SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Horizon3.ai is a rapidly growing cybersecurity company building NodeZero, an autonomous penetration testing and security assessment platform trusted by enterprises, MSSPs, and consulting firms. The company combines former U.S. Special Operations cyber operators with startup engineers and seasoned security professionals to tackle ineffective tools, false positives, alert fatigue, and the high costs of traditional security consulting.
You'll join the Detection & Deception (DnD) Team as a Staff Security Researcher/Developer focused on evolving Tripwires—a threat detection and deception capability that uses autonomous pentests to place honeytokens along high-risk attack paths. When attackers interact with tripwires, the system generates alerts for defenders to investigate and respond.
Day-to-day work spans product research, threat-informed design, and full-stack feature development. You'll combine deep security domain expertise with hands-on coding to design, prototype, and ship new security capabilities. This includes honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response. You'll partner with product managers and designers to identify high-impact opportunities and work alongside engineers to rapidly turn ideas into MVPs and production features.
As a Staff-level engineer, you'll own the end-to-end technical vision for your workstream, set and raise the technical bar through example, mentor engineers around you, and build frameworks and architecture for others to do their best work. You'll translate ambiguous product goals into concrete technical roadmaps, partner closely with product leadership on strategy, and sequence MVPs without painting the team into a corner. You'll work independently with minimal supervision, demonstrating initiative and strong communication skills—both technical writing and conveying findings to non-technical stakeholders.
Required: Expert-level Python proficiency in large-scale systems; deep network security experience (reconnaissance, lateral movement); Windows expertise (Active Directory, authentication, internals); strong understanding of network protocols (SMB, WMI) and their exploitation vectors; relational (Postgres) or graph (Neo4j) database experience; minimum 4 years building offensive or defensive security solutions (endpoint, threat detection, low-level systems); Bachelor's in Computer Science or related field. Equivalent experience demonstrated through proof-of-concept write-ups or published vulnerability research is considered.
Preferred: OSCP, GCWN, or equivalent certifications; red teaming, penetration testing, incident response, or detection engineering background; large-scale software project experience; cloud administration/attack/defense experience; Docker and containerization knowledge.