SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Attack Engineer, Internal/AD

Horizon3.ai - Remote - Remote - posted 2026-09-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Horizon3.ai is seeking a Staff Attack Engineer to lead the technical direction of internal network and Active Directory attack capabilities within NodeZero, an autonomous pentesting platform. This is a strategic role focused on keeping NodeZero ahead of rapidly evolving enterprise security hardening and attack tradecraft. You will own the technical roadmap for internal and AD attack domains, serving as the primary subject matter expert and raising the bar for engineers on the team. The role bridges cutting-edge offensive security research with production software engineering—turning manual techniques into safe, reliable, repeatable attacks that operate autonomously across the largest enterprise environments. Key responsibilities include: - Leading technical strategy and serving as SME for internal-network and Active Directory attack capabilities - Researching emerging AD tradecraft (AD Certificate Services abuse, SCCM/ConfigMgr attacks, Kerberos abuse, delegation attacks, NTLM coercion and relay, shadow credentials, ACL/GPO abuse, hybrid identity pivots) and translating it into production attack content - Designing and maintaining production-grade Python code that powers these capabilities safely at enterprise scale - Focusing on modern, hardened environments (NTLM deprecation, SMB signing enforcement, Kerberos-only, Protected Users, tiered admin, LAPS, gMSA/dMSA) and building attacks that succeed when easy paths are closed - Building and configuring representative AD test environments to validate, demonstrate, and regression-test attack scenarios - Extending attack-path modeling and graph data models to represent new identity, privilege-escalation, and lateral-movement paths - Setting priorities and coverage roadmaps based on real customer environments, threat intelligence, and emerging techniques - Mentoring attack engineers and raising standards for code quality, research rigor, and operational safety - Cross-functional collaboration with engineers, product managers, and customer-facing teams; authoring internal documentation and external research Required qualifications: Deep hands-on offensive experience against Active Directory and internal enterprise networks from initial foothold through domain and enterprise compromise. Command of current AD tradecraft including credential access, Kerberos attacks, NTLM coercion/relay, AD Certificate Services abuse, ACL/GPO abuse, and lateral movement/persistence. Demonstrated experience attacking modern hardened environments. Strong software engineering fundamentals with expert-level Python and a track record of shipping production-quality code. Ability to independently research unfamiliar systems and rapidly become the team expert. Track record of technical leadership, setting direction, driving complex/high-risk work, and mentoring. Strong written and verbal communication. Passion for building products, not just finding vulnerabilities. 8+ years of combined offensive security and/or software engineering experience with significant focus on Active Directory and internal network attacks. Preferred: OSCP, OSEP, CRTO, or equivalent certifications. Experience with SCCM, Windows Admin Center, and modern Windows management-plane attack surfaces. Hybrid identity attacks (Entra ID, Entra Connect, primary refresh tokens, seamless SSO) and on-prem to cloud pivots. Development or contributions to offensive tooling (BloodHound, Impacket, netexec). Familiarity with graph databases (Neo4j) and attack-path analysis. Experience integrating security research into production multi-tenant SaaS.

Similar roles