Manager, Attack Engineering
Job description
Manager, Attack Engineering at Horizon3.ai.
About the role
You will lead and expand the External Attack Engineering team at Horizon3.ai, owning the end-to-end strategy, execution, and scaling of offensive capabilities embedded in the NodeZero platform. You will drive hands-on technical delivery while setting the quality and rigor bar for external attack surface testing across public infrastructure, SaaS, and enterprise commercial software. In this role, you will translate real-world attacker tradecraft into production-safe autonomous capabilities that help customers find and fix exploitable attack vectors before criminals do. You will partner closely with Product and Design to turn offensive insights into prioritized roadmap items and intuitive, actionable user experiences for the platform. You will also own customer-facing technical briefings and high-impact engagements to articulate exploitability, business risk, and remediation clearly. This position is critical to shaping how Horizon3.ai automates continuous external assessment for organizations of all sizes.
Key facts
What you'll do
Lead and grow a team of Attack and Full-Stack Engineers specializing in the External Attack Surface, including Commercial and SaaS platform.
Set technical direction, priorities, and quality standards for external offensive capabilities across public-facing infrastructure and enterprise SaaS.
Mentor engineers and elevate the bar for offensive rigor, delivery quality, and clarity when engaging with customers and stakeholders.
Drive hiring and organizational scaling as the External Attack team expands to meet growing customer demand.
Own offensive strategy across external and public-facing platforms, enterprise SaaS, and externally-facing commercial software.
Guide development of end-to-end attack methodologies spanning discovery, exploitation, verification, and remediation.
Drive continuous, at-scale discovery of public-facing external assets to identify potential attack paths and misconfigurations.
Evaluate identity-centric threats by leveraging dark web and open-source intelligence to simulate credential compromise and phishing consequences.
Implement stealth-oriented authentication and password testing methodologies that reflect modern attacker tradecraft while remaining production-safe.
Simulate access abuse and data exfiltration across critical SaaS-based knowledge and information management ecosystems to validate real-world risk.
Ensure NodeZero capabilities are realistic, production-safe, and aligned with current attacker techniques and behaviors.
Partner with Product and Design to translate field insights into prioritized roadmap input and productized capabilities for external attack surfaces.
Create tight feedback loops between real-world attack findings and platform evolution to continuously improve offensive coverage and usability.
Help define next-generation attack surfaces across cloud and AI systems to anticipate emerging external risks.
Own the UI/UX and product design for the external attack surface and perimeter breach scenarios, simplifying configuration and developing visualizations that turn complex attack paths into clear, actionable risk stories.
Oversee high-impact customer engagements and technical briefings to demonstrate exploitability, business impact, and remediation options.
Contribute to external content such as blogs, demos, and thought leadership that showcases the effectiveness of autonomous pentesting.
Requirements
5+ years leading offensive security, red team, or attack engineering teams in fast-paced, product-driven environments.
Proven experience managing and scaling teams of 6-10+ engineers while maintaining high technical and delivery standards.
Strong expertise in one or more of the following domains: external/public-facing infrastructure attack surfaces, enterprise SaaS platforms and external commercial software, identity and SaaS providers, and enterprise platform layers.
Demonstrated ability to design, execute, and operationalize end-to-end attack methodologies from discovery through verification and remediation.
Experience leveraging dark web and open-source intelligence to model identity-centric threats, including credential compromise and phishing impact scenarios.
Deep knowledge of stealth-oriented authentication and password testing approaches aligned with modern attacker behavior.
Hands-on experience simulating access abuse and data exfiltration across SaaS-based knowledge and information management ecosystems.
A strong product mindset with the ability to translate complex offensive findings into clear, customer-facing narratives and actionable platform improvements.
Nice to have
Experience contributing to blogs, demos, or other external content that demonstrates offensive security expertise and thought leadership.
Practical notes
This is a full-time remote position based in the United States.
The role may involve occasional travel, visa sponsorship considerations, and adherence to standard project timelines as defined by business needs.