Senior Backend Engineer, Defensive Agent

Horizon3
$199,000 - $235,000Remote

About The Position

Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

Requirements

  • Bachelor's Degree in Computer Science, Computer Engineering or related field.
  • 7+ yrs professional software engineering experience using modern object-oriented or functional languages (Python, Go, Scala, C++, TypeScript, etc).
  • Experience building applications on cloud computing platforms such as AWS, Azure, GCP, using container technologies such as Docker and Kubernetes.
  • Expert proficiency in SQL.
  • Demonstrated experience designing and operating distributed systems in production: asynchronous workflows, queues, retries, idempotency, and partial failure.
  • A track record of shipping and operating production services, including on-call ownership.

Nice To Haves

  • Experience building agentic or LLM-backed systems in production
  • Experience with a durable execution (such as Temporal) or workflow engine or having built equivalent checkpointing yourself.
  • Experience building multi-tenant platforms with hard isolation requirements, workload identity, and short-lived credential brokering.
  • Experience integrating a long tail of third-party APIs behind a normalized abstraction.
  • Familiarity with security control planes and their APIs — EDR (CrowdStrike, SentinelOne, Microsoft Defender), firewalls, SIEM, cloud IAM.
  • Experience with database architectures including relational (PostgreSQL) and graph (Neo4j), and experience building GraphQL backends.
  • Experience with observability tooling (Datadog, Prometheus, Grafana) and distributed tracing.
  • Awareness of prompt injection and untrusted-input handling in systems where an agent consumes data from the environment it operates in.

Responsibilities

  • Build and own the agent execution runtime: durable, resumable, long-running workflows with checkpointing, idempotent steps, cancellation, and timeouts at both the step and run level.
  • Design and implement the tool layer that agents act through — a registry with versioning, schema validation, per-tenant enablement, and authorization enforced server-side rather than by the model.
  • Build the connector framework for third-party security control planes (EDR, firewall, identity, SIEM, cloud IAM).
  • Implement the safe-change pipeline: dry-run and simulation, blast-radius classification, approval gates for high-impact actions, staged rollout, rollback, and an immutable per-tenant audit trail.
  • Extend NodeZero's tenant isolation model to agents that take write actions, covering execution boundaries, egress control, quotas, and cross-tenant leakage in caches, indexes, and logs.
  • Develop core product features in ETL and GraphQL to support data processing and retrieval for agent context, run history, and remediation state.
  • Build the ETL pipelines that turn pentest and remediation outcomes into the datasets our researchers train and evaluate against.
  • Instrument everything. Distributed tracing across an agent run, cost and token accounting per tenant, and the tooling to answer "why did the agent do that" without guessing.
  • Partner with AI researchers, attack engineers, and product to take capabilities from prototype to production, and feed platform constraints back into research direction early rather than late.

Benefits

  • health, vision & dental insurance for you and your family
  • a flexible vacation policy
  • generous parental leave
  • equity package in the form of stock options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service