Staff Attack Engineer – Internal/AD

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $247k - $275k / year

⏰ Full Time

🔴 Lead

👷🏻‍♀️ Engineer

👻 Ghost score 20%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Horizon3.ai

Horizon3.ai

51 - 200 employees

Founded 2019

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Cybersecurity • Artificial Intelligence • SaaS

Horizon3. ai is a cybersecurity company that specializes in autonomous penetration testing through its platform, NodeZero. The company's mission is to proactively identify and address attack vectors before they can be exploited, allowing organizations to continuously assess their security posture across various environments including cloud, IoT, and on-premises systems. Founded by veterans from the US Special Operations and National Security sectors, Horizon3. ai offers a self-service SaaS solution that provides organizations with insights into their security vulnerabilities without requiring persistent or credentialed agents.

📋 Description

• Serve as technical lead and primary subject matter expert for internal-network and Active Directory attack capabilities across NodeZero • Research emerging AD and internal tradecraft and turn it into production attack content • Design, build, and maintain production-grade Python powering safe, enterprise-scale capabilities • Develop attacks for modern hardened environments where common paths are closed • Stand up, configure, and exploit representative AD test environments for validation, demonstration, and regression testing • Extend attack-path modeling and graph data models for identity, privilege-escalation, and lateral-movement paths • Set priorities and coverage roadmap based on customer environments, threat intelligence, and emerging techniques • Mentor and develop attack engineers • Raise standards for code quality, research rigor, and operational safety • Collaborate with engineers, product managers, and customer-facing teams • Author internal documentation, external research, and blog posts

🎯 Requirements

• Deep, hands-on offensive experience against Active Directory and internal enterprise networks, from initial foothold through domain and enterprise compromise • Command of current AD tradecraft, including credential access, Kerberos attacks, NTLM coercion and relay, AD Certificate Services abuse, ACL and GPO abuse, lateral movement, and persistence • Demonstrated experience attacking modern, hardened environments, including NTLM deprecation, enforced signing, Kerberos-only, and tiered administration • Expert-level Python and strong software engineering fundamentals • Track record of shipping and maintaining production-quality code • Ability to independently research unfamiliar systems and technologies • Track record of technical leadership, setting direction, driving high-complexity and high-risk work, and mentoring engineers • Strong written and verbal communication, including technical documentation • Passion for building products, not just finding vulnerabilities • 8+ years of combined offensive security and/or software engineering experience, with significant focus on Active Directory and internal network attacks • OSCP, OSEP, CRTO, or equivalent offensive certification preferred • Experience with SCCM, Windows Admin Center, and modern Windows management-plane attack surfaces preferred • Experience with hybrid identity attacks, including Entra ID, Entra Connect, primary refresh tokens, seamless SSO, and on-premises-to-cloud pivots preferred • Experience developing or contributing to BloodHound, Impacket, netexec, or similar offensive tooling preferred • Familiarity with Neo4j and attack-path analysis preferred • Experience integrating security research into production, multi-tenant SaaS preferred • Public contributions such as open-source tools, technical blog posts, conference talks, or published CVEs preferred • Experience building production-safe autonomous or automated offensive tooling preferred • Legally authorized to work in the United States • Must not require employment visa sponsorship now or in the future

🏖️ Benefits

• Equity package in the form of stock options for all full-time roles • Health, vision & dental insurance for you and your family • Flexible vacation policy • Generous parental leave • Career development opportunities • Inclusive and collaborative culture • Remote and hybrid work models depending on role and location • Up to 10% travel

Apply Now

Similar Jobs

🔥 1 hour ago

Pax8

1001 - 5000

🏪 Marketplace

🤝 B2B

☁️ SaaS

Staff Frontier Engineer building and operating complex AI evaluation systems for Pax8’s technology marketplace. Driving safe, data-backed engineering decisions across the organization.

🔥 2 hours ago

XBOX

10,000+ employees

🎮 Gaming

🔧 Hardware

👥 B2C

Animation Engineer advancing skeletal animation systems and character believability for Activision’s AAA games. Designing workflows and features with animators and global studio teams.

🔥 3 hours ago

Braun Intertec Corporation

501 - 1000

💼 Consulting

🏥 Healthcare

📦 Logistics

Principal Geotechnical Engineer managing complex geotechnical consulting projects for Braun Intertec. Leading technical teams, client relationships, proposals, engineering analysis, and North Dakota projects.

🔥 8 hours ago

INTERA Incorporated

201 - 500

💼 Consulting

⚡ Energy

Principal water resources scientist/engineer expanding INTERA’s Midwest water resources and supply consulting practice. Building client relationships, securing work, and leading complex water projects.

🔥 16 hours ago

General Dynamics Information Technology

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

ICAM IdP Engineer designing secure, federated authentication for 4 million DoD identities. GDIT delivers technology and mission services across government, defense, and intelligence.