Staff Attack Engineer (AI/LLM)
Horizon3
full-remoteleadpermanentsecuritybackend Full remote 71 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
AI/LLM SecurityPrompt InjectionDefense EvasionAutonomous PentestingNodeZeroPythonThreat ModelingOWASP Top 10 for LLMsMITRE ATLASNeo4j
About the role
Role Overview
Staff Attack Engineer specializing in AI/LLM security. You will break AI and agentic systems and translate that research into automated, repeatable attacks inside NodeZero.
Key Missions
- Design and execute prompt injection and defense evasion attacks, focusing on models that are generalizable and reusable.
- Build automated attack modules for NodeZero based on offensive AI/agent research.
- Exploit tool-use and attack AI infrastructure.
- Perform threat modeling for agentic systems by mapping trust boundaries and attack surfaces.
- Apply a productization mindset by building and extending LLM-powered applications with production concerns.
Requirements
- Proven ability to break AI/LLM and agentic systems.
- Experience in a security product or offensive security team; ideally shipped offensive capabilities or tooling.
- Strong penetration testing fundamentals and understanding of common attack chains.
- Expert-level ownership: drive high-complexity, high-risk programs and set strategy.
- Self-motivated problem solver who builds proactive solutions.
- Deep understanding of trust boundaries around AI tools, data sources, and permissions; ability to systematically test and exploit them.
- Familiarity with AI/LLM security frameworks such as OWASP Top 10 for LLMs and MITRE ATLAS.
- Expert-level Python and software engineering skills.
Nice to Have
- Familiarity with graph databases (e.g., Neo4j).
- CTF experience, especially AI/ML-focused challenge categories.
- Contributions to AI security research (blogs, conference talks, CVEs, open-source tools).
- Experience with cloud AI services: Azure OpenAI and GCP Vertex AI.
- Experience with AWS Bedrock and AWS Agent Core.
- Background in traditional exploit development or vulnerability research.
About Horizon3
Horizon3 is a security-focused company building autonomous pentesting capabilities. It develops NodeZero, a platform that automates security testing and offensive workflows for modern systems, including AI and agentic technologies.
Scraped 7/14/2026