Перейти к основному содержимому
Horizon3

Manager, Attack Engineering

УдалённоUnited States только
Опубликовано
Роль
Инженерный менеджмент
Опыт
Синьор
Занятость
Полная занятость
$235k–$280k/yr
Проверьте доступность

Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

Engineering manager for a US-remote cybersecurity role leading external attack engineering. Needs 5+ years leading offensive security/red team/attack engineering teams, experience managing 6–10+ engineers, and deep external attack surface expertise. Python is preferred; APIs, cloud automation, infrastructure tooling, CI/CD, IaC, and Git are expected.

Обязательные навыки

APIsCloud automationInfrastructure toolingCI/CDTerraformCloudFormationGit

Желательные навыки

PythonAI/LLM systems

Чем предстоит заниматься

  • Lead and grow a team of Attack and Full-Stack Engineers specializing in the External Attack Surface, including Commercial and SaaS platform.
  • Set technical direction, priorities, and quality standards for external offensive capabilities.
  • Mentor engineers and raise the bar for offensive rigor, delivery quality, and customer-facing clarity.
  • Drive hiring and organizational scaling as the External Attack team expands.
  • Own offensive strategy across external and public-facing platforms and infrastructure, enterprise SaaS and externally-facing enterprise commercial software, and identity, SaaS providers, and enterprise platform layers.
  • Guide development of end-to-end attack methodologies from discovery to verification.
  • Drive continuous, at-scale discovery of public-facing external assets.
  • Evaluate identity-centric threats by leveraging dark web and open-source intelligence to simulate credential compromise and phishing consequences.
  • Implement stealth-oriented authentication and password testing methodologies reflecting modern attacker tradecraft.
  • Simulate access abuse and data exfiltration across critical SaaS-based knowledge and information management ecosystems.
  • Ensure NodeZero capabilities are realistic, production-safe, and aligned with modern attacker tradecraft.
  • Partner with Product and Design to translate field insights into prioritized roadmap input and productized capabilities.
  • Create tight feedback loops between real-world attack findings and platform evolution.
  • Help define next-generation attack surfaces across cloud and AI systems.
  • Own the UI/UX and product design for the external attack surface and perimeter breach scenarios, including simplifying the configuration of attack operations and developing visualizations that translate complex attack paths into clear, actionable storytelling regarding customer risk, exploitability, and findings.
  • Oversee high-impact customer engagements and technical briefings.
  • Ensure clear articulation of exploitability, business impact, and remediation.
  • Contribute to external content such as blogs, demos, and thought leadership where appropriate.
  • Manage an on-call rotation for the team, ensuring appropriate coverage and response to critical incidents.

Что требуется

  • 5+ years leading offensive security, red team, or attack engineering teams.
  • Experience managing teams of 6–10+ engineers and scaling organizations.
  • Proven ability to balance hands-on technical depth with strategic leadership.
  • Strong expertise in one or more: external/public-facing infrastructure attack surfaces; enterprise SaaS platforms and externally-facing enterprise commercial software; identity and access abuse across diverse ecosystems.
  • Deep understanding of common misconfigurations and exploitation paths in external platforms.
  • Deep understanding of system-level compromise and lateral movement in externally-facing enterprise commercial software.
  • Deep understanding of complex multi-platform attack scenarios.
  • Ability to chain attack paths end-to-end and clearly explain impact.
  • Strong background in software engineering; Python preferred.
  • Experience with APIs, cloud automation, and infrastructure tooling.
  • Familiarity with CI/CD and infrastructure-as-code.
  • Comfortable working with Git, MR workflows, and product development cycles.
  • Experience translating offensive findings into product capabilities.
  • Strong communication skills across technical and non-technical audiences.
  • Customer-first mindset with focus on real-world impact.
  • Preferred: Experience across diverse environments, including cloud infrastructure, enterprise SaaS, and externally-facing enterprise commercial software.
  • Preferred: Experience in security tooling, red teaming, or offensive engineering products.
  • Preferred: Relevant security certifications such as OSCP, cloud or SaaS security are a plus.
  • Preferred: Public research, blogs, or open-source contributions related to external attack surfaces.
  • Highly self-directed and effective in ambiguous environments.
  • Able to operate at both strategic and hands-on technical levels.
  • Maintains high standards for quality, safety, and customer trust.
  • Strong cross-functional partner across Engineering, Product, and GTM.
  • This job may require up to 10% travel.

Преимущества

  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.
  • Competitive Compensation: We offer competitive salary, equity and benefits.
  • Health, vision & dental insurance for you and your family.
  • Flexible vacation policy.
  • Generous parental leave.
  • All full-time roles are eligible for an equity package in the form of stock options.

Horizon3 is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find, fix, and verify exploitable attack vectors before criminals exploit them. Its flagship product, NodeZero, delivers production-safe autonomous pentests and assessment operations across internal, external, cloud, and hybrid cloud environments.

🇺🇸 Соединенные ШтатыCybersecurityСтартап
$235k–$280k/yr