SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Backend Engineer, Defensive Agent

Horizon3.ai - Remote - Remote - posted 2026-09-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 199,000 - 235,000 / annual

Horizon3 is a fast-growing cybersecurity company building NodeZero, an autonomous pentesting platform that helps organizations proactively find, fix, and verify exploitable attack vectors before criminals exploit them. The platform is used by ITOps/SecOps teams, consulting pentesters, and MSSPs across organizations of all sizes, from educational institutions to Global 100 enterprises. As a Senior Backend Engineer on the Defensive Agent team, you will build the production platform that powers NodeZero's defensive agents. This is a distributed systems role focused on real infrastructure challenges, not glue code. The agents execute inside customer environments under tight isolation, credential, and egress constraints. When an agent proposes a production change, the platform must simulate it, stage it, gate it on approval, roll it back, and provide immutable audit trails of exactly what happened and on whose authority. You will own the agent execution runtime, tool layer, orchestration, connector framework, and observability infrastructure. Key responsibilities include: - Build and own the agent execution runtime with durable, resumable, long-running workflows featuring checkpointing, idempotent steps, cancellation, and timeouts at both step and run levels. - Design and implement the tool layer that agents act through, including a registry with versioning, schema validation, per-tenant enablement, and server-side authorization enforcement. - Build the connector framework for third-party security control planes (EDR, firewall, identity, SIEM, cloud IAM). - Implement the safe-change pipeline: dry-run and simulation, blast-radius classification, approval gates for high-impact actions, staged rollout, rollback, and immutable per-tenant audit trails. - Extend NodeZero's tenant isolation model to agents taking write actions, covering execution boundaries, egress control, quotas, and cross-tenant leakage prevention in caches, indexes, and logs. - Develop core product features in ETL and GraphQL to support data processing and retrieval for agent context, run history, and remediation state. - Build ETL pipelines that turn pentest and remediation outcomes into datasets for researcher training and evaluation. - Instrument everything: distributed tracing across agent runs, cost and token accounting per tenant, and tooling to answer "why did the agent do that" without guessing. - Partner with AI researchers, attack engineers, and product to move capabilities from prototype to production, feeding platform constraints back into research direction early. You will work closely with AI researchers but are not being hired to tune prompts—you are being hired to build the substrate that makes their work shippable and safe. REQUIREMENTS: - Bachelor's Degree in Computer Science, Computer Engineering, or related field - 7+ years professional software engineering experience using modern object-oriented or functional languages (Python, Go, Scala, C++, TypeScript, etc.) - Experience building applications on cloud computing platforms (AWS, Azure, GCP) using container technologies (Docker, Kubernetes) - Expert proficiency in SQL - Demonstrated experience designing and operating distributed systems in production: asynchronous workflows, queues, retries, idempotency, and partial failure handling - Track record of shipping and operating production services, including on-call ownership SET YOU APART (preferred): - Experience building agentic or LLM-backed systems in production - Experience with durable execution engines (Temporal) or workflow engines, or having built equivalent checkpointing - Experience building multi-tenant platforms with hard isolation requirements, workload identity, and short-lived credential brokering - Experience integrating a long tail of third-party APIs behind normalized abstractions - Familiarity with security control planes and their APIs (EDR, firewalls, SIEM, cloud IAM) - Experience with database architectures including relational (PostgreSQL) and graph (Neo4j), and building GraphQL backends - Experience with observability tooling (Datadog, Prometheus, Grafana) and distributed tracing - Awareness of prompt injection and untrusted-input handling in systems where agents consume environment data

Similar roles