ForgeApply
Try it free

ForgeApply · Job listing

Staff Defensive Security Software Engineer

Horizon3ai

Remote · US, Remote, US$240k – $270k

Apply in about a minute — without sacrificing quality.

ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.

About this role

GET TO KNOW US

Horizon3.ai http://Horizon3.ai is an innovative, rapidly growing cybersecurity company on a mission to help organizations proactively identify, fix, and verify exploitable vulnerabilities before they can be leveraged by cybercriminals. Our flagship product, NodeZero™, delivers autonomous pentests and security assessments that scale across complex environments, including internal, external, cloud, and hybrid cloud infrastructures. From small educational institutions to global enterprises, our platform is trusted by a wide range of organizations—IT and SecOps teams, MSSPs, MSPs, and consulting pentesters.

Our team blends former U.S. Special Operations cyber operators, startup engineers, and seasoned cybersecurity professionals. Together, we’re tackling the industry's toughest challenges: ineffective tools, false positives, alert fatigue, skills shortages, and the high costs and long timelines associated with traditional consulting. We are a culture of learn-it-alls—focused on collaboration, respect, ownership, and delivering results.

As a fully remote company, we prioritize flexibility and require a minimum 25Mbps broadband connection.

THE OPPORTUNITY

We are looking for a Staff Security Researcher / Developer to join our Detection & Deception (DnD) Team to help build Horizon3’s deception capabilities. The team works across product, design, and engineering to deliver features such as Tripwires and Rapid Response.

This role will focus initially on evolving Tripwires — a threat detection and deception capability within the NodeZero platform that uses autonomous pentests to place decoys (honeytokens) along high-risk attack paths. When an attacker interacts with a tripwire, the system generates an alert so defenders can investigate and respond.

It's a great fit for someone who thrives in an agile, fast-paced environment and is excited to ship high-quality work that has a real impact on the cybersecurity landscape.

WHAT YOU’LL DO

As a Security Engineer on the Tripwires team, you'll combine deep security domain expertise with hands-on full-stack development to design, prototype, and ship new security capabilities within NodeZero. You'll partner with product managers and designers to identify high-impact opportunities, and work alongside product engineers to quickly turn those ideas into MVPs and production features. Day-to-day work spans product research, threat-informed design, and feature development — with a particular focus on honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response. By building these capabilities, you'll deepen customer engagement with our platform and deliver novel solutions that measurably improve their security posture.

WHAT YOU’LL BRING

- Technical Leadership: Owns the end-to-end technical vision for the workstream and rallies the team around it — from blank doc through shipping, iterating, and deprecating.

- Software Engineering: Production code contributions at Lead/Staff level in a modern backend language (Go, Rust, Python, or similar) in a service-oriented environment.

- Self-Motivation: The ability to work independently with minimal supervision, demonstrating initiative and a high level of energy.

- Collaboration: Work closely with other cross-functional partners to build and improve our product portfolio

- Communication: Strong technical writing and documentation skills, with the ability to convey findings and methodologies to both technical and non-technical stakeholders.

- Technical Design: Proficiency in designing, presenting, and evaluating technical solutions, ensuring high-quality software and secure development practices.

- Team Leadership: - Sets and raises the technical bar (design reviews, code quality, operational discipline) by example rather than by mandate. - Mentors and enhances the engineers around them; Build the frameworks and architecture for others to do the best work of their careers. - Holds the team accountable to outcomes rather than activity; surfaces risks and tradeoffs early and in writing.

- Product-Minded Technical Leadership: - Translates ambiguous product goals into concrete technical roadmaps. - Partners closely with PM — comfortable in PRD reviews, not just sprint planning. - Sequences an MVP without painting the team into a corner.

REQUIRED QUALIFICATIONS

- Python: Expert-level proficiency in large-scale Python software development.

- Network Security: Deep experience with network security topics such as reconnaissance and lateral movement.

- Windows Experience: Proficiency with Active Directory, Windows authentication, and other windows internals

- Network Protocols: Strong understanding of network protocols such as SMB and WMI and their intricacies, including their role in exploitation vectors.

- Database Experience: Experience with relational (Postgres) or graph (Neo4j) database systems.

- Security Experience: Minimum of 4 years of experience in building offensive or defensive security solutions, ideally in endpoint, threat detection, or low-level systems.

- Education: Bachelor's Degree in Computer Science, Computer Engineering or related field.

Equivalent experience may be considered if demonstrable through proof-of-concept write-ups, published vulnerability research, or similar achievements.

PREFERRED QUALIFICATIONS

- OSCP (Offensive Security Certified Professional), GCWN (GIAC Certified Windows Security Administrator) or equivalent certifications.

- Previous experience in red teaming or penetration testing, incident response, detection engineering, deception technologies, or other deeply technical roles with relevant skill sets.

- Previous experience working on large-scale software projects.

- Experience administering, attacking, or defending cloud environments.

- Knowledge of and experience with Docker and containerization tech

Ready to apply to Horizon3ai?

Apply in about a minute

Similar jobs

More like this: Software Engineer Jobs · Remote Software Engineer Jobs · More jobs at Horizon3ai · Browse all jobs