Horizon3 AIposted 17 days ago
$185,000 - $240,000/Yr
Full-time • Mid Level
San Francisco, CA

About the position

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, 'checkbox' security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.

Responsibilities

  • Design, develop, and integrate web application offensive security content into the NodeZero platform
  • Design, develop, and integrate novel attack capabilities into the NodeZero platform, including offensive security tooling and AI-enhanced techniques.
  • Research and implement AI-driven methods for vulnerability detection, exploitation, and workflow automation.
  • Extend and maintain platform architecture, data models, and system design to support new product features.
  • Monitor production for issues or missed opportunities and create or resolve Jira tickets as needed.
  • Integrate open-source and in-house tools, ensuring quality through testing, code reviews, and production monitoring.
  • Investigate, own, and resolve bugs in developed content.
  • Collaborate cross-functionally to address customer and prospect concerns related to attack content.
  • Author technical blog posts showcasing new research, exploits, or attack methodologies.
  • Mentor junior engineers and contribute to continuous improvement of team processes and standards.

Requirements

  • Experience conducting full scope web application pentests
  • Experience with proxy tools like Burp and with browser developer tools
  • Proficient in object-oriented programming and test-driven development, with strong analytical and problem-solving skills.
  • Experience applying AI-assisted development tools to security research and automation tasks
  • Curiosity about emerging AI technologies.
  • Skilled in designing, evaluating, and communicating technical solutions across systems, APIs, algorithms, and data structures.
  • Familiarity with relational and graph databases, particularly Postgres and Neo4j.
  • Strong written and verbal communication, including technical documentation.
  • Ability to manage multiple priorities, work independently, and mentor teammates of varying experience levels.
  • Quick to learn and adopt new technologies as needed.
  • History of recognized security research, including documented CVE discoveries and responsible disclosure.
  • Track record of successful bug bounty contributions.

Nice-to-haves

  • Experience developing software and automation to aid in web application pentesting
  • Background in large-scale software development projects.
  • Experience fine-tuning language models or implementing retrieval-augmented generation (RAG) for security-focused applications.
  • Experience with AI/LLM tools for building agentic workflows (e.g., LangChain, LangFlow) and integrating contextual data using protocols like Model Context Protocol (MCP).

Benefits

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
  • Remote Work: We are a 100% remote company. Enjoy the convenience and work-life balance that comes with remote work.
  • Competitive Compensation: We offer competitive salary and benefits which includes health, vision & dental care for you and your family, a flexible vacation policy, and generous parental leave.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service