Senior Attack Engineer, Offensive Tooling
Horizon3.aiUS, Remote$180k – $240kPosted 6 April 2026
Job Description
Senior Attack Engineer, Offensive Tooling
Get to Know Us
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs.
We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results.
SUMMARY
We are looking for an Offensive Tooling Engineer to design, develop, and maintain a custom implant framework and supporting C2 infrastructure. You will build cross-platform post-exploitation capabilities in Rust, develop evasion techniques, and create tooling that operates reliably in defended environments.
This is a hands-on engineering role — you will own the full lifecycle from concept through deployment, testing, and monitoring. Your work will have a significant impact on the effectiveness of the NodeZero proactive security platform towards helping defenders prepare themselves against real world threats.
ESSENTIAL FUNCTIONS
- Develop and maintain a multi-platform implant written in Rust (Windows, Linux, macOS; x86/x64/ARM)
- Build and extend C2 server infrastructure, task dispatch, and communications protocols
- Implement post-exploitation modules: credential access, process injection, privilege escalation, lateral movement
- Research and implement AV/EDR evasion techniques to keep tooling operational against modern defenses
- Design and build network pivoting and tunneling capabilities
- Write integration tests that exercise tooling against real targets across multiple OS and architecture combinations
COMPETENCIES/REQUIREMENTS
- Strong proficiency in Rust, including unsafe code, FFI, async runtimes (tokio), and cross-compilation
- Deep knowledge of Windows internals: Win32 API, process injection, memory manipulation, DLL loading, PE format
- Experience with credential access techniques (DPAPI, LSASS, browser credential stores)
- Familiarity with Linux internals: libc, process enumeration
- Understanding of networking at the packet level (TCP/IP, ICMP, custom binary protocols)
- Demonstrated experience building or maintaining C2 / implant software (custom or open-source)
- Background in red team operations or offensive tool development
- Proficiency in Python for developing and maintaining attack automation and integration
- Experience developing production safe, high quality code deployed to end user machines
DESIRED/NICE TO HAVE
- Experience with privilege escalation technique development
- Experience researching and implementing EDR evasion techniques
- PE parsing and reflective loading
- Integration testing offensive tools against defended environments
Perks of Horizon3.ai
- Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
- Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
- Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
- Remote Work: We are a 100% remote company. Enjoy the convenience and work-life ... (truncated, view full listing at source)
Apply Now
Direct link to company career page
AI Resume Fit Check
See exactly which skills you match and which are missing before you apply. Free, instant, no spam.
Check my resume fitFree · No credit card