineers, and raise the bar on code quality, research rigor, and operational safety. - Collaborate cross-functionally with engineers, product managers, and customer-facing teams, and author internal documentation and external research and blog posts. What You’ll Bring REQUIRED - Deep, hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold through domain and enterprise compromise. - Command of current AD tradecraft: credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, and lateral movement and persistence. - Demonstrated experience attacking modern, hardened environments (NTLM deprecation and enforced signing, Kerberos-only, tiered administration). - Strong software engineering fundamentals with expert-level Python, and a track record of shipping and maintaining production-quality code, not just scripts and proofs of concept. - Ability to independently research unfamiliar systems and technologies and rapidly become the team's expert. - A track record of technical leadership: setting directi

Similar Jobs

Related searches:

Hybrid Jobs Lead Jobs Hybrid Lead Jobs Lead AI Safety & Security security

Get jobs like this delivered weekly

Free AI jobs newsletter. No spam.