Staff Defensive Security Software Engineer

Horizon3 AI
$240,000 - $270,000Remote

About The Position

Horizon3.ai is seeking a Staff Security Researcher / Developer to join their Detection & Deception (DnD) Team. This role will focus on building and evolving deception capabilities within the NodeZero platform, specifically enhancing the Tripwires feature. Tripwires is a threat detection and deception capability that uses autonomous pentests to place decoys (honeytokens) along high-risk attack paths. When an attacker interacts with a tripwire, the system generates an alert for defenders. The ideal candidate thrives in an agile, fast-paced environment and is excited to ship high-quality work that has a real impact on cybersecurity.

Requirements

  • Expert-level proficiency in large-scale Python software development.
  • Deep experience with network security topics such as reconnaissance and lateral movement.
  • Proficiency with Active Directory, Windows authentication, and other Windows internals.
  • Strong understanding of network protocols such as SMB and WMI and their intricacies, including their role in exploitation vectors.
  • Experience with relational (Postgres) or graph (Neo4j) database systems.
  • Minimum of 4 years of experience in building offensive or defensive security solutions, ideally in endpoint, threat detection, or low-level systems.
  • Bachelor's Degree in Computer Science, Computer Engineering or related field.
  • Equivalent experience may be considered if demonstrable through proof-of-concept write-ups, published vulnerability research, or similar achievements.
  • Production code contributions at Lead/Staff level in a modern backend language (Go, Rust, Python, or similar) in a service-oriented environment.
  • Ability to work independently with minimal supervision, demonstrating initiative and a high level of energy.
  • Work closely with other cross-functional partners to build and improve our product portfolio.
  • Strong technical writing and documentation skills, with the ability to convey findings and methodologies to both technical and non-technical stakeholders.
  • Proficiency in designing, presenting, and evaluating technical solutions, ensuring high-quality software and secure development practices.

Nice To Haves

  • OSCP (Offensive Security Certified Professional), GCWN (GIAC Certified Windows Security Administrator) or equivalent certifications.
  • Previous experience in red teaming or penetration testing, incident response, detection engineering, deception technologies, or other deeply technical roles with relevant skill sets.
  • Previous experience working on large-scale software projects.
  • Experience administering, attacking, or defending cloud environments.
  • Knowledge of and experience with Docker and containerization technologies.
  • Familiarity with identity and directory services such as Active Directory, Entra ID, or Okta.
  • Familiarity with cloud authentication and authorization technologies such as Azure Service Principals or AWS IAM.

Responsibilities

  • Combine deep security domain expertise with hands-on full-stack development to design, prototype, and ship new security capabilities within NodeZero.
  • Partner with product managers and designers to identify high-impact opportunities.
  • Work alongside product engineers to quickly turn ideas into MVPs and production features.
  • Conduct product research, threat-informed design, and feature development.
  • Focus on honeytoken and honeypot creation, deployment, and detection logic for Tripwires and adjacent products like Rapid Response.
  • Deepen customer engagement with the platform and deliver novel solutions that measurably improve their security posture.
  • Own the end-to-end technical vision for the workstream and rally the team around it.
  • Set and raise the technical bar (design reviews, code quality, operational discipline) by example.
  • Mentor and enhance the engineers around them; build frameworks and architecture for others to do their best work.
  • Hold the team accountable to outcomes rather than activity; surface risks and tradeoffs early and in writing.
  • Translate ambiguous product goals into concrete technical roadmaps.
  • Partner closely with Product Management, comfortable in PRD reviews.
  • Sequence an MVP without painting the team into a corner.

Benefits

  • Health, vision & dental care for you and your family
  • Flexible vacation policy
  • Generous parental leave
  • Equity package (in the form of stock options)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service