Staff Defensive Security Software Engineer
Job description
Staff Defensive Security Software Engineer at Horizon3.ai.
About the role
Join a cybersecurity company focused on proactively finding and fixing exploitable vulnerabilities within the complex landscape of modern enterprise environments. This position is centered on the design and implementation of advanced deception capabilities that reside at the core of our flagship product, NodeZero. You will own the creation of features that actively detect and mislead attackers, shifting the advantage back to the defender before any real damage occurs. In this capacity, you will build the logic that entices and traps malicious actors, providing critical visibility into their tactics. The role requires a mindset that bridges the gap between offensive techniques and defensive architecture, ensuring solutions are both robust and realistic. You will work closely with cross-functional teams to ensure that the deception layers integrate seamlessly into the broader security platform. Ultimately, your contributions will directly enhance the ability of organizations to detect intruders early and disrupt their operational plans.
Key facts
What you'll do
- Architect and deploy new security features that enhance threat detection and deception across distributed systems.
- Develop and refine Tripwires that utilize realistic decoys to trigger alerts and notify defenders of active intrusion attempts.
- Analyze product requirements and translate high-level goals into secure, scalable, and maintainable technical solutions.
- Conduct deep research into current attacker methodologies and TTPs to proactively inform the design of defensive countermeasures.
- Engineer robust integrations with identity providers and directory services to ensure accurate attribution and context within deception workflows.
- Optimize database interactions for high-fidelity logging and telemetry, utilizing relational stores like Postgres and graph databases such as Neo4j.
- Collaborate with the product management team to prioritize features that maximize the detection fidelity and operational value of the platform.
- Implement low-level network interactions necessary for endpoint deception, focusing on protocols and services attackers commonly abuse.
- Write clean, tested code that adheres to strict security standards and supports long-term operational stability in production environments.
- Participate in on-call rotations to respond to critical issues, ensuring rapid iteration and improvement of defensive capabilities.
Requirements
- Possess a minimum of 4 years of professional experience building offensive or defensive security solutions, with a demonstrated focus on endpoint security, threat detection, or low-level system internals.
- Demonstrate expert-level proficiency in Python, capable of managing large-scale software projects with complex dependencies and performance requirements.
- Exhibit a deep, practical understanding of network security concepts, including advanced reconnaissance techniques and common lateral movement strategies employed by adversaries.
- Show mastery of Windows internals, including the intricacies of the Windows operating system architecture and its core subsystems.
- Demonstrate expert knowledge of Active Directory, including its architecture, authentication mechanisms, and group policy implementations.
- Possess strong familiarity with network protocols such as SMB and WMI, including their legitimate uses and common exploitation patterns in attacks.
- Have hands-on experience with relational databases like Postgres or graph databases like Neo4j, including schema design and query optimization.
- Hold a Bachelor's Degree in Computer Science, Computer Engineering, or a closely related technical field, or possess equivalent demonstrable experience that validates your expertise.
Nice to have
- Possess industry certifications such as OSCP, GCWN, or other comparable credentials that validate your offensive security capabilities.
- Have prior professional experience in red teaming, penetration testing, incident response, or detection engineering roles.
- Have led or contributed to large-scale software projects that involved complex integrations and high reliability requirements.
- Demonstrate familiarity with cloud environments, including the ability to administer, attack, or defend infrastructure and services within public cloud platforms.
- Have hands-on experience with Docker and broader containerization technologies, including orchestration and networking within containerized deployments.
- Possess deep knowledge of identity services such as Active Directory, Microsoft Entra ID, or enterprise platforms like Okta and their authentication workflows.
- Understand cloud authentication and authorization technologies, including the implementation and management of Azure Service Principals and AWS IAM policies.
Practical notes
- This is a fully remote position that requires a reliable connection with a minimum bandwidth of 25Mbps to support development and testing activities.
- The role may require up to 5% travel for company events, strategic planning sessions, or professional development opportunities.
- Benefits package includes comprehensive health, vision, and dental care, flexible vacation policies, and generous parental leave options.
- Applicants are permitted to redact age-identifying information from their application materials to ensure fair consideration.
- The position is open to residents of the United States, and remote work arrangements are contingent upon legal and tax compliance.